
NJ Regulation 22-05 Compliance for New Jersey Financial & Insurance Firms
Mortgage lenders, insurance agencies, title companies, check cashers and credit unions: find out what NJ Regulation 22-05 actually asks of you, which breach-reporting clock applies to your license, and how to prove your controls work before an examiner asks.
What NJ Regulation 22-05 Actually Requires
NJ Regulation 22-05 is the name most people search for, but the document itself is New Jersey Department of Banking and Insurance Bulletin No. 22-05. Commissioner Marlene Caride issued it on March 2, 2022, after the Russian invasion of Ukraine raised the cyber threat to the U.S. financial sector. It is addressed to every individual and entity regulated by the Department, from a one-office insurance producer to a state-chartered bank.
Most of the bulletin covers sanctions screening. The cybersecurity section is short, and it is specific. NJ Regulation 22-05 tells regulated entities to evaluate their systems for cyber risk and take appropriate action, and it names the controls the Department expects to see:
- Core controls: multi-factor authentication (MFA), privileged access management, vulnerability management, and disabling or securing remote desktop protocol (RDP) access.
- Incident response and business continuity: review, update and test both plans, and make sure they address destructive attacks such as ransomware.
- Essential services: re-evaluate how you keep serving customers and protect critical data through an extended outage.
- Backups: run a full test of your ability to restore systems and data from backup. Do not assume restores work until one has.
- People: provide additional cybersecurity awareness training and reminders for all employees.
- Reporting: report cybersecurity events immediately to law enforcement, including the FBI and CISA, and to the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC).
What NJ Regulation 22-05 does not contain matters just as much. There is no size exemption, no annual certification form and no fixed hour count for reporting. That is why NJ Regulation 22-05 compliance is less about filling in a form and more about being able to show, with evidence, that each control is in place and has been tested.
Bulletin 22-05 also rarely stands alone. A mortgage lender that follows it is usually also covered by the FTC Safeguards Rule. A credit union is also covered by NCUA rules, and a firm licensed in New York is also covered by NYDFS Part 500. The practical question is not “are we compliant with 22-05?” but “which rules apply to our license, and can we prove we meet all of them?” The rest of this page answers that question by vertical.
NJDBI-Licensed Verticals Requiring Cybersecurity Compliance
NJ Regulation 22-05 applies to anyone the Department of Banking and Insurance regulates. The table below maps the most common DOBI-licensed businesses to the risk that keeps their owners up at night and the control an examiner, auditor or cyber insurer will want to see first.
| NJDBI-Regulated Vertical | Critical Operational Liability | Required Technical Control | Rules Beyond 22-05 |
|---|---|---|---|
| Mortgage lenders, brokers and servicers | High-volume nonpublic personal information (NPI) and loan files | MFA on email and the LOS, encryption at rest and in transit | FTC Safeguards Rule, NJ breach law |
| Insurance agencies and producers | Client data held in the AMS and shared with carriers and vendors | Written risk assessment, vendor oversight, privileged access control | NYDFS Part 500 if NY-licensed, NJ breach law |
| Title and settlement companies | Wire transfer fraud and ransomware during closings | Tested incident response plan, email security, endpoint detection | NJ breach law; FTC rules may reach settlement services |
| Check cashers and money transmitters | Transaction data and cash-handling systems | Tight access controls, logging, continuous employee training | FTC Safeguards Rule, federal BSA/AML |
| State-chartered banks and savings banks | Core banking availability and customer accounts | Tested backup restores, 24/7 monitoring, RDP locked down | Federal 36-hour incident notification rule, GLBA guidelines |
| Credit unions | Member data and online banking uptime | MFA, vulnerability management, tested continuity plan | NCUA 72-hour cyber incident reporting |
| Consumer lenders, pawnbrokers, real estate brokers | Personal and financial records on small, lightly staffed networks | MFA, managed patching, encrypted backups | FTC Safeguards Rule where credit is extended, NJ breach law |
Mortgage Lender IT Support New Jersey Lenders Can Count On
Loan officers work from phones, laptops and home offices, and every file they touch carries Social Security numbers, bank statements and tax returns. Mortgage lender IT support New Jersey firms need starts with MFA on every mailbox and the loan origination system, encrypted laptops, and a way to disable a departing loan officer’s access within minutes. Those are the same controls NJ Regulation 22-05 names, and the same ones the FTC Safeguards Rule requires of non-bank lenders.
