Endpoint Index
Research / Industry guide

Endpoint Security for Insurance Agencies: What NYDFS Part 500 Requires at Each Size

Updated · data as of · 6 min read

Contents
  1. Executive summary
  2. Three tiers, three shopping lists
  3. The limited exemption, read closely
  4. Agencies without the exemption: add email filtering
  5. Class A: rare for an agency, strict if it applies
  6. Ransomware and the 24-hour clock
  7. What should each agency buy?
  8. Mistakes agencies make
  9. Frequently asked questions
  10. Methodology and caveats
  11. Sources

Executive summary

A New York insurance agency should work out its Part 500 tier before buying anything, because the tier decides the product: an agency with the limited exemption needs centrally managed malware protection and multi-factor authentication, an agency without it needs malware controls that also filter email and web traffic, and only a Class A company must run EDR. The middle tier is the one agencies under-buy. Section 500.14(a)(2) of 23 NYCRR asks for "risk-based controls designed to protect against malicious code, including those that monitor and filter web traffic and electronic mail to block malicious content." Endpoint antivirus alone does not filter email.

Our records (17 products, vendor-checked 2026-10-02) show 8 with EDR, while only 2 include email security and 6 more sell it as an add-on to the endpoint agent. Every covered agency, exempt or not, must notify the Department of Financial Services within 72 hours of determining that a cybersecurity incident has occurred, and within 24 hours of paying a ransom (500.17).

Three tiers, three shopping lists

Tier Test Endpoint obligation What to buy
Limited exemption Any one of: fewer than 20 employees and independent contractors; under $7.5 million gross annual revenue in each of the last three fiscal years; under $15 million year-end total assets (500.19(a)) Exempt from 500.14(a)(1), (a)(2) and (b); the risk assessment still applies Centrally managed endpoint protection, plus MFA as 500.12 requires
Covered, not exempt Licensed by DFS and over every exemption threshold Monitor authorised users' activity (500.14(a)(1)) and protect against malicious code, including web and email filtering (500.14(a)(2)) Endpoint protection with email security, EDR preferred
Class A At least $20 million gross annual revenue in each of the last two fiscal years, plus over 2,000 employees or over $1 billion revenue (500.1) EDR to monitor anomalous activity including lateral movement, and centralised logging and alerting (500.14(b)) EDR feeding a SIEM

Each exemption test brings in affiliates as well as the agency itself, so a small agency inside a larger group may not be as small as it looks.

The limited exemption, read closely

500.19(a) exempts qualifying agencies from sections 500.4, 500.5, 500.6, 500.8, 500.10, 500.14(a)(1), (a)(2) and (b), 500.15 and 500.16. That is a long list, and it is easy to read it as "nothing applies". It is not. An exempt agency still runs a cybersecurity programme and a risk assessment, still files its annual certification or acknowledgment by 15 April, still reports incidents within 72 hours, and under 500.12 still uses MFA for remote access to its systems, for remote access to third-party applications holding nonpublic information, and for all privileged accounts.

For an exempt agency, endpoint protection is not named, but a risk assessment that leaves client policy data on unprotected PCs is hard to defend. The sensible buy is cheap, tested and centrally managed: Microsoft Defender for Business ($36.00 per user per year) or Bitdefender GravityZone Business Security ($38.50 per endpoint per year), both with current lab results on their product pages. The small-business cost report sets their prices against the rest of the market.

A sole agent working under an agency's or carrier's cybersecurity programme may not need a separate programme at all (500.19(b)).

Agencies without the exemption: add email filtering

This table is limited to products that include email security or sell it as an add-on to the same console, because 500.14(a)(2) names email filtering and most agencies' malicious code arrives by email. It also shows which of them record activity (EDR, useful for 500.14(a)(1)) and which include a 24/7 team.

ProductEmail securityEDR24/7 managed response
Bitdefender GravityZone Business SecurityAdd-onNot offeredNot offered
ESET PROTECT CoreAdd-onNot offeredNot offered
Bitdefender GravityZone Business Security PremiumAdd-onNot offeredNot offered
Acronis Cyber ProtectAdd-onNot offeredNot offered
ThreatDown EliteAdd-onIncludedIncluded
ThreatDown AdvancedAdd-onIncludedNot offered
CynetIncludedIncludedIncluded
Trend Micro Worry-Free Services AdvancedIncludedNot offeredNot offered
From each vendor's product and pricing pages. "Add-on" means available at extra cost. Follow a product link for sources and verification dates.

An agency on Microsoft 365 can meet the email part through Microsoft's own mail filtering instead, and pair it with any endpoint product. What matters for the examiner is that both controls exist and are documented.

Class A: rare for an agency, strict if it applies

Class A thresholds are high enough that few independent agencies reach them. A Class A company needs EDR plus centralised logging and alerting, unless its CISO approves equivalent controls in writing. See EDR products with SIEM integration for which products feed which log platforms.

Ransomware and the 24-hour clock

If an agency pays an extortion demand, 500.17(c) requires notice to DFS within 24 hours of the payment and a written explanation within 30 days, including the alternatives considered. Ransomware rollback, where a product includes it, is one of those alternatives, and so are tested backups. Being able to say "we could restore without paying" is the better position.

What should each agency buy?

Sole agent or two-person agency. Check 500.19(b) first. If you still need your own programme, one centrally managed endpoint product plus MFA on email and carrier portals covers the risk assessment's obvious findings.

Agency of 10 to 19 people. Exempt on headcount. Buy a low-cost managed product, turn on MFA for privileged accounts, and document both in the risk assessment you must still keep.

Agency of 20 to 60 people, over the revenue test. Not exempt. Buy endpoint protection with email filtering from the table above, or pair Microsoft's email filtering with your endpoint product, and prefer EDR for the activity-monitoring duty.

Mistakes agencies make

  • Treating the limited exemption as a full exemption. MFA, incident notice and the annual filing remain.
  • Measuring size without affiliates. The exemption tests count affiliates too.
  • Buying endpoint protection with no email filtering when not exempt, then being unable to show 500.14(a)(2)'s email control.
  • Paying a ransom without the 24-hour notice. The clock runs from the payment, not the incident.

Frequently asked questions

Does Part 500 cover independent insurance agents?

Agents and brokers licensed by DFS are covered entities. An agent covered by the cybersecurity programme of their agency or carrier need not build a separate one (500.19(b)).

Must a small agency run EDR under NYDFS?

Only Class A companies must (500.14(b)). A non-exempt agency must monitor authorised users' activity and block malicious code, for which EDR is the practical tool; an exempt agency has neither duty.

What are the limited exemption thresholds?

Fewer than 20 employees and independent contractors, or under $7.5 million gross annual revenue in each of the last three fiscal years, or under $15 million in year-end total assets, each including affiliates (500.19(a)).

What must an agency tell DFS after paying a ransom?

Notice within 24 hours of the payment, and within 30 days a written description of why payment was necessary, and the alternatives to payment that were considered (500.17(c)).

Methodology and caveats

Sections 500.1, 500.12, 500.14, 500.17 and 500.19 of 23 NYCRR were checked word for word on 30 September 2026. The capability table's eight products were selected because each lists email security as included or as an add-on in the Endpoint Index database; other values come from the same database with vendor sources and dates.

Your agency's status under Part 500 is a legal question for counsel or DFS. This guide covers what to buy once you know it.

Sources

  1. Legal Information Institute. 23 NYCRR 500.14, Monitoring and training. Checked 30 September 2026.
  2. Legal Information Institute. 23 NYCRR 500.19, Exemptions. Checked 30 September 2026.
  3. Legal Information Institute. 23 NYCRR 500.12, Multi-factor authentication. Checked 30 September 2026.
  4. Legal Information Institute. 23 NYCRR 500.17, Notices to superintendent. Checked 30 September 2026.
  5. Legal Information Institute. 23 NYCRR 500.1, Definitions. Checked 30 September 2026.
  6. New York State Department of Financial Services. Cybersecurity resource center.
  7. Endpoint Index records for the eight email-capable products and the two low-cost options named (2026-10-02).

Related research

All research ›

Methodology · Report an error · Vendor not listed? Get listed