Built for NY DFS Section 500.10

Cybersecurity Services for Small Business

Incident response coordination, business-hours monitoring and alerting, and remediation help, priced for small businesses. Meet NY DFS cybersecurity requirements with hands-on help from our team.

Why Small Businesses Choose Us

No long-term contracts required
Built for teams of 1-25
Direct access to our security team during business hours
Monthly security reports for auditors
NY DFS compliance documentation included
Based in Western New York
NY DFS specialists
Plain-language findings and next steps
Backed by our own compliance platform

Cybersecurity Services

Comprehensive security services to protect your business and meet NY DFS requirements.

Monitoring & Alerting

Business-hours monitoring of your endpoints and Microsoft 365 environment, with alerts reviewed and followed up by our team.

  • Business-hours alert review
  • Endpoint protection (EDR) alert follow-up
  • Microsoft 365 security alert review
  • Antivirus, firewall, and encryption status checks
  • Monthly security summary

Incident Response Coordination

When something goes wrong, we coordinate containment, cleanup, and recovery with your team and vendors.

  • Incident triage & prioritization
  • Containment and recovery coordination
  • Malware removal
  • Root cause analysis
  • Post-incident report and DFS notification support

Remediation Support

Hands-on help fixing the issues found by scans, assessments, and your compliance dashboard.

  • Patch and configuration fixes
  • BitLocker and firewall remediation
  • MFA rollout assistance
  • Vulnerability remediation tracking
  • Records of completed fixes

Incident Response Planning

Written plans and annual testing to meet NY DFS 500.16.

  • Written incident response plan
  • Business continuity and disaster recovery plan
  • Annual tabletop exercise
  • Contact and escalation lists
  • Plan updates as your business changes

Meet NY DFS Cybersecurity Requirements

NY DFS 23 NYCRR 500 requires covered entities to maintain a cybersecurity program. Our services help you meet these specific requirements:

Learn More About NY DFS Compliance
500.05

Vulnerability Management

Annual penetration testing, automated vulnerability scans at a risk-based frequency, and risk-prioritized remediation.

500.06

Audit Trail

Maintain audit trails to detect and respond to cybersecurity events.

500.10

Cybersecurity Personnel

Qualified cybersecurity personnel or third-party service provider.

500.16

Incident Response & Business Continuity

Written incident response and business continuity plans, tested at least annually.

500.17

Notification Requirements

Notify DFS within 72 hours after determining a cybersecurity incident occurred, and within 24 hours of any extortion payment.

Protect Your Business Today

Schedule a free consultation and see how our cybersecurity services can help protect your business.