P&CNew Yorkmedium
A New York-domiciled P&C insurer discovers a ransomware attack that encrypted policyholder PII. Under 23 NYCRR 500.17, what notice obligation runs to the Superintendent, and within what time?
Notice to the Superintendent as promptly as possible but in no event later than 72 hours after determination that a cybersecurity event has occurred
BAnnual aggregate disclosure only, due each April 15 with the Form ACR
CNo notice required unless more than 500 New Yorkers are affected
DNotice within 30 calendar days of confirming the breach
Why this is the answer
23 NYCRR 500.17(a) imposes a strict 72-hour reporting clock that begins when the Covered Entity 'determines' a reportable cybersecurity event has occurred — not when the event itself happens. Reportable events include those that require notice to any other government regulator and those that have a reasonable likelihood of materially harming any material part of the Covered Entity's operations. The 2023 amendments added § 500.17(c), requiring notice of ransom/extortion payments within 24 hours and a follow-up explanation within 30 days. Notice is filed through the DFS Cybersecurity Portal.
Studying for the New York Property & Casualty exam?
This question comes from our P&C bank. Take a free practice test — no signup.
