NYDFS Vishing Advisory: Part 500 Training Expectations

Rachel Andersen··5 min read
New York financial district offices representing NYDFS-regulated entities subject to Part 500 training requirements

Regulatory guidance on security training usually stays comfortably generic: train your people, raise awareness, repeat annually. In 2026, the New York State Department of Financial Services broke that pattern. In a February industry letter, the regulator described a specific social-engineering campaign, attackers phoning employees while impersonating IT help desks and service providers, and directed regulated entities to train their people against exactly those tactics. For covered banks, insurers, and financial services companies, training staff on vishing is no longer a best practice. It is a written supervisory expectation.

The 2026 Advisories: A Regulator Names the Attack

On 6 February 2026, NYDFS issued a cybersecurity advisory on targeted vishing attacks in which threat actors impersonate IT help desks and service providers to manipulate employees over the phone. The letter directs regulated entities to provide targeted awareness training on these tactics. The precision is what makes this letter unusual: the regulator names the pretext, help-desk and service-provider impersonation, and prescribes the countermeasure, training aimed at that pretext specifically.

NYDFS followed up on 21 May 2026 with guidance on measures regulated entities should consider in a heightened cybersecurity threat environment. Two cybersecurity industry letters inside four months is a clear signal of elevated supervisory attention, and examiners routinely treat such letters as a preview of the questions they will ask. An entity that cannot show how it responded to the February advisory should expect that gap to surface.

Part 500 Is Now Fully in Effect

The advisories land on top of a regulation that finished phasing in only last November. The final provisions of the amended Part 500 took effect on 1 November 2025, including multi-factor authentication for any user accessing any information system under Section 500.12, and written asset-inventory policies under Section 500.13(a). As Hogan Lovells noted in its coverage, the first annual certification covering these provisions was due on 15 April 2026, meaning senior officers have already attested to compliance with the complete rule.

The training baseline sits in Section 500.14(a)(3), which requires annual cybersecurity awareness training that includes social engineering, for all personnel. Read the rule and the February advisory together and the expectation sharpens considerably: annual social-engineering training is the floor set by regulation, and targeted vishing content is the layer the regulator has now explicitly asked for. A generic annual module that never mentions phone-based impersonation of the IT help desk no longer matches what NYDFS has put in writing.

There is a technical thread here too. Universal MFA under Section 500.12 is precisely the control help-desk vishing is built to defeat, whether by talking an employee into reading out a code, approving a push notification, or convincing the help desk itself to reset credentials or re-enroll a device. The controls and the training are two halves of the same defense.

Enforcement Has Real Money Behind It

None of this is theoretical. NYDFS levied 63.3 million dollars in Part 500 penalties across 2024 and 2025, and observers expect the 2026 examination cycle to be the most comprehensive yet, the first to test the fully effective amended rule end to end. Past enforcement actions have repeatedly cited gaps between what entities certified and what they could evidence. With the advisories on record, training programs are a natural target for that scrutiny: examiners can simply ask what changed after 6 February 2026, and dated records will answer the question one way or the other.

Training to the Advisory: What Good Looks Like

It is worth pausing on why attackers moved to the phone in the first place. Years of investment in email security have made classic phishing harder: attachments get sandboxed, links get rewritten, and suspicious messages get quarantined before anyone sees them. A voice call bypasses that entire stack. There is no URL to scan and no payload to detonate, only a persuasive human with a plausible pretext and, increasingly, an AI-cloned voice to go with it. The only control standing between a convincing caller and a credential reset is a trained person following a verification procedure, which is precisely why NYDFS aimed its advisory at training rather than technology.

Responding well therefore means training for the named attack, not just refreshing the annual module. Practical components include:

  • Help-desk vishing simulations. Run scenarios in both directions: employees receiving calls from a fake IT help desk, and help-desk staff receiving convincing password-reset or MFA re-enrollment requests from a fake employee. The second direction is where many real intrusions start.
  • MFA-abuse awareness. Teach number-matching, why push-fatigue prompts must be rejected and reported, and the iron rule that no legitimate IT team ever asks anyone to read out a one-time code.
  • Verification rituals. Establish and rehearse call-back procedures on independently known numbers for any request touching credentials, MFA, or payment details, so that verifying a caller is a routine act rather than an awkward exception.
  • Exam-ready records. Keep dated completion data, simulation results, and remediation follow-ups mapped to Section 500.14(a)(3) and to the February advisory, so the response to the regulator's letter is demonstrable, not anecdotal.

This is where a structured program pays for itself. Security awareness training combined with realistic vishing and phishing simulations produces exactly the evidence trail an examiner will ask for, and platforms like empowsec generate those dated records as a by-product of running the program rather than as a separate documentation project.

Key Takeaways

  • NYDFS named the attack. The 6 February 2026 advisory addresses vishing that impersonates IT help desks and service providers, and directs regulated entities to deliver targeted awareness training on those tactics.
  • Part 500 is fully effective. Universal MFA under Section 500.12 and asset-inventory policies under Section 500.13(a) took effect 1 November 2025, with the first covering certification due 15 April 2026.
  • Annual social-engineering training is mandatory. Section 500.14(a)(3) requires it for all personnel, and the advisory tells you what this year's content must include.
  • Enforcement is well funded. 63.3 million dollars in penalties across 2024 and 2025, with the 2026 exam cycle expected to be the most comprehensive yet.
  • Train both sides of the help desk. Simulate calls into and out of IT support, drill verification call-backs, and keep dated records that tie the program to the regulator's letters.
Share: