Cybersecurity for financial firms.
Protect customer data, meet NYSDFS, and answer what the examiners and your customers ask.
We help you work out what applies to you
Part 500 applies if you are licensed, registered, or chartered under New York banking, insurance, or financial services law. How much of it applies depends on your size and a few other things, and helping you work that out is where we start. From there OrbitalFire handles the hard cybersecurity work for smaller firms.
What smaller firms find hard is rarely the controls themselves. It is documenting the decisions and explaining why a given approach suits your environment, in a way that still holds up when somebody reads it back to you a year later. That is the part we take off you.
What we help with
The annual cycle, in order
Know where you stand
The risk assessment Part 500 requires, scored, with findings ranked by risk rather than by section number.
Write it down properly
The cybersecurity policy work that follows from the assessment, matching how the firm actually operates.
Document the controls
Compensating controls and the decisions behind them, written up so the reasoning holds under review rather than only the deployment being on record.
File the certification
Certification and exemption reviews turned into predictable check-ins rather than a fire drill in the weeks before the deadline.
And running alongside it
Your vendors, and theirs
Third Party Risk Management for the questionnaires you receive and the ones you send.
Training your people will finish
Awareness Training and Phishing Testing, which Part 500 expects and examiners ask to see evidence of.
The areas examiners return to
Vulnerability Management, asset inventory, and Incident Response planning, which come up in examination after examination.
Examination support
We have been through this with customers and know what examiners look for. The earlier we are involved, the better it goes.
Your customers ask many of the same questions your regulator does, just on a different form. The work that makes you defensible to NYSDFS is the work that gets a prospect's security questionnaire off your desk.
The qualified individual, without the headcount
Part 500 requires that a qualified individual oversee and implement your cybersecurity work and report annually to your board. That role can be filled by an internal CISO or an external firm, and OrbitalFire fills it for a number of covered entities.
What cannot be delegated is the certification itself. A senior officer of your firm puts their name on the annual compliance statement, and with it comes accountability for everything that certification represents. Our job is to make sure that when they sign, the documentation behind it is real.
Does Part 500 apply to us?
It applies to entities licensed, registered, or chartered under New York banking, insurance, or financial services law, which covers investment advisers, community banks, insurance companies, and licensed lenders among others. Smaller firms can file for a limited exemption based on headcount, revenue, and year-end assets. It has to be filed rather than assumed, and it reduces what applies rather than removing it.
Can OrbitalFire be our qualified individual?
Yes. Part 500 allows the role to be filled by an affiliate or a third party, and we fill it for a number of covered entities. What cannot be delegated is the annual certification, which a senior officer of your firm signs.
What do examiners actually look for?
Documentation, more than tooling. Decisions recorded at the time, a scope you can defend, and an explanation of why a given control is appropriate for your environment. A control that is deployed but undocumented is the one that causes trouble.
We think we are exempt. Does that end it?
No. A limited exemption reduces which sections apply rather than removing the obligation, and which sections you keep depends on your situation. It also has to be revisited as the firm changes, so an exemption that fit three years ago may not fit now. We run exemption reviews as part of the annual cycle, and work out what is still yours.
What usually goes wrong with controls?
Rarely the implementation itself. We regularly see teams struggle to explain why a given approach suits their environment. We help align that decision with risk, documentation, and leadership intent, so the control is defensible and not only deployed.
Tell us about your business.
A half-hour conversation about what you're being asked for and where you actually stand. If we can help, you'll have a proposal usually within a day.
Not ready to talk? Check your readiness in five minutes and see where to start.