Industry Letter
Date: September 10, 2026
To: All entities regulated by the New York State Department of Financial Services
Re: Guidance on How to Conduct and Use Risk Assessments Required by the DFS Cybersecurity Regulation
The New York State Department of Financial Services (“DFS” or “the Department”) requires regulated entities (“Covered Entities1”) to maintain cybersecurity programs based on their Risk Assessments2. The Department is issuing this guidance to clarify regulatory requirements and highlight best practices when designing, conducting, and updating Risk Assessments (“Guidance”). This Guidance does not create new obligations.
Cybersecurity risk is an inherent part of operating or utilizing Information Systems3 and processing Nonpublic Information4 (“NPI”). DFS’s Cybersecurity Regulation (“Part 500”) requires Covered Entities to understand and address cybersecurity risks in order to maintain cybersecurity programs that are, as required by Section 500.2(a), “designed to protect the confidentiality, integrity and availability” of their Information Systems and the NPI stored thereon. An integral, mandatory element of this process is the performance of Risk Assessments. A Risk Assessment is defined in the Cybersecurity Regulation as:
the process of identifying, estimating and prioritizing cybersecurity risks to organizational operations (including mission, functions, image and reputation), organizational assets, individuals, customers, consumers, other organizations and critical infrastructure resulting from the operation of an information system. Risk assessments incorporate threat and vulnerability analyses and consider mitigations provided by security controls planned or in place.5
In other words, a Risk Assessment is an evaluation that identifies, analyzes, and prioritizes cybersecurity risks taking into account the Covered Entity’s size, complexity, and risk profile. Risk Assessments must be “sufficient to inform the design of” the Covered Entity’s cybersecurity program.6 In addition, Risk Assessments must be reviewed and updated at least annually and whenever a change in the Covered Entity’s business or technology causes a material change to the Covered Entity’s cyber risk.7 Moreover, Risk Assessments must be carried out in accordance with written policies and procedures, which must include:
- criteria for evaluating and categorizing identified cybersecurity risks or threats facing the Covered Entity;
- criteria for assessing the confidentiality, integrity, security, and availability of the Covered Entity’s Information Systems and NPI, including the adequacy of existing controls in the context of identified risks; and
- requirements describing how identified risks are addressed by the cybersecurity program, as based on the Risk Assessment.8
The Risk Assessment must inform and support the Covered Entity’s decisions regarding control selection, compensating controls, and risk acceptance.9 The Department expects each Covered Entity to be able to demonstrate how its Risk Assessment informed cybersecurity controls, compensating controls, and risk acceptance decisions. Risk Assessments should be tailored to an organization's size, complexity, unique risks, operations, assets, and other circumstances. A Risk Assessment conducted by an individual or small business will often look very different from one performed by a Class A Company10. However, the goal of the Risk Assessment – to assess risks so the organization can make informed decisions about its cybersecurity program – remains the same regardless of size.
The Department reviews Covered Entities’ Risk Assessments and information security policies and procedures during examinations and investigations. In these reviews and in interviews with Covered Entity personnel, DFS has identified common gaps in Risk Assessments which, in turn, have contributed to deficient cybersecurity programs. These observations include, among others:
- Incomplete asset scope and visibility, including outdated or incomplete asset inventories; failing to identify where NPI resides or flows; and omitting critical business processes, Third-Party Service Providers,11 cloud environments, or other external dependencies.
- Weak or inconsistent methodologies, including failing to consistently identify, analyze, prioritize, and document cybersecurity risks; evaluate the effectiveness of existing controls; or distinguish between inherent and residual risk.
- Failure to account for evolving and interconnected risks, including emerging technologies, changes in the threat landscape, interdependencies, concentration risk, and single points of failure that could materially affect the Covered Entity's operations.
- Insufficient governance and risk treatment, including failing to assign ownership, document risk response decisions, integrate Risk Assessment results into enterprise governance, or update Risk Assessments following material changes to the business, technology, or threat environment.
- Failure to account for or inform the cybersecurity program, resulting in policies, controls, and resource decisions that are not demonstrably based on the Covered Entity's identified cyber risks.
Conversely, the Department has observed that robust cybersecurity programs are designed using dynamic, data-driven Risk Assessments. These Risk Assessments are then integrated into enterprise governance processes, based on a defined and repeatable methodology, and are appropriately scoped, documented, and reviewed. This Guidance reviews what is required by the Cybersecurity Regulation, as well as best practices based on the Department’s observations.
1. Governance and Oversight
Effective governance is essential to a sound Risk Assessment process. The Cybersecurity Regulation requires Covered Entities to implement and maintain written policies and procedures that are approved at least annually by a Senior Officer12 or the Covered Entity’s Senior Governing Body13.
