TL;DR: NYDFS fined eight insurance companies $14.2 million after breaches exposed data on more than 825,000 people, while upcoming Part 500 changes will require MFA for any individual accessing any information system and a maintained asset inventory, according to Push Security. Policy-based MFA alone is no longer enough; organisations must prove account-level coverage across every login path.
Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “What the expansion of NYCRR Part 500 means for MFA regulation and compliance”.
By the numbers:
- Push Security data says 2 in 5 accounts are missing MFA.
Key questions
Q: What breaks when MFA is only validated at the IdP and not per account?
A: IdP-level validation can miss local passwords, alternate logins, and unmanaged app paths that still allow access without MFA.
Q: Why do shadow SaaS apps create IAM risk?
A: Shadow SaaS creates IAM risk because access can exist outside approved onboarding, review, and offboarding processes.
Q: How should security teams prove MFA compliance across all applications?
A: They should verify MFA at the account and login-method level for every in-scope application, not just at the identity provider.
Practitioner guidance
- Validate MFA at the account level Build evidence of which authentication method each user, admin, and third-party account actually uses, then compare that to policy claims rather than assuming the IdP view is complete.
- Inventory every in-scope application Maintain a current list of internet-accessible, cloud, SaaS, and outsourced systems so the MFA requirement can be tested against the full estate, including unmanaged tools.
- Remove alternate login paths Disable local password authentication, legacy logins, and any spare access method that lets users bypass SSO or MFA after onboarding.
Bottom line: NYDFS enforcement shows that MFA failures are now treated as operational control gaps, not as documentation issues.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Enterprise-wide MFA validation is now a proof problem, not a policy problem: NYDFS is signalling that organisations must demonstrate actual coverage across every access path, including local, cloud, and shadow application logins. A central policy that says MFA is enabled no longer settles the question. For identity programmes, the control has shifted from configuration intent to verifiable login behaviour.
A question worth separating out:
Q: Should organisations prioritise asset inventory or MFA rollout first?
A: They should treat them as a single programme because MFA coverage cannot be validated without knowing the full system estate. In practice, discovery should start immediately and continue alongside enforcement, especially where shadow IT and third-party services are present. Without inventory, MFA claims are incomplete and difficult to defend.
👉 Read our full editorial: NYDFS is forcing enterprise-wide MFA validation, not policy theater