NYDFS Audit Resource

NYDFS cybersecurity audit preparation: what to expect and how to organize evidence.

A NYDFS cybersecurity audit is not just a request for policies. Examiners ask for narratives, numbered evidence, governance records, technical reports, meeting preparation, and proof that the Part 500 program operates in practice.

By Brian Edelman, Founder & CEO, FCI Cyber · Last updated: September 2026

The short version

Prepare for the audit as an evidence-production project.

Recent NYDFS cybersecurity examination requests and meeting agendas show a consistent pattern: the Department wants the current policy, the governance record, the technical proof, the remediation trail, and the people who can explain how the program works. A firm that waits until the request arrives will spend the exam period reconstructing evidence under deadline pressure.

This guide is not legal advice. It is a practical preparation guide for organizing cybersecurity evidence before a NYDFS request list or examiner meeting arrives.

Request list

Expect numbered evidence requests

DFS requests typically ask for electronic copies, brief narratives, item-number file labels, and explanations for anything marked not applicable.

Meetings

Expect operational interviews

IT management and support teams should be ready to discuss topology, patching, firewalls, monitoring, mobile devices, departures, BCDR, and remediation.

Evidence

Expect proof, not intent

Policies matter, but reports, screenshots, minutes, test results, contracts, logs, and remediation records are what make the response defensible.

What the request usually asks for

The evidence categories to assemble before NYDFS asks.

The exact request varies by entity and examination scope. The recurring categories below are the areas firms should keep current, indexed, and ready to explain.

Audit areaEvidence to prepare
Applicability, Class A, exemptions, affiliatesClass A analysis if applicable, exemption support, affiliate/intercompany agreements, adopted-program documentation, and service-level agreements.
Policies and Part 500.3 program documentsInformation security, data governance, asset inventory, access control, BCDR, systems operations, network monitoring, training, application security, physical security, privacy, vendor management, risk assessment, incident response, and vulnerability management policies.
Governance and oversightCybersecurity organization chart, CISO resume/job description, outsourced CISO agreement if applicable, backup CISO plan, board expertise evidence, committee charters, meeting minutes, annual CISO reports, plans, budgets, and risk appetite documentation.
Testing, vulnerabilities, and patchingInternal and external penetration testing reports, vulnerability scans, patch installation and aging reports, vulnerability-intake process, remediation prioritization, external testing agreements, and independent review evidence.
Audit trails, monitoring, and technical controlsAudit trail controls, log integrity and retention procedures, centralized logging, security-violation reports, failed-access reports, EDR/anti-malware reports, alert handling, and monitoring ownership.
Access privileges, MFA, and email authenticationAccess policies, user and privileged access lists, remote access, MFA records, annual access-review reports, password standards, DMARC or email-authentication evidence, PAM/PIM details, and MFA exception approvals.
Risk assessment and change triggersCurrent approved risk assessment, methodology, risk criteria, mitigation and acceptance decisions, board/senior-management summaries, update triggers, new products/services, and material IT/IS changes.
Gaps, remediation, MRAs/MRIAs, and prior findingsSelf-assessments, control gap analyses, material-improvement schedules, remediation trackers, independent validation, and evidence of corrective action for previous findings or violations.
Third parties, vendors, cloud, and contractorsVendor inventory, risk ratings, due diligence, contracts, critical-vendor reviews, board reporting, third-party risk assessments, cloud provider contracts, MFA/encryption controls, and TPRM tooling.
Assets, data disposal, encryption, training, IR, and BCDRAsset inventory with owner/location/criticality/end-of-life status, secure disposal procedures, encryption standards and implementation evidence, training materials and attendance, incident response plans/playbooks, BIA, BCDR plans, tabletop/failover tests, backup restoration evidence, and unreported event lists.
IT audit and independent testingIT audit org chart, auditor resumes/training, audit committee charter/minutes, internal audit charter/manual, IT audit risk assessment, audit universe, audit plan, audit reports, exception tracking, workpapers, and audit involvement in major technology changes.
IT management, development, and operationsSuccession plans, management reports/dashboards, cyber insurance summary, GLBA monitoring reports, project/change management standards, custom software documentation, network diagrams, capacity reports, helpdesk reports, hardening standards, and system administrator responsibilities.

Examiner meetings

What your IT and support teams should be ready to discuss.

Meeting agendas often test whether the written response matches operational reality. Prepare subject-matter owners who can explain the process and point to the evidence.

Network topology

How often diagrams are updated, what triggers updates, and whether diagrams include servers, clusters, internet connections, users, DNS/core services, DMZs, data stores, VLANs, wireless networks, cloud resources, service-provider VPNs, and remote access points.

Firewall and IDS/IPS monitoring

Who monitors firewalls and IDS/IPS, how event reports are reviewed, and how firewall rules are reviewed for ongoing business need.

Patch management

How patches are applied, whether automated systems identify and patch assets, whether patch reports are generated, and whether someone independently reviews patch status.

Joiner, mover, leaver controls

Whether departure and role-change checklists ensure accounts are disabled or modified when employees leave or responsibilities change.

Mobile and personal devices

What company-issued or personal devices can access or store, plus patching, monitoring, anti-malware, remote wipe, encryption, secure wireless, and VPN controls.

