National cyber insurance · A division of Thrive Risk Management CA License #6012320
New York · SHIELD Act + Part 500

New York cyber insurance, built for the SHIELD Act & NYDFS Part 500.

Cyber insurance built for a state that regulates security twice over — the SHIELD Act’s reasonable-safeguards duty on every business holding New Yorkers’ data, and NYDFS Part 500’s 72-hour incident reporting and MFA mandates for financial-services licensees — with an Attorney General who has turned breach settlements into a production line.

Structured for SHIELD Act safeguards & notification duties
Built for NYDFS Part 500 72-hour reporting & MFA mandates
Regulatory defense for AG and DFS proceedings alike

Request a New York cyber Quote

Tell us about your business. A licensed advisor responds — no spam, no call center.

By submitting you consent to be contacted by Thrive Risk Management Insurance Solutions regarding your quote. No obligation.

HomeNew York cyber Insurance
New York cyber, in plain terms

New York polices cybersecurity from two directions. The SHIELD Act imposes a reasonable-safeguards duty and breach-notification obligations on any business, anywhere, that holds a New York resident’s private information. And if you are licensed by the Department of Financial Services — banks, insurance agencies, mortgage brokers, money transmitters — 23 NYCRR Part 500 adds a prescriptive cybersecurity program with 72-hour incident reporting, amended in November 2023 and fully phased in by November 2025. The $11.3 million GEICO/Travelers settlement shows what happens when both regimes hit at once. Here is what that means for your cyber policy.

The SHIELD Act: a duty of care for every business

New York’s baseline is the Stop Hacks and Improve Electronic Data Security (SHIELD) Act, codified at General Business Law §899-aa and §899-bb. It does two things. First, §899-bb requires any person or business holding a New York resident’s private information — regardless of where the business sits — to develop, implement, and maintain reasonable administrative, technical, and physical safeguards, with the statute itself listing what those look like: a designated security coordinator, risk assessments, employee training, vetted vendors under contract, and tested controls. Second, §899-aa requires notice of a breach to affected residents without unreasonable delay, notice to the Attorney General, the Department of State, and the State Police — and to the consumer reporting agencies when more than 5,000 New Yorkers are affected.

There is no private right of action under the SHIELD Act — enforcement belongs to the Attorney General, who can seek up to $5,000 per violation for safeguards failures and up to $20 per failed notification, capped at $250,000, for notice violations. And this Attorney General uses it: New York has extracted a steady stream of breach settlements from national retailers, healthcare companies, and accounting firms, frequently pairing the penalty with a mandated multi-year security program. For a cyber policy, that means the New York tail of any breach includes a near-automatic AG inquiry — a regulatory-defense exposure even when no lawsuit ever gets filed.

NYDFS Part 500: the toughest sector rule in the country

If you hold a license from the New York Department of Financial Services — and that includes independent insurance agents and brokers, not just banks — 23 NYCRR Part 500 applies, and its November 1, 2023 amendment sharpened every edge:

  • 72-hour incident reporting: covered entities must notify DFS within 72 hours of a reportable cybersecurity event — and within 24 hours of making any ransomware or extortion payment, with a written explanation of why payment was necessary due 30 days later. Your incident-response vendors have to be capable of feeding a regulator on that clock.
  • Prescriptive controls on a phased schedule: the amendment layered in mandatory MFA, CISO accountability with board-level reporting, encryption, vulnerability management, and annual compliance certifications, with compliance dates phased through November 1, 2025 — so as of today, the full amended rule is live, and “we were still phasing in” is no longer a defense.
  • Real penalties, jointly enforced: in November 2024 the Attorney General and DFS jointly announced an $11.3 million settlement with GEICO ($9.75M) and Travelers ($1.55M) after attackers harvested driver’s-license numbers from quoting tools — citing the Cybersecurity Regulation, the SHIELD Act, and Executive Law together. One incident, two regulators, three statutes.