Cybersecurity Compliance for Insurance Agencies NJ Regulators Expect
An independent agency may have eight people and access to thousands of client records through its agency management system and carrier portals. Cybersecurity compliance for insurance agencies NJ examiners and carriers look for is practical: MFA everywhere, admin rights removed from daily accounts, a tested restore of the AMS, and training that covers carrier-impersonation phishing. If your agency also holds a New York license, NYDFS Part 500 adds a formal cybersecurity program, a written risk assessment and a 72-hour reporting rule. See our dedicated page on IT support for insurance brokers in NJ.
Title Companies and Wire Fraud
Title and settlement firms are a favorite target for business email compromise, because one spoofed closing instruction can redirect a buyer’s entire down payment. The controls that stop it are email authentication (SPF, DKIM and DMARC), MFA, a written call-back rule for any change to wiring instructions, and an incident response plan that includes calling your bank and the FBI the same hour. That last step is exactly what NJ Regulation 22-05 means by reporting immediately.
Banks, Credit Unions, Check Cashers and Money Transmitters
Depository institutions already live under federal examination, so NJ Regulation 22-05 mostly reinforces what their examiners ask for. Smaller licensees such as check cashers and money transmitters often have the least IT staff and the most cash-handling exposure. For them, the fastest risk reduction is locking down remote access, patching on a schedule and proving backups restore.
Mandatory Cybersecurity Frameworks for 2026 Compliance
NJ Regulation 22-05 sets expectations. The rules below set enforceable requirements and deadlines, and at least one of them almost certainly applies to your firm. Which one depends on your charter or license, not on your size.
FTC Safeguards Rule
Non-bank financial institutions, including mortgage lenders and brokers, consumer finance companies and check cashers, must run a written information security program under the FTC Safeguards Rule. It requires a Qualified Individual, a written risk assessment, MFA, encryption, access controls and training. Since May 2024, a notification event involving 500 or more consumers must be reported to the FTC within 30 days of discovery. Our FTC Safeguards Rule compliance page walks through all ten elements.
Federal Rules for Banks and Credit Unions
Banks supervised by the FDIC, OCC or Federal Reserve, including New Jersey state-chartered banks, must notify their primary federal regulator within 36 hours of determining that a qualifying computer-security incident has occurred. Federally insured credit unions must report a reportable cyber incident to the NCUA within 72 hours. Both sit on top of the GLBA information security guidelines examiners already test.
NYDFS Part 500 for Firms Also Licensed in New York
Many New Jersey agencies and lenders also hold New York licenses. If you do, 23 NYCRR Part 500 applies to that license: a formal cybersecurity program, a written risk assessment, MFA, an asset inventory, and notice to the New York Department of Financial Services within 72 hours of a cybersecurity event. This is where the “72-hour” rule people associate with NJ Regulation 22-05 actually comes from.
New Jersey’s Breach Notification Law
Any business holding New Jersey residents’ personal information must notify affected customers in the most expedient time possible and without unreasonable delay, and must report to the Division of State Police before notifying customers. That duty applies whether or not a financial regulator is involved.