BCDR and remediation

Whether disaster recovery and business continuity tests include systems and personnel, use failovers/tabletops, and produce tracked remediation plans.

Acceptable use and clean desk

Whether acceptable use covers user-activity monitoring and whether clean desk controls address sensitive papers, mobile devices, end-of-day cleanup, and locked storage.

Planning, budget, insurance, and succession

How IT/IS planning and budgets address cybersecurity, how key-person succession works, and whether cyber insurance limits are tied to a risk assessment.

Preparation plan

How to prepare before the NYDFS request arrives.

The goal is to make the eventual response mechanical: current evidence, named owners, short narratives, and no scramble to reconstruct history.

Step 1
Build a request-index evidence library.

Create folders that mirror likely request categories: governance, policies, risk assessment, testing, access, MFA, vendors, cloud, assets, monitoring, training, incident response, BCDR, audit, and remediation. Use item-number labels when responding to an actual DFS list.

Do now: for every document, capture owner, approval date, last review date, source system, and whether it supports annual certification records.
Step 2
Write the narrative before the evidence is requested.

DFS requests often ask for a brief written narrative explaining the documentation and process. The narrative should describe what the control is, who owns it, how often it is reviewed, which evidence proves it operates, and what exceptions or remediation exist.

Do now: draft one-page narratives for risk assessment, CISO oversight, access reviews, MFA, patching, vendor management, incident response, BCDR, and vulnerability management.
Step 3
Reconcile policy language to operating proof.

Policies that overpromise create audit risk. Compare each Part 500 policy to the reports and controls that prove the policy is actually enforced. If the policy says a review happens annually, identify the minutes, report, ticket, screenshot, or signoff that proves it.

Do now: map every written requirement to evidence. Where evidence is missing, create a remediation owner and target date.
Step 4
Prepare the people who will be interviewed.

An audit response can fail in the meeting even if the document folder is strong. IT management, support, cybersecurity, compliance, vendor management, and internal audit owners should know which processes they own and where the evidence lives.

Do now: run a tabletop of the examiner meeting. Ask the exact operational questions: topology, patching, firewall rules, IDS/IPS, mobile devices, access removals, DR tests, remediation, and cyber insurance.

Common mistakes

Where firms get caught unprepared.

Submitting policies without proof

A policy answers what should happen. The audit asks whether it did happen and whether the firm can prove it.

Treating N/A as a checkbox

If something is not applicable, explain why. A blank or unsupported N/A can create more questions than a complete answer.

Letting evidence live with one person

Succession and backup ownership matter. The evidence process cannot depend on one CISO, IT manager, vendor, or spreadsheet owner.

Forgetting remediation history

Findings, MRAs, MRIAs, exceptions, and prior audit issues need tracked corrective action and independent validation where applicable.

Not preparing vendors and cloud records

DFS asks about service providers, contracts, due diligence, cloud use, MFA, encryption, and critical-vendor oversight.

Waiting for the meeting agenda

The operational questions are predictable. The firm should be ready to discuss them before the examiner schedules the meeting.

NYDFS audit FAQ

Common questions before a DFS cybersecurity audit.

What does NYDFS ask for in a cybersecurity audit?

NYDFS commonly asks for Part 500 policies, governance records, CISO reports, board and committee minutes, risk assessments, penetration testing and vulnerability evidence, patch reports, access and MFA records, third-party and cloud documentation, incident response and BCDR evidence, training records, and remediation tracking.

How should a firm prepare its NYDFS audit response?

Create a numbered evidence index that mirrors the request list, label every file by item number, include a short narrative for each item, explain any not-applicable responses, and assign owners for governance, IT, cybersecurity, vendor, incident response, and audit evidence.

What should a firm expect in NYDFS IT management meetings?

Firms should be ready to discuss IT succession planning, budgeting, acceptable use and monitoring, clean desk controls, cyber insurance, network topology, firewall rule reviews, IDS/IPS monitoring, patch management, employee departures, mobile devices, and disaster recovery and business continuity testing.

What is the biggest mistake firms make before a NYDFS cybersecurity audit?

The biggest mistake is treating the audit as a policy collection exercise. NYDFS requests operational proof: reports, screenshots, logs, meeting minutes, contracts, test results, remediation records, and evidence that controls are reviewed and maintained over time.

How FCI helps
The documentation should already exist before the audit starts.

FCI helps financial-services firms enforce cybersecurity controls and produce the evidence that maps those controls to regulatory expectations. The FCI Portal centralizes endpoint status, user controls, monitoring records, remediation evidence, and compliance reporting so the audit response is assembled from an operating program, not rebuilt from scratch.

For NYDFS preparation, the practical question is simple: if DFS sent a request list today, could your firm produce the policy, the proof, the owner, the review date, and the remediation trail for each item?

Best next step: use the 16-question assessment to identify evidence gaps, then run a 30-minute gap analysis to map those gaps to Part 500 audit categories.

Prepare before NYDFS asks.

Start with the readiness assessment, review the Part 500 requirements, or ask FCI to identify which audit evidence your firm can produce today and which items would require a scramble.