← All industries
Industry deep dive

US financial services — NYDFS Part 500, GLBA, SEC

Penetration testing from inside and outside the boundary, risk-based scanning and signed evidence for NYDFS Part 500, the FTC Safeguards Rule and SEC disclosure, run continuously on an on-premise appliance so nonpublic information never reaches a vendor cloud.

US financial regulators set explicit testing floors. The NYDFS cybersecurity regulation, 23 NYCRR Part 500, was amended with effect from November 1, 2023, and its last transitional periods ended on November 1, 2025, so every amended requirement now applies, including §500.5: penetration testing from inside and outside the information systems' boundaries, by a qualified party, at least annually. The FTC Safeguards Rule (16 CFR Part 314) covers non-bank financial institutions under FTC jurisdiction, such as mortgage lenders and finance companies: absent effective continuous monitoring, annual penetration testing and vulnerability assessments every six months. Listed companies add the SEC rules: Form 8-K Item 1.05 within four business days of determining that an incident is material, and Regulation S-K Item 106 in the annual report.

What is on the US financial CISO's desk

NYDFS §500.5 and the April 15 filing

Annual inside-and-outside penetration testing, scans at a risk-based frequency and after material changes, remediation prioritized by risk. The April 15 certification is signed by the highest-ranking executive and the CISO and must rest on documentation that demonstrates material compliance.

NYDFS §500.17: 72 hours from determination

Notice to DFS as promptly as possible and no later than 72 hours after determining that a cybersecurity incident has occurred at the entity, an affiliate or a third-party service provider. An extortion payment adds a notice within 24 hours and a written explanation within 30 days.

FTC Safeguards Rule §314.4(d)(2)

Continuous monitoring, or annual penetration testing plus vulnerability assessments every six months and after material changes. Institutions holding information on fewer than 5,000 consumers are exempt from this paragraph (§314.6). Events involving 500 or more consumers go to the FTC within 30 days of discovery.

SEC Item 1.05 and Item 106

Four business days from the materiality determination, which itself must be made without unreasonable delay after discovery. The 10-K description of risk management processes will be read against what actually happened; testing records are what make it defensible.

How Zero Hunt fits a US financial institution

Pillar 1 — Generative Pentest

Inside-and-outside testing between annual engagements

Black-box campaigns from outside the boundary and gray-box campaigns from a standard user's position run on a schedule and after material changes. Findings carry proof of exploitability, the input that risk-based prioritization under §500.5(c) and §314.4(d) needs, and each fix is re-tested with the same proof. The regulation still asks for a qualified party; Zero Hunt gives that party, internal or external, continuous evidence between annual tests.

Pillar 3 — Automatic Compliance

One signed record for several US regimes

Findings are mapped once to NYDFS Part 500, the GLBA Safeguards Rule, the SEC disclosure rules, PCI DSS, SOX IT controls and NIST CSF. Every attack attempt is an Ed25519-signed entry in a hash chain and exported reports are ECDSA-signed, so the records behind the April 15 filing and the 10-K description can be shown to be unaltered.

Pillar 2 — AI Traffic Analysis

A detection timeline for the clocks that follow

AI traffic analysis on the appliance GPU flags exfiltration, command-and-control and lateral movement toward payment and trading systems, with signed timestamps. The DFS 72 hours run from your determination that an incident occurred and the SEC four business days from your materiality determination; the record shows when each fact became known.

Capability emphasis for US financial services

  • ▸Black-box and gray-box campaigns: outside and inside the boundary, as §500.5(a)(1) describes
  • ▸Findings also mapped to PCI DSS requirements 11.3 (vulnerability scans) and 11.4 (penetration testing, including segmentation checks)
  • ▸No outside AI provider receiving nonpublic information: models run on the appliance and the data stays on it
  • ▸Remediation records with owner, re-test result and signed timestamps for the annual certification
  • ▸Integrates with your SIEM/SOAR via REST, WebSocket and webhook

Who buys this in US financial services

CISO sponsoring, because the April 15 filing carries their signature next to the chief executive's; the head of vulnerability management running it; internal audit and compliance checking the mapping against Part 500, the Safeguards Rule or PCI DSS; for listed companies, the disclosure committee using the incident timeline; CFO authorizing because the testing evidence builds up all year rather than once a year.

Frameworks mapped for this sector, worldwide

The same on-premise appliance serves regulated organizations in every region. For this sector, findings and evidence are mapped out of the box to:

Global / cross-industry
  • PCI DSS
  • SWIFT Customer Security Programme
  • NIST Cybersecurity Framework
  • SOC 2
  • ISO/IEC 27001:2022
United States
  • NYDFS Part 500
  • GLBA / FTC Safeguards Rule
  • SEC cybersecurity disclosure rules
  • SOX IT controls

Why this sector runs its AI red team on-premise, on private AI →

Go deeper on the regulations

Want to see this against your environment?

A 30-minute technical demo runs Zero Hunt against a recorded slice of your stack, scoped to the regulatory regime you operate under.