23 NYCRR 500 · CYBERSECURITY RISK ASSESSMENT

See what a hacker
already knows about
your agency.

A Motiva Risk Assessment scores your exposure, shows you the
exact gaps a DFS examiner would flag, and proves what an
attacker could reach today. Complimentary. No obligation.
Your Risk Assessment Request is Confirmed! 🎉
We have received your details. Our team is already preparing your external exposure scan.

Want to skip the wait?
Schedule your 30-minute confidential review directly with Walter Contreras, to walk through your findings together.
Oops! Something went wrong while submitting the form.

30 min · Confidential · No obligation

THIS IS FOR YOU

Why agencies fail DFS reviews

DFS doesn't just ask if you have cybersecurity in place — they ask you to prove it. The number
one item they request is a cybersecurity risk assessment.
Most agencies struggle to produce:
Documented risk assessment results
Proof of MFA enforcement across all access points
Employee cybersecurity training records
Find the gaps before DFS does.
When this evidence isn't readily available, audits
become stressful and risky. This assessment surfaces
those gaps early — while you still have time to close
them.
THE LOGIC BEHIND THE ASSESSMENT

How we do it, and why it works

We look at your agency the way an attacker does. Most breaches don't start with sophisticated
hacking; they start with a person and a password. So that's where we start too.
91%
of cyberattacks begin with a phishing email. One click can put an attacker inside your agency, with the same access your employee has.
1 in 5
1
Look from the outside in
We map what an attacker sees: exposed services, leaked credentials, and email that can be spoofed — before anyone touches your network.
2
Test where people are weakest
We check for reused and breached passwords, stolen Microsoft 365 sessions, and accounts with more access than they should have.
3
Score it against the standard
Every finding is mapped to a recognized national framework and to 23 NYCRR 500, so your results line up with what a DFS examiner expects.
OUR FRAMEWORK

Structured on the NIST Cybersecurity
Framework

So your results map directly to what regulators and examiners expect to see.
What is NIST?
NIST — the National Institute of Standards and Technology — is a U.S. federal agency within the Department of Commerce that publishes the standards organizations use to manage cybersecurity risk. Its Cybersecurity Framework is the most widely adopted model in the country and underpins financial-sector regulation, including NY DFS 23 NYCRR 500. We organize every assessment around its six core functions.
01
Govern
How cyber risk is managed, assigned, and overseen.
02
Identify
Know your assets, data, and where exposure lives.
03
Protect
Access control, MFA, training, and encryption.
04
Detect
Monitoring to spot suspicious activity as it happens.
05
Respond
A tested plan to act quickly when something goes wrong.
06
Recover
Restore operations and learn from every event.
A PREVIEW OF WHAT WE SURFACE

What your report actually shows

Below are two of the highest-impact findings we look for. Every example uses masked demo
data — your report shows your real environment, with sensitive details handled confidentially.

…and everything else we check

Exposed sensitive records
Unencrypted PII — SSNs, tax documents, client files — sitting in reachable locations.
End-of-life systems
Operating systems no longer receiving security patches, open to known exploits.
Outdated security software
Antivirus and endpoint tools running old versions with unpatched flaws.
Unmanaged remote access
Remote-access tools installed on machines that shouldn't have them.
External IP vulnerabilities
Weaknesses on your internet-facing addresses that attackers scan for daily.
Email authentication gaps
SPF, DKIM, and DMARC misconfigurations that let attackers spoof your domain.
WHY MOTIVA

Most IT firms know IT. We know what DFS
auditors actually ask for.

Three reasons NY companies move from a generic MSP to Motiva.
DFS
DFS-approved instructor
Walter is approved by the Department of Financial Services to teach licensed insurance professionals — few (if any) competing MSPs in New York can say this.
Docs
Documented program
Written cybersecurity program, risk assessment, board reports, audit cycles, and a multi-year maturity roadmap — the artifacts regulators ask to see.
100%
Audit-tested
Audit pass rate across Motiva insurance and mortgage clients. Two-plus years. Zero fines. Zero violations.

Results you can measure. Trusted by the best.

+100
Insurance & mortgage firms protected
98%
First contact resolution
2+ yrs
Perfect compliance track record
100%
Client audit pass rate
YOUR NEXT 30 MINUTES

Find out where your company actually stands.

A focused 30-minute review for NY insurance agencies. No pitch, no pressure — just clarity. You'll speak directly with Walter Contreras, Motiva's CEO and a DFS-approved instructor.
Your Risk Assessment Request is Confirmed! 🎉
We have received your details. Our team is already preparing your external exposure scan.

Want to skip the wait?
Schedule your 30-minute confidential review directly with Walter Contreras, to walk through your findings together.
Oops! Something went wrong while submitting the form.

30 min · Confidential · No obligation

© 2026 Motiva Networks — All Rights Reserved. · 1100 Franklin Avenue, Garden City NY 11530 · (646) 374-1820