Your Reporting Clock at a Glance
| Rule | Who it covers | Deadline | Report to |
|---|---|---|---|
| NJ Regulation 22-05 (DOBI Bulletin 22-05) | All DOBI-regulated individuals and entities | Immediately | FBI, CISA and NJCCIC |
| Federal incident notification rule | FDIC-, OCC- and Fed-supervised banks | 36 hours | Primary federal regulator |
| NCUA cyber incident rule | Federally insured credit unions | 72 hours | NCUA |
| NYDFS Part 500 | Firms also licensed by New York DFS | 72 hours | New York DFS |
| FTC Safeguards Rule | Non-bank lenders, brokers, check cashers | 30 days (500+ consumers) | FTC |
| NJ breach notification law | Any business with NJ residents’ data | Most expedient time possible | NJ State Police, then customers |
Does your firm have an incident response plan you have actually tested?
NJ Regulation 22-05 says report immediately. Your license may add a 36-hour, 72-hour or 30-day deadline on top. None of those clocks wait while you figure out who to call. Do not wait for a breach to build your playbook.
Schedule a Free 22-05 Compliance Review or call (973) 295-5570
Your NJDBI Compliance Audit Checklist: 10 Questions to Answer Now
Use this NJDBI compliance audit checklist to find your gaps before an examiner, auditor or cyber insurance underwriter does. Every item traces back to a control named in NJ Regulation 22-05 or one of the frameworks above. If you cannot answer “yes, and here is the evidence,” it belongs on your remediation list.
- Is MFA enforced on every email account, remote access path and financial system? Not “available.” Enforced, with no exceptions for executives.
- Are administrator rights separated from daily accounts? Privileged access management starts with nobody browsing the web as an admin.
- Is RDP disabled or behind a VPN with MFA? Exposed remote desktop remains one of the most common ransomware entry points.
- Do you scan for and patch vulnerabilities on a schedule? Keep the scan reports; they are your evidence.
- Do you have a written incident response plan that names who calls the FBI, your regulator and your insurer?
- Have you tested that plan in the last twelve months with a tabletop exercise that includes ransomware?
- Have you performed a full restore from backup, not just checked that the backup job succeeded?
- Is nonpublic information encrypted on laptops, in email and in cloud storage?
- Has every employee completed security awareness training this year, including phishing simulations?
- Do you know which reporting deadline applies to your license and do you have the contact details ready?
Most firms we meet can answer yes to three or four of these. The rest are usually fixable within a quarter once someone owns them. A security risk assessment turns this checklist into documented findings you can hand to an examiner.
Managed Security Services for NJ Financial & Insurance Entities
eMDTec is a Verona-based managed IT and cybersecurity firm that has supported New Jersey businesses since 2002. For DOBI-licensed firms, we deliver the controls NJ Regulation 22-05 names and the documentation that proves they work: MFA rollout, privileged access cleanup, 24/7 endpoint detection and response, managed patching, encrypted backup with scheduled restore tests, email security and phishing training.
We work as your full IT department or alongside the person who handles IT today through co-managed IT.
NJ Financial IT Compliance Services, All Year
Compliance is not a project you finish in March. Our NJ financial IT compliance services run on a calendar: quarterly vulnerability scans, monthly patch reports, an annual risk assessment, an annual incident response tabletop, and a restore test you can show an examiner. You get one evidence folder that answers NJ Regulation 22-05, the FTC Safeguards Rule and your cyber insurance questionnaire at the same time. If you also need a written information security program, our WISP compliance services build it from the same findings.
What to Look For in an NJ Financial Services Cybersecurity Provider
Choosing an NJ financial services cybersecurity provider is itself a vendor-risk decision, and regulators increasingly ask how you oversee the companies that touch your data. Ask any provider these questions:
- Can you name the specific controls in NJ Regulation 22-05 and show how you evidence each one?
- Who monitors alerts at 2 a.m., and how fast do they act?
- Will you sign a written agreement covering how you protect our nonpublic information?
- Do you test restores, or only confirm that backups ran?
- Can someone be on site in Essex, Morris, Passaic or Bergen County the same day?
We are happy to answer every one of them in writing. See our financial services IT support page for the full service stack, or cybersecurity services for how our 24/7 monitoring works.
