I keep finding the same coverage gap in community bank D&O policies. On page 35, give or take a few pages, the policy has an exclusion — “arising out of any cyber event.” What that clause does is block D&O coverage for anything connected to a data breach: the investigation phase, the formal defense, everything. The provision that gets hit first is called “pre-claim investigative costs,” which is supposed to cover regulatory inquiries before formal charges are filed. The declarations page says that coverage exists. The exclusion on page 35 says it doesn’t.
I’ve been pointing this gap out to the banks for a while now, and the reaction is almost always the same. Nobody knew.
The enforcement track record
23 NYCRR 500 is the NYDFS cybersecurity regulation that requires every New York-regulated financial institution to maintain a cybersecurity program, report breaches within 72 hours, and certify compliance annually. It applies to all entities regulated by NYDFS, including state-chartered community banks operating in New York.
This gap is especially a concern for community banks based in New York. It became a real problem when NYDFS started collecting fines. Since 2024, they collected $63 million in cybersecurity penalties under Part 500.
Genesis Global paid $8 million. GEICO paid $9.75 million. PayPal paid $2 million for something as basic as not requiring MFA.
In October 2025, NYDFS swept eight auto insurers in a single action for unprotected NPI in public-facing web apps: $19 million. All crypto firms, insurers, fintechs. No community banks yet.
The per-day penalty rates are flat:
- Standard violations: $2,500 per day
- Reckless conduct: $15,000 per day
- Willful violations: $75,000 per day
The amended regulation became fully effective November 2025, and the enforcement triggers are wider now than when those early crypto fines hit.
Will NYDFS pursue community banks? I don’t know. What I do know is that the violations triggering these fines aren’t esoteric. Missing MFA. Incomplete risk assessments. Late breach notification. False compliance certifications. I see some of these violations in IT audits on a regular basis.
The costs nobody budgets for
Let’s say your bank has a data breach. You follow your playbook: you notify NYDFS within 72 hours, you activate the incident response plan, you notify customers. That part is expensive but you have prepared for it.
After that, the bills start piling up in ways your budget didn’t account for: NYDFS sends a request for information. FDIC opens its own examination. AG’s office calls separately. Each agency wants its own document production and its own meetings with the board. You need separate outside counsel for each. Keep in mind: Nobody has yet filed charges. Nobody has yet issued a formal order, which is what would trigger the D&O policy’s defense costs coverage. But there are still lots and lots of questions that need lots and lots of lawyers to answer.
I’ve estimated what this might cost. One regulatory inquiry runs above $100,000 in outside counsel in the first six months, and that’s conservative. Three inquiries at once? I’ve heard estimates past $500,000.
D&O policies have a provision for this phase: “pre-claim investigative costs.” That pays for responding to regulatory inquiries before formal proceedings begin. In the community bank programs I’ve audited, this provision has not held up, and the reason goes back to the cyber exclusion on page 35.
I asked brokers whether they read the cyber exclusion part before renewal and explain the implications to their clients. The answers I am hearing aren’t encouraging.
There are more ways the coverage can fall short. Some programs cap investigative costs at $100,000. And some banks just have not selected the coverage at all. Nobody flagged it at renewal. That one frustrates me because it’s the easiest to fix.
Penalties and personal exposure
Many board members of community banks are volunteer directors. They rarely connect a cybersecurity regulation to their personal financial exposure caused by a gap in their D&O coverage their broker hasn’t raised. I’m not confident most brokers have thought about it either.
What you can check right now
Pull your D&O policy and look for three things.
If any of these three checks come back wrong, your program has a gap that needs attention before your next renewal.
Your examiner confirmed the D&O policy exists. That doesn’t tell you whether it pays when NYDFS starts asking questions.
If you want a more thorough review of your insurance program, get in touch.
The D&O cyber exclusion is one of five ways coverage breaks down when three policies interact. I mapped the others in Five Common Cyber Incidents, Three Policies, and the Gaps Between Them.