Security Practices
Built-in security tools that go beyond checkbox compliance. Run phishing tests, assess vendors, track vulnerabilities, and manage incidents.
Security Tools Built for Compliance
Every tool maps directly to a NY DFS requirement, so you are building real security while satisfying your regulator.
Phishing Simulation
Run phishing campaigns from 26 realistic templates with credential-harvest landing pages and department targeting. Anyone who clicks lands on an education page. Supports Section 500.14.
Vendor Risk Assessments
Send vendors a secure questionnaire link, track a weighted risk score over time, and watch contract and BAA expiry dates. Supports Section 500.11.
Vulnerability Tracking
Track vulnerability remediation across your environment. Prioritize by severity. Supports Section 500.05.
Risk Register
Identify, score, and track risks to your information systems. Supports Section 500.09.
Incident Tracking
Log and track security incidents, with a 72-hour DFS notice clock from your determination, a DFS update log, and extortion-payment deadlines. Supports Sections 500.16 and 500.17.
Security Training
36 text and scenario-based security awareness courses, each with a quiz, plus completion tracking.
Mapped to NY DFS Requirements
Each security practice tool supports specific sections of 23 NYCRR 500.
Vulnerability Management
Covered by: Vulnerability Tracking
Risk Assessment
Covered by: Risk Register
Third-Party Service Provider Security
Covered by: Vendor Risk Assessments
Monitoring & Training
Covered by: Phishing Simulation & Security Training
Incident Response & Business Continuity
Covered by: Incident Tracking
Notices to Superintendent
Covered by: Incident Tracking (72-hour clock, extortion deadlines)
Beyond Checkbox Compliance
These are not just compliance checkboxes. Each tool helps you build real security practices that protect your business and satisfy auditors.
- Phishing campaigns that send anyone who clicks to an education page
- Vendor assessments that identify real supply chain risks
- Vulnerability tracking that drives remediation
- Incident workflows with a 72-hour DFS notice clock from your determination
- Risk scoring that prioritizes what matters most
What's Included
Phishing Simulation
Run phishing campaigns from 26 realistic templates with credential-harvest landing pages and department targeting. Anyone who clicks lands on an education page. Supports Section 500.14.
Vendor Risk Assessments
Send vendors a secure questionnaire link, track a weighted risk score over time, and watch contract and BAA expiry dates. Supports Section 500.11.
Vulnerability Tracking
Track vulnerability remediation across your environment. Prioritize by severity. Supports Section 500.05.
Risk Register
Identify, score, and track risks to your information systems. Supports Section 500.09.
Incident Tracking
Log and track security incidents, with a 72-hour DFS notice clock from your determination, a DFS update log, and extortion-payment deadlines. Supports Sections 500.16 and 500.17.
Security Training
36 text and scenario-based security awareness courses, each with a quiz, plus completion tracking.
Build Real Security Practices Today
Request a demo and begin testing, assessing, and tracking security across your organization.