How an NJ Regulation 22-05 Engagement Works
Every NJ Regulation 22-05 engagement follows the same three steps, whether you are a five-person agency or a multi-branch lender.
Assess
We map your license to the rules that apply, then test each control NJ Regulation 22-05 names: MFA, privileged access, vulnerability management, RDP exposure, incident response, continuity, backups and training. You get a plain-English findings report ranked by risk.
Remediate
We close the gaps in order of risk, starting with the items that stop ransomware and email fraud. Each fix is documented with before-and-after evidence so your compliance file builds as the work gets done.
Maintain
We monitor around the clock, patch on schedule, retest restores, run your annual tabletop and refresh the risk assessment. When a regulator, auditor or insurer asks, the evidence is ready.
Find Out Where Your Firm Stands on NJ Regulation 22-05
A free 30-minute review tells you which rules apply to your license, which of the ten checklist items you can already prove, and what to fix first. No obligation and no sales pitch.
NJ Regulation 22-05 Compliance FAQs
What is NJ Regulation 22-05?
NJ Regulation 22-05 is the common name for New Jersey Department of Banking and Insurance Bulletin No. 22-05, issued March 2, 2022. Its cybersecurity section directs every DOBI-regulated entity to review its cyber program, with attention to MFA, privileged access management, vulnerability management and RDP, and to test incident response, continuity and backup restores.
Is NJ Regulation 22-05 a law with fines?
It is a bulletin, not a statute or an adopted regulation, and it does not set its own fine schedule. It does state the Department’s expectations of the businesses it licenses, and the enforceable rules that apply alongside it, such as the FTC Safeguards Rule, NYDFS Part 500 and federal banking rules, do carry penalties. We are not attorneys, so confirm your specific obligations with counsel.
Who has to follow NJ Regulation 22-05?
Every individual and entity regulated by the Department of Banking and Insurance. That includes banks, credit unions, mortgage lenders and brokers, money transmitters, check cashers, consumer lenders, insurers, insurance producers, title insurance producers and other DOBI licensees.
Does NJ Regulation 22-05 require reporting a breach within 72 hours?
No. NJ Regulation 22-05 says to report cybersecurity events immediately to law enforcement, including the FBI and CISA, and to NJCCIC. The 72-hour deadline comes from NYDFS Part 500 and the NCUA rule. Banks face a 36-hour federal rule and non-bank lenders a 30-day FTC rule.
Is there a small-business exemption?
Bulletin 22-05 has no size exemption. Some other rules do scale: the FTC Safeguards Rule relaxes certain requirements for firms with fewer than 5,000 consumer records, and NYDFS Part 500 has a limited exemption for small covered entities. Neither removes the need for MFA and a tested incident response plan.
How often should we test our incident response plan and backups?
The bulletin asks for testing without setting a schedule. We recommend at least one ransomware tabletop and one full restore test every year, plus a restore test after any major system change. That cadence also satisfies most cyber insurance questionnaires.
Does the FTC Safeguards Rule apply to my NJ firm too?
If you are a non-bank financial institution, such as a mortgage lender or broker, consumer finance company or check casher, very likely yes. Insurance activities are generally overseen by state insurance regulators instead, so agencies should confirm with counsel whether any part of their business, such as premium finance, falls under the FTC.
What does an eMDTec 22-05 compliance review include?
A free 30-minute call to map your license to the rules that apply and walk through the ten-question checklist on this page. If you want to go further, a full assessment tests each control, documents the evidence and gives you a prioritized remediation plan.
Sign Up for More Information
At eMDTec, our team of cybersecurity experts are here to help you understand the requirements imposed by New Jersey’s Dept. of Banking & Insurance and ensure you have the protections in place that are essential for your compliance. Sign up today to learn more about how we can help.
Start a Conversation and Learn How Technology Can Transform Your Business
Reach out today to schedule a meeting where we'll learn about your business and create an IT action plan that works for you.
Schedule Your Free Consultation Call (973) 295-5570