Feature Incident Response
NYDFS's May Guidance on Heightened Cybersecurity Threats Is Now an Exam Reference. Here's What Your IR Program Needs to Show.
On May 21, 2026, NYDFS published explicit guidance on what regulated entities should do when cybersecurity risks spike — and told examiners to treat it as a reference point. Here's what the guidance actually requires, why 'voluntary' understates the stakes, and what your incident response program needs to fix before a NYDFS exam.
Table of Contents
TL;DR
- NYDFS issued two industry letters on May 21, 2026, covering heightened cybersecurity threat environment measures and frontier AI risk — both now function as exam reference material
- Five specific actions: test backups including RTOs, review and test IR and BCP plans against current threats, build extended-downtime communications strategies, confirm OT resilience, and monitor transactions for AML/sanctions compliance during incidents
- NYDFS explicitly stated it will treat failure to consider these measures as an examination issue — even where the guidance is nominally voluntary
- Coming three months after the $2.25 million Delta Dental settlement, this guidance defines what NYDFS expects your IR program to look like before the next incident
On May 21, 2026, NYDFS published something that most compliance teams flagged and filed. They shouldn’t have.
Two industry letters landed simultaneously: one on frontier AI cyber risks, one on measures regulated entities should consider in a heightened cybersecurity threat environment. The AI letter got the coverage. The heightened threat letter didn’t. That’s backwards from an exam preparation standpoint.
NYDFS didn’t just issue recommendations. It announced explicitly that it would use the guidance as a reference point in examinations. The word “voluntary” appears nowhere. What appears instead is a clear signal: if your IR program doesn’t account for these measures, you need to document why — and documentation gaps are examination findings waiting to happen.
This came three months after the department’s $2.25 million April 2026 settlement with Delta Dental, the first NYDFS cybersecurity enforcement action of 2026. The settlement identified three gaps that the May guidance directly responds to: an IR plan without sufficient specificity on regulatory reporting, absent data retention policies, and a six-month notification delay. The May guidance isn’t a coincidence. It’s the department telling every other regulated entity: here’s what we found, and here’s what we now expect.
What NYDFS Defined as a “Heightened Threat Environment”
The guidance establishes a specific condition: a period when cybersecurity risks are significantly elevated and have a high likelihood of impacting your information systems, nonpublic information, or operations.
That definition matters for your IR plan design. Most incident response plans treat threats as binary — you either have an incident or you don’t. NYDFS is asking for a third state: a pre-incident elevated posture. Your program should define how it determines it’s in a heightened environment (geopolitical events, sector-wide alerts from FS-ISAC, direct NYDFS communications), and what specific procedures activate automatically when that determination is made.
If your current IR plan doesn’t have a heightened-environment section, it has a gap your examiner will see.
The Five Measures NYDFS Expects You to Consider
The guidance isn’t a long list. It’s five specific, operational actions:
1. Test your backups — including recovery time objectives.
Not “confirm backups exist.” Test them, with documented results, including whether you can restore critical systems within your stated RTOs. NYDFS Part 500 has required annual backup restoration testing since the 2023 amendments. The May guidance reinforces that this testing needs to be scenario-specific, not just “we confirmed the backup completed successfully.” Can you restore your core system in four hours? Can you prove it with a test log?
2. Review and test incident response and business continuity plans against current threats.
The guidance uses the phrase “threat-relevant operational resilience procedures.” That’s not generic testing — it’s testing calibrated to the specific threat landscape NYDFS is signaling. If ransomware is the headline threat, your tabletop should include a ransomware scenario. If your threat environment has elevated vendor breach risk, your tabletop should include a vendor compromise scenario.
Part 500 requires IR plan testing at least annually with all critical staff and management. The May guidance adds a temporal element: testing should occur when the threat environment shifts, not just on a calendar schedule.
3. Develop communications strategies for extended downtime.
This is the gap most small compliance teams skip. Your IR plan probably says “communicate with customers during an incident.” NYDFS wants a documented strategy — who says what, through what channels, with what cadence — specifically for extended operational disruptions where your normal communication systems may also be compromised. Regulators, customers, bank partners, the board: each has a different communication need and a different timeline expectation. Document them separately.
