Built for NY DFS Section 500.05

Security Assessments for Small Business

Find vulnerabilities before attackers do. Our penetration testing and vulnerability assessments meet NY DFS requirements at small business prices.

NY DFS Requirements

Section 500.05 requires annual penetration testing and risk-based vulnerability scanning:

500.05(a)(1)Penetration Testing

At least annual testing from inside and outside your systems by a qualified internal or external party

500.05(a)(2)Vulnerability Scanning

Automated scans plus manual review, at a frequency set by your risk assessment

Assessment Services

Comprehensive security testing to identify vulnerabilities and meet compliance requirements.

Penetration Testing

DFS 500.05(a)(1)

Simulated cyber attacks to identify security weaknesses before real attackers do.

External Penetration Test

External vulnerability assessment and network perimeter testing of your internet-facing systems, with a detailed report.

Starting at $1,500

Internal Penetration Test

Test your internal network from an insider threat perspective. NY DFS requires testing from both inside and outside your system boundaries.

Custom quote

Web Application Test

Deep dive into your web applications for OWASP Top 10 vulnerabilities.

Custom quote

Vulnerability Scanning

DFS 500.05(a)(2)

Automated scans to identify known vulnerabilities across your environment, delivered as a managed service.

Quarterly

External scanning with monthly scans and quarterly reports.

$750/quarter

Annual

Internal and external scanning with weekly scans and continuous monitoring.

$2,400/year

Web Application Scan

Automated scanning of web applications for common vulnerabilities.

Custom quote

Risk Assessment

DFS 500.09

Identify, analyze, and prioritize cybersecurity risks to your business.

Initial Risk Assessment

Comprehensive baseline assessment of your security posture.

Starting at $2,500

Annual Risk Review

Annual review and update of your risk assessment, as NY DFS 500.09 requires.

Starting at $1,500

Risk Assessment + Remediation

Assessment plus hands-on help implementing fixes.

Starting at $5,000

Social Engineering Tests

Test your human firewall with realistic social engineering simulations.

Phishing Simulations

Realistic phishing simulations on the Buffalo Sentinel platform, with results by user and department. We can run them for you as a managed service.

Included in every platform plan (from $500/yr)

Vishing (Voice Phishing)

Phone-based social engineering tests targeting your staff.

Starting at $1,000

Physical Security Test

Attempt to gain unauthorized physical access to your facilities.

Starting at $2,000

Our Assessment Process

A structured approach to identify and address security vulnerabilities.

1

Scoping

Define the assessment scope, targets, and rules of engagement.

2

Testing

Conduct the assessment using industry-standard methodologies.

3

Analysis

Analyze findings and determine risk levels and business impact.

4

Reporting

Deliver detailed report with findings, risk ratings, and remediation steps.

5

Remediation

Optional hands-on support to fix identified vulnerabilities.

Audit-Ready Deliverables

Every assessment includes detailed documentation that satisfies NY DFS examination requirements:

Executive summary for leadership
Technical findings with severity ratings
Proof-of-concept evidence
Remediation recommendations
Risk-ranked priority list
Re-test verification (optional)

Sample Report Contents

Executive Summary2-3 pages
Methodology & Scope3-5 pages
Findings & Evidence10-30 pages
Risk RatingsCVSS scoring
Remediation GuideStep-by-step
AppendicesRaw scan data

Schedule Your Security Assessment

Get a free scoping call to determine the right assessment for your business and budget.