How your cyber insurance should be structured in New York

A New York cyber program has to assume that any serious incident produces parallel regulatory proceedings, so regulatory-defense coverage that responds to both an AG investigation and a DFS enforcement action — with penalties covered where insurable — is the first thing we check, not the last. For DFS licensees, Part 500 also changes the underwriting itself: applications now effectively mirror the regulation’s control set, and a misstatement about MFA or encryption on an application is the classic path to a denied claim, so we make sure what you attest matches what you run. First-party breach-response coverage should be built around the 72-hour and 24-hour clocks — panel breach counsel and forensics who file DFS notices routinely — and because SHIELD Act exposure follows New Yorkers’ data everywhere, out-of-state businesses selling into New York need this structure too, not just Manhattan firms.

New York cyber — Frequently Asked

Questions New York operators ask.

My business is not a bank — do New York’s cybersecurity laws still apply to me?
Almost certainly yes, on at least one level. The SHIELD Act applies to any person or business, located anywhere, that owns or licenses the private information of even one New York resident — there is no size threshold and no industry carve-out, only scaled-down expectations for small businesses. That means an out-of-state e-commerce company with New York customers owes the same reasonable-safeguards duty as a Manhattan enterprise, and the same breach-notification obligations to affected residents, the Attorney General, the Department of State, and the State Police. Separately, if you hold any license from the Department of Financial Services — and this catches thousands of small insurance agencies, mortgage brokers, and finance companies, not just banks — NYDFS Part 500 adds a prescriptive cybersecurity program on top, with 72-hour incident reporting and mandatory MFA now fully in force after the amended rule finished phasing in on November 1, 2025. Limited exemptions exist for the smallest licensees, but they shrink under the amendment and never eliminate the reporting duty. We map which regime applies to you before structuring the policy, because the answer drives both the coverage you need and the questions underwriters will ask.
Will my cyber policy respond if the New York Attorney General or DFS comes after me following a breach?
It should — if it was structured for New York. Most quality cyber forms include regulatory coverage for investigations and proceedings brought by a government agency arising out of a covered incident, and in New York that grant earns its keep: the Attorney General routinely opens inquiries after reported breaches and has settled with businesses from national retailers to regional accounting firms, while DFS runs its own enforcement track for licensees — and in the GEICO/Travelers matter the two acted jointly, securing $11.3 million over compromised quoting tools. The items to verify are, first, that defense costs for a regulatory proceeding sit inside the insuring agreement and not just as a sublimited afterthought; second, that fines and penalties are covered where insurable by law; and third, that your application answers about MFA, encryption, and incident-response planning are accurate, because for DFS licensees those answers track Part 500 obligations and a wrong one can unwind the policy exactly when you need it. One more New York-specific point: the AG’s penalty math for failed notifications runs per person, so the coverage that pays for fast, complete, properly filed notification is quietly one of the most valuable clauses in the form.
Doesn’t my general liability policy cover cyber attacks?
No — and this is the most expensive assumption in small-business insurance. General liability responds to bodily injury and physical damage to tangible property, and courts have generally held that electronic data is not tangible property. On top of that, standard GL policies now carry explicit exclusions for access to or disclosure of confidential or personal information, added across the market after early data-breach lawsuits. Commercial property policies have the same problem: they cover the server hardware, not the data on it or the income lost while your systems are locked. Cyber insurance exists as a separate line precisely because it covers what those policies deliberately carve out — breach response, ransomware, data restoration, and privacy lawsuits. If a client contract requires “cyber liability,” a GL certificate will not satisfy it.
What does a cyber insurance policy actually cover?
A modern policy has two sides. First-party coverage pays your own costs after an incident: forensics to determine what happened, breach counsel, the notification letters state law requires you to send, credit monitoring for affected people, ransomware and extortion response, business income lost during an outage, and the cost of restoring data. Third-party coverage defends and pays when others come after you: lawsuits from customers or employees whose data was exposed, claims that malware spread from your systems, regulatory investigations, and PCI assessments from the card brands. Most policies add crime-style endorsements for social engineering and funds-transfer fraud, where many real-world losses now occur. The Federal Trade Commission’s Data Breach Response guide shows how many moving parts a breach involves — a good cyber policy funds and coordinates essentially all of them.
Other States

cyber insurance in other states.

Need New York cyber coverage that clears your contracts?

Tell us about your operation and your loss history — we’ll confirm we can write New York and structure the limits to match.

Get a New York Quote Call (818) 356-8150