Overview
According to the NYDFS’s latest amendments to the Cybersecurity Regulation, a BFSI company must undergo general risk assessment at least once a year, penetration testing at least once a year, and vulnerability assessment — at least twice a year. While AWS offers some baseline measures for meeting NYDFS guidelines, it is each organization’s responsibility to configure and operate its cloud environment in full compliance with NYDFS. ScienceSoft determines what NYDFS requirements are relevant to your particular case and runs a comprehensive assessment covering technical, administrative, and physical security controls to examine NYDFS compliance on both AWS’s and your organization’s side.
Depending on your needs, our assessment can cover:
- AWS infrastructure review, including computing resources, networking, data storage and management, security mechanisms, and AWS-hosted apps.
- Penetration testing, vulnerability assessment, automated and manual code review.
- Assessment of administrative safeguards, including internal policies regulating IT asset management, customer data access and governance, security risk management and incident response, data backup and disaster recovery procedures.
- Assessment of technical safeguards, including identity and access controls, audit logging, data encryption, and data integrity controls in the cloud.
- Assessment of physical safeguards, including the isolation of dedicated AWS cloud instances and access to physical devices and workstations connected to the cloud.
- Examination of BFSI employees’ knowledge of NYDFS compliance and cyber hygiene.
After the audit, we deliver a comprehensive report covering the revealed NYDFS compliance gaps and a detailed remediation plan. You get a clear checklist of corrective actions required to achieve your organization’s full compliance with the NYDFS Cybersecurity Regulation and pragmatic advice on implementing the necessary steps quickly and cost-effectively. If you need practical help with implementing the improvements, ScienceSoft’s AWS-certified engineers, NYDFS consultants, and cybersecurity specialists are ready to reconfigure your cloud environment, refine the security program, redesign the data governance framework, and establish additional cybersecurity mechanisms in accordance with the NYDFS requirements.
Highlights
- In NYDFS compliance services since the framework inception in 2017; financial IT and compliance consultants with 5–20 years of experience who speak your language and know the nuances of NYDFS application in real-world BFSI scenarios.
- AWS-certified experts, such as AWS Certified Solution Architects and AWS Certified SysOps Administrators, who help BFSI organizations create and maintain secure AWS environments.
- Certified Ethical Hackers proficient in holistic penetration testing (black, gray, and white box testing, social engineering) to find all potential loopholes in your IT security.
Details
Unlock automation with AI agent solutions

Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Support
Vendor support
Contact us at +1 214 306 6837 or contact@scnsoft.com .