Included in All Plans

Security Practices

Built-in security tools that go beyond checkbox compliance. Run phishing tests, assess vendors, track vulnerabilities, and manage incidents.

Security Tools Built for Compliance

Every tool maps directly to a NY DFS requirement, so you are building real security while satisfying your regulator.

Phishing Simulation

Run phishing campaigns from 26 realistic templates with credential-harvest landing pages and department targeting. Anyone who clicks lands on an education page. Supports Section 500.14.

Vendor Risk Assessments

Send vendors a secure questionnaire link, track a weighted risk score over time, and watch contract and BAA expiry dates. Supports Section 500.11.

Vulnerability Tracking

Track vulnerability remediation across your environment. Prioritize by severity. Supports Section 500.05.

Risk Register

Identify, score, and track risks to your information systems. Supports Section 500.09.

Incident Tracking

Log and track security incidents, with a 72-hour DFS notice clock from your determination, a DFS update log, and extortion-payment deadlines. Supports Sections 500.16 and 500.17.

Security Training

36 text and scenario-based security awareness courses, each with a quiz, plus completion tracking.

Mapped to NY DFS Requirements

Each security practice tool supports specific sections of 23 NYCRR 500.

500.05

Vulnerability Management

Covered by: Vulnerability Tracking

500.09

Risk Assessment

Covered by: Risk Register

500.11

Third-Party Service Provider Security

Covered by: Vendor Risk Assessments

500.14

Monitoring & Training

Covered by: Phishing Simulation & Security Training

500.16

Incident Response & Business Continuity

Covered by: Incident Tracking

500.17

Notices to Superintendent

Covered by: Incident Tracking (72-hour clock, extortion deadlines)

Beyond Checkbox Compliance

These are not just compliance checkboxes. Each tool helps you build real security practices that protect your business and satisfy auditors.

  • Phishing campaigns that send anyone who clicks to an education page
  • Vendor assessments that identify real supply chain risks
  • Vulnerability tracking that drives remediation
  • Incident workflows with a 72-hour DFS notice clock from your determination
  • Risk scoring that prioritizes what matters most

What's Included

Phishing Simulation

Run phishing campaigns from 26 realistic templates with credential-harvest landing pages and department targeting. Anyone who clicks lands on an education page. Supports Section 500.14.

Vendor Risk Assessments

Send vendors a secure questionnaire link, track a weighted risk score over time, and watch contract and BAA expiry dates. Supports Section 500.11.

Vulnerability Tracking

Track vulnerability remediation across your environment. Prioritize by severity. Supports Section 500.05.

Risk Register

Identify, score, and track risks to your information systems. Supports Section 500.09.

Incident Tracking

Log and track security incidents, with a 72-hour DFS notice clock from your determination, a DFS update log, and extortion-payment deadlines. Supports Sections 500.16 and 500.17.

Security Training

36 text and scenario-based security awareness courses, each with a quiz, plus completion tracking.

Build Real Security Practices Today

Request a demo and begin testing, assessing, and tracking security across your organization.