4. Confirm that operational technology can function if IT systems are compromised.
If your core banking system, payment processing, or customer authentication systems go down, what runs independently? Your business continuity plan should answer that question with specifics, not just “we have manual procedures.” For larger institutions with physical infrastructure, this includes confirming that operational technology — building access, transaction terminals, communications equipment — can sustain operations if your IT environment is unavailable.
5. Monitor financial transactions for sanctions and AML compliance during an incident.
This one gets overlooked entirely in most fintech IR plans. When your systems are compromised and your team is in incident mode, transaction monitoring doesn’t stop being a legal obligation. The guidance asks regulated entities to confirm they have procedures for maintaining AML and sanctions screening during an incident — including who is responsible, what manual procedures exist, and how long they can sustain them. If your AML monitoring system goes down, what’s the protocol?
Why “Voluntary” Is the Wrong Frame
NYDFS’s enforcement track record clarifies what “should consider” means in practice. The Delta Dental settlement found an IR plan that didn’t address regulatory reporting obligations with “sufficient specificity” — that’s a standard NYDFS examiners will now apply to every IR plan they review.
The May guidance provides the specificity standard. An IR plan that doesn’t address heightened threat environment procedures, backup restoration testing, communications strategies for extended downtime, and specific regulatory notification timelines will be compared against this guidance. “We didn’t know you expected that” isn’t a response that works when the guidance is published on the NYDFS website.
For any NYDFS-regulated entity — bank, insurer, money transmitter, cryptocurrency firm — the calculus is straightforward: the cost of updating your IR plan is a compliance team sprint. The cost of an IR plan gap found in examination is a consent order, public enforcement action, and the remediation that follows. The Delta Dental settlement cost $2.25 million and generated coverage still cited in compliance forums months later.
What a NYDFS-Ready Tabletop Exercise Looks Like Now
NYDFS expects annual tabletop exercises with documented attendance, including all critical staff and management. Post-May 2026, that tabletop should be designed specifically against the heightened threat environment framework:
| Scenario | Why It Matters |
|---|---|
| Ransomware with extended downtime (7–14 days) | Tests RTOs, manual transaction monitoring continuity, comms strategy execution |
| Vendor breach (third-party access compromised) | Tests third-party IR coordination, notification timing, data scoping |
| Data exfiltration without operational disruption | Tests delayed discovery — the core Delta Dental timeline failure |
| Simultaneous IT failure and OT resilience test | Tests whether OT can sustain operations when IT is unavailable |
Document who attended, what scenarios were tested, what gaps were found, and what remediation actions were assigned with owners and due dates. Your examiner will ask for this documentation. “We did a tabletop” is not sufficient — “here are the sign-in records, scenario scripts, and remediation tracking log” is what a defensible exam package looks like.
The Data Minimization Connection
The Delta Dental settlement made one finding that the May guidance specifically responds to: tens of thousands of files sitting on servers longer than necessary because Delta Dental had no written data retention policies. NYDFS noted that strong record retention programs minimize the data available for extraction.
This isn’t strictly an IR plan requirement — it’s a data governance gap that IR controls can’t compensate for. But NYDFS is connecting them explicitly: an incident that exposes data you shouldn’t still have retained is a compound violation. Your IR plan should reference your data retention policies and include a step to assess whether extracted data was within your retention schedule.
If you don’t have written data retention policies, the NYDFS September 2026 cybersecurity risk assessment guidance clarifies where this fits in your overall Part 500 compliance posture.
The Multi-Regulator Layer
NYDFS doesn’t operate in isolation. Regulated entities in financial services face a notification stack: NYDFS 72 hours, OCC 36 hours for banking organizations, and CIRCIA’s 72-hour requirement that CISA has targeted for finalization in September 2026. Each uses a different materiality standard, starts the clock at a different trigger point, and requires a different report format.
