15 views 3 mins 0 comments

New York State Department of Financial Services Issues New Cybersecurity Guidance on Risk Assessments for Financial Services Entities

In Legal News
September 13, 2026

Guidance Emphasizes Importance of Ongoing Risk Assessments and Reminds Entities of Compliance Obligations Under Nation-Leading Cybersecurity Regulation

New York State Department of Financial Services (DFS) Acting Superintendent Kaitlin Asrow today issued new cybersecurity guidance outlining the Department’s expectations for DFS-regulated entities’ on conducting risk assessments sufficient to inform their cybersecurity programs. The guidance outlines requirements regarding scope, frequency, and the role of risk assessments in informing entities cybersecurity programs. Under the Department’s nation-leading cybersecurity regulation, regulated entities are required to review and update risk assessments at least annually and whenever a change in the business or technology causes a material change to the entities’ cybersecurity risk. 

“Risk assessments are the foundation of a strong cybersecurity program,” said Department of Financial Services Acting Superintendent Kaitlin Asrow. “As cybersecurity risks evolve and institutions’ risk profiles change, it is critical that their cybersecurity programs adapt, and this guidance outlines those expectations.”  

The guidance does not impose new obligations or requirements on regulated entities. Rather, the guidance is intended to clarify regulatory requirements under the Department’s cybersecurity regulation and share best practices that entities should consider implementing. The guidance outlines key elements of effective risk assessment, including expectations related to governance and oversight, methodology, scope, documentation, and the need to integrate assessments into cybersecurity programs.  Factors entities should consider when performing a risk assessment include: 

  • Material Technology Change: Reassessing risk before or after major system migration, acquisition, or implementation of a new critical system. 
  • Third-Party Risk: Evaluating whether multiple critical functions depend on the same cloud provider, managed service provider, software platform, or other common dependency. 
  • Emerging Risk: Considering how adoption of AI or other emerging technologies changes the entity’s threat exposure, data risks, access controls, or third-party dependencies. 
  • Risk-Informed Controls: Assessing identified risks to determine whether existing controls, policies, monitoring, or risk acceptance decisions need to be strengthened or updated. 

The DFS cybersecurity regulation became effective in March 2017, with an updated amendment, fully in effect as of November 2025, designed to enhance cybersecurity governance, mitigate risks, and strengthen protections for New York businesses and consumers against cybersecurity threats. 

A copy of the guidance is available on the Department’s newly refreshed Cybersecurity Resource Center, a streamlined, easier-to-navigate hub for cybersecurity guidance, resources, and frequently asked questions.  

### 

Source: DFS