US financial services — NYDFS Part 500, GLBA, SEC
Penetration testing from inside and outside the boundary, risk-based scanning and signed evidence for NYDFS Part 500, the FTC Safeguards Rule and SEC disclosure, run continuously on an on-premise appliance so nonpublic information never reaches a vendor cloud.
US financial regulators set explicit testing floors. The NYDFS cybersecurity regulation, 23 NYCRR Part 500, was amended with effect from November 1, 2023, and its last transitional periods ended on November 1, 2025, so every amended requirement now applies, including §500.5: penetration testing from inside and outside the information systems' boundaries, by a qualified party, at least annually. The FTC Safeguards Rule (16 CFR Part 314) covers non-bank financial institutions under FTC jurisdiction, such as mortgage lenders and finance companies: absent effective continuous monitoring, annual penetration testing and vulnerability assessments every six months. Listed companies add the SEC rules: Form 8-K Item 1.05 within four business days of determining that an incident is material, and Regulation S-K Item 106 in the annual report.
What is on the US financial CISO's desk
NYDFS §500.5 and the April 15 filing
Annual inside-and-outside penetration testing, scans at a risk-based frequency and after material changes, remediation prioritized by risk. The April 15 certification is signed by the highest-ranking executive and the CISO and must rest on documentation that demonstrates material compliance.
NYDFS §500.17: 72 hours from determination
Notice to DFS as promptly as possible and no later than 72 hours after determining that a cybersecurity incident has occurred at the entity, an affiliate or a third-party service provider. An extortion payment adds a notice within 24 hours and a written explanation within 30 days.
FTC Safeguards Rule §314.4(d)(2)
Continuous monitoring, or annual penetration testing plus vulnerability assessments every six months and after material changes. Institutions holding information on fewer than 5,000 consumers are exempt from this paragraph (§314.6). Events involving 500 or more consumers go to the FTC within 30 days of discovery.
SEC Item 1.05 and Item 106
Four business days from the materiality determination, which itself must be made without unreasonable delay after discovery. The 10-K description of risk management processes will be read against what actually happened; testing records are what make it defensible.
How Zero Hunt fits a US financial institution
Inside-and-outside testing between annual engagements
Black-box campaigns from outside the boundary and gray-box campaigns from a standard user's position run on a schedule and after material changes. Findings carry proof of exploitability, the input that risk-based prioritization under §500.5(c) and §314.4(d) needs, and each fix is re-tested with the same proof. The regulation still asks for a qualified party; Zero Hunt gives that party, internal or external, continuous evidence between annual tests.
One signed record for several US regimes
Findings are mapped once to NYDFS Part 500, the GLBA Safeguards Rule, the SEC disclosure rules, PCI DSS, SOX IT controls and NIST CSF. Every attack attempt is an Ed25519-signed entry in a hash chain and exported reports are ECDSA-signed, so the records behind the April 15 filing and the 10-K description can be shown to be unaltered.
A detection timeline for the clocks that follow
AI traffic analysis on the appliance GPU flags exfiltration, command-and-control and lateral movement toward payment and trading systems, with signed timestamps. The DFS 72 hours run from your determination that an incident occurred and the SEC four business days from your materiality determination; the record shows when each fact became known.
Capability emphasis for US financial services
- ▸Black-box and gray-box campaigns: outside and inside the boundary, as §500.5(a)(1) describes
- ▸Findings also mapped to PCI DSS requirements 11.3 (vulnerability scans) and 11.4 (penetration testing, including segmentation checks)
- ▸No outside AI provider receiving nonpublic information: models run on the appliance and the data stays on it
- ▸Remediation records with owner, re-test result and signed timestamps for the annual certification
- ▸Integrates with your SIEM/SOAR via REST, WebSocket and webhook
Who buys this in US financial services
CISO sponsoring, because the April 15 filing carries their signature next to the chief executive's; the head of vulnerability management running it; internal audit and compliance checking the mapping against Part 500, the Safeguards Rule or PCI DSS; for listed companies, the disclosure committee using the incident timeline; CFO authorizing because the testing evidence builds up all year rather than once a year.
Frameworks mapped for this sector, worldwide
The same on-premise appliance serves regulated organizations in every region. For this sector, findings and evidence are mapped out of the box to:
- Global / cross-industry
- PCI DSS
- SWIFT Customer Security Programme
- NIST Cybersecurity Framework
- SOC 2
- ISO/IEC 27001:2022
- United States
- NYDFS Part 500
- GLBA / FTC Safeguards Rule
- SEC cybersecurity disclosure rules
- SOX IT controls
Why this sector runs its AI red team on-premise, on private AI →
Go deeper on the regulations
- Playbook · 10 minNYDFS Part 500 penetration testing and vulnerability management — the §500.5 playbook
An operational guide to 23 NYCRR 500.5 as amended in November 2023: the penetration testing, scanning and remediation duties, who they cover, and the evidence behind the annual filing.
- Playbook · 9 minSEC cybersecurity disclosure — the Form 8-K Item 1.05 and Item 106 playbook
A CISO playbook for the SEC's 2023 cybersecurity rules: the Form 8-K Item 1.05 filing due four business days after a materiality determination, and the annual Item 106 disclosure.
- Playbook · 9 minThe KEV-driven emergency patch window — a CISO decision playbook for BOD 26-04
A decision playbook for when a product you run lands on the CISA KEV catalog: how to assign the right remediation clock under BOD 26-04 and choose between patch, mitigate, or isolate.
Want to see this against your environment?
A 30-minute technical demo runs Zero Hunt against a recorded slice of your stack, scoped to the regulatory regime you operate under.