Where applicable, Covered Entities must designate a Chief Information Security Officer (“CISO”)14 or a Senior Officer to oversee the Risk Assessment process. In addition to requiring participation from the CISO or another appropriate role, Covered Entities should elicit input and participation from relevant business units, operations, compliance, legal, and other key stakeholders. This cross-functional involvement promotes the evaluation of cybersecurity risks in the context of the Covered Entity’s business activities, data, third-party relationships, and regulatory obligations, resulting in a more comprehensive and risk-informed assessment.
Importantly, Covered Entities should ensure the results of Risk Assessments are communicated to senior management and, where appropriate, the Senior Governing Body. Section 500.4(b)(3) of the Cybersecurity Regulation requires the CISO to report material cybersecurity risks to the Senior Governing Body. Risk Assessments are one important mechanism for identifying and substantiating the organization’s risks.
In addition, and as applicable, Section 500.4(d) requires the Senior Governing Body to exercise oversight of the entity’s cybersecurity program, including by confirming that the Covered Entity’s management has allocated sufficient resources to implement and maintain an effective cybersecurity program. While Part 500 does not require formal approval of Risk Assessments from a board of directors or senior management, findings and recommendations in Risk Assessments help leadership make informed decisions regarding resource allocation, cybersecurity investments, control selection, and risk acceptance.
2. Defined and Repeatable Methodology
Covered Entities should adopt a clear and repeatable methodology for identifying, analyzing, and prioritizing actions to address cybersecurity-related risks. A strong methodology begins with a structured process for identifying threats and vulnerabilities relevant to the entity’s operations, technology environment, and data. This process should incorporate multiple inputs, including, where available, threat intelligence, incident trend analysis, vulnerability scans, penetration testing, and findings from audits or prior Risk Assessments. Moreover, the methodology should define, at a minimum, reasonable estimates of the likelihood and impact of risks and apply consistent rating criteria to ensure that results are measurable and comparable over time.15
Covered Entities should evaluate both external and internal threats, such as malicious actors, system misconfigurations, insider misuse, and process failures. The identification of vulnerabilities should extend beyond technical weaknesses to include weaknesses in administrative controls, natural disasters, human factors, and third-party dependencies that could be exploited by threat actors or otherwise cause cyber risk. Covered Entities should consider potential malicious actions and user errors, as well as natural disasters that could cause power outages, disrupt data centers, and impair system availability. The potential loss of NPI, financial loss, operational disruptions, legal or regulatory exposure, reputational damage, and replacement costs should be addressed in a Risk Assessment. Considering these factors together supports a more accurate assessment of risk severity and prioritization.
The Department does not require Covered Entities to use a specific methodology in Risk Assessments, although many Covered Entities align their Risk Assessment methodologies with recognized frameworks.16 Consistent and repeatable methodologies can help to set benchmarks, evaluate control effectiveness, provide example scoring criteria, and describe how risk considerations contribute toward an overall risk severity score. While frameworks provide a useful methodology and approach, Covered Entities should ensure that their chosen approach is appropriately tailored to their own business model, technology environment, and risk profile.
Moreover, the Department has observed that mature cybersecurity programs apply consistent risk criteria across relevant organizational risk management processes, including those for third-party (e.g., vendors, Affiliates17) risk management, IT operations, and business continuity or disaster recovery planning. Using harmonized criteria promotes consistency in how risks are identified, measured, and prioritized across the organization, supports clearer communication to management and the board, and enables more coordinated and effective risk mitigation efforts. Finally, Covered Entities should periodically review methodologies to confirm they are appropriate for their organization.
3. Scope and Coverage
In defining the scope of a Risk Assessment, Covered Entities should consider the full range of internal and external factors that could materially affect their cybersecurity risk profile. The scope should be appropriate to the Covered Entity's size, complexity, business activities, and technological environment, and should be reviewed periodically to ensure it remains current. While the scope of Risk assessments will vary by entity, effective Risk Assessments should cover all assets, emerging risks, third-party risk, and concentration risk.
All Assets
A comprehensive Risk Assessment should cover all assets and other factors that could affect the confidentiality, integrity, or availability of Information Systems. These assets and factors include hardware, software, infrastructure, human capital, processes, and data such as NPI. Covered Entities are required to maintain an accurate and current asset inventory.18 That inventory should serve as the foundational input to the Risk Assessment. In conducting the Risk Assessment, Covered Entities should also consider, as appropriate, where NPI resides, how it flows through Information Systems, who has access to assets, and how assets are protected. The asset inventory should serve as a foundational input to the Risk Assessments process. The Department has observed that a failure to account for assets in a Risk Assessment provides an incomplete view of risks, which can lead to material gaps in a Covered Entity’s cybersecurity program.