NYDFS’s heightened enforcement posture and CIRCIA’s finalization are converging at the same moment. IR programs designed for a single-regulator world need to be updated for a multi-regulator environment where the clocks run simultaneously and don’t sync.
The May guidance makes one thing clear: NYDFS isn’t waiting for CIRCIA or federal harmonization. It published its own standard, it told examiners to use it as a reference, and it’s already demonstrated through enforcement that notification gaps have a price.
What to Fix Before Your Next Exam
If your IR plan was built before May 2026 and hasn’t been updated, prioritize these gaps:
- Add a heightened threat environment section — define the trigger conditions, list the procedures that activate, identify who owns the determination
- Update notification timelines with specificity — regulator name, timeline from determination, materiality standard, report format required; not generic “notify regulators promptly”
- Build a communications strategy for extended downtime — separate runbooks for regulators, customers, bank partners, and board with timing, channel, and message owner for each
- Document your backup restoration test result — not just that backups exist, but the recovery time you achieved in your most recent test and when it was conducted
- Add data retention cross-reference — confirm your IR plan links to your retention policy and includes a step to assess exposure scope against retention records at incident initiation
- Update tabletop documentation requirements — sign-in records, scenario scripts, gap findings, remediation assignments, and status tracking are all examiner-facing artifacts
The Incident Response & Breach Notification Kit includes playbooks for the most common fintech incident types, all-50-states breach notification timelines, tabletop exercise scenarios you can run immediately, and documentation templates designed to produce examiner-ready records. When your next exam asks for your IR plan and tabletop evidence, these are the files you hand over.
So What?
NYDFS’s May 21, 2026 guidance did something enforcement actions alone couldn’t: it defined proactive IR program expectations before an incident, not just compliance failures after one. For regulated entities, that changes the frame from “do we have an IR plan” to “does our IR plan address what NYDFS specifically said it would look for.”
The answer for most small and mid-size regulated entities is no. The five measures in the guidance map directly to the gaps NYDFS found in Delta Dental, and they’ll map directly to what examiners look for in your next exam. Updating your IR plan against this guidance isn’t a compliance project for next quarter. It’s exam preparation with a lead time you’re already burning.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is NYDFS's heightened cybersecurity environment guidance?
Is the heightened cybersecurity environment guidance mandatory?
What does NYDFS consider a 'heightened cybersecurity threat environment'?
What IR plan changes does the NYDFS guidance require?
What did the Delta Dental enforcement action teach us about NYDFS IR expectations?
What should I do if our IR plan hasn't been updated since the 2023 Part 500 amendments?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Incident Response & Breach Notification Kit
Step-by-step incident response playbooks and breach notification templates for all 50 states.
◆ Keep reading
Related posts.
Incident Response
NYDFS Fined Delta Dental $2.25M for an IR Plan That Couldn't Answer the Right Questions. Can Yours?
NYDFS's first cyber enforcement action of 2026 — a $2.25 million penalty against Delta Dental — wasn't about missing firewalls or unpatched servers. It was about an incident response plan that didn't address regulatory reporting obligations clearly. Here are the five gaps regulators consistently find in incident response programs at financial services firms, and how to close them before an examiner does.
Sep 14, 2026
Incident Response
CISA's CIRCIA Is Finalizing This Month. Here's What the New 72-Hour Reporting Clock Means for Your Financial Services Incident Response Program.
CISA's CIRCIA final rule — requiring 72-hour cyber incident reporting to CISA and 24-hour ransomware payment disclosure — is expected to publish in September 2026. For financial services firms, it creates a fifth notification obligation running parallel to OCC/FDIC, SEC, NYDFS, and state breach notification clocks. Here's what your IR program needs to add before the effective date.
Sep 8, 2026
Incident Response
The 36-Hour Notification Clock Doesn't Wait for Your Investigation. Here's What the OCC's June 2026 Cybersecurity Report Means for Your Incident Response Program.
The OCC's June 2026 Cybersecurity Report and NYDFS's $144M+ enforcement record make one thing clear: incident response programs designed around investigating before notifying will fail the regulatory test. Here's what your program needs to do differently.
Sep 4, 2026