Emerging Risks
The cybersecurity threat landscape continues to evolve rapidly. Risk Assessments should consider whether emerging technologies or changes in the threat environment materially affect their risk profile. Examples may include the adoption or use of artificial intelligence, advances in quantum computing that may affect future cryptographic protections, increasing software supply chain attacks, evolving ransomware techniques, and significant geopolitical tensions or conflict that result in increased nation-state cyber activity. The Department's cybersecurity guidance and advisories may assist Covered Entities in identifying and evaluating emerging risks relevant to their operations.
Third-Party and Supply Chain Risk
Risk Assessments should evaluate cybersecurity risks associated with Third-Party Service Providers based on the criticality of the services provided, the sensitivity of the information accessed or maintained, the level of connectivity to the Covered Entity's Information Systems, and the potential operational impact should the provider experience an incident or other disruption. This evaluation should include, where appropriate, cloud service providers, managed security service providers, software vendors, payment processors, Affiliates, and other organizations that support critical business functions.
Cyber Interdependencies and Concentration Risk
Risk Assessments should evaluate cyber interdependencies among Information Systems, shared technology platforms, information security services, and Third-Party Service Providers. Technologies, platforms, or vendors that present limited risk when evaluated independently may collectively create significant cyber risk when multiple critical systems or business functions rely on common infrastructure, cloud service providers, software platforms, managed service providers, or other shared dependencies. Covered Entities should identify potential single points of failure, assess concentration risk, and evaluate how a Cybersecurity Event affecting one dependency could impact other Information Systems or critical business functions. Understanding these cyber interdependencies enables Covered Entities to better assess systemic cyber risk, prioritize mitigation efforts, and strengthen the resilience of their cybersecurity program.
4. Documentation and Traceability
Covered Entities must maintain documentation sufficient to demonstrate how cybersecurity risks were identified, assessed, and addressed through the Risk Assessment process. Effective programs preserve evidence of the methodology used, the data considered, and the rationale supporting conclusions and management decisions. This includes maintaining records that link each identified cybersecurity risk to the specific controls or compensating measures implemented to mitigate the risks identified. The documentation should also capture instances where management elects to accept a risk, including the justification for risk acceptance and any residual risk considerations. Such transparency enables supervisory review to understand the reasonableness of the determination and allows internal stakeholders to better evaluate whether cybersecurity risks are managed systematically.
Cybersecurity risks should be clearly identified and documented before they are evaluated, prioritized, mitigated, transferred, or accepted. A Covered Entity cannot assess the likelihood or impact of risks, or make informed decisions regarding remediation or risk acceptance, if the risks have not been clearly identified and documented. Documenting identified risks and gaps enables organizations to prioritize remediation efforts, monitor progress over time, and identify patterns or recurring weaknesses across assessment cycles. Conversely, insufficient documentation and unidentified risks undermine the effectiveness of the cybersecurity program and impede informed decision making.
The Department also notes that strong traceability between identified risks and implemented controls supports the design and execution of effective audit and testing programs. Risk Assessments that clearly map risks to controls, internal audit functions, and independent testing functions can more efficiently validate that the controls identified are configured correctly and operating as intended. This alignment promotes greater confidence in the entity’s cybersecurity program. In this way, well-documented and traceable Risk Assessments not only strengthen cybersecurity governance but also improve operational efficiency by making the audit process more targeted and effective.
Finally, Covered Entities should maintain a mechanism, such as a risk register or comparable tracking process, to record the assessment results, monitor remediation activities, and document changes to residual risk over time. When integrated into the Risk Assessment process, such mechanisms provide management with visibility into the status of identified risks, remediation progress, and emerging trends and support informed decision making regarding risk treatment and resource allocation.
5. Integration and Updates to Risk Assessments
The most effective Risk Assessments are integrated into a Covered Entity’s broader cybersecurity program rather than treated as stand-alone exercises. Section 500.2 requires a Covered Entity’s cybersecurity program to be based on its Risk Assessment so that the program may be designed to perform core cybersecurity functions.19 Covered Entities must use the results of the Risk Assessment to inform the design and implementation of, as well as updates to, cybersecurity policies, procedures, controls, and testing plans.
Covered Entities must review and update Risk Assessments “as reasonably necessary,” but at least annually, and, at a minimum, whenever a change in their business or technology causes “a material change” to their cyber risk.20 For example, major system migrations, mergers or acquisitions, significant outsourcing arrangements, or significant developments in cybersecurity technologies (e.g., frontier AI models),21 changes in threat actor capabilities, or the adoption of emerging technologies may all constitute material changes to a Covered Entity’s cyber risk. Additionally, Covered Entities should consider other factors when determining whether to perform or update a Risk Assessment such as the identification or active exploitation of critical hardware and software vulnerabilities or geopolitical events that have the potential to increase ideologically motivated cyberattacks.22
Risk Assessments must be dynamic and responsive to material changes in the Covered Entity’s threat environment, technology, and business operations. Entities that maintain a continuous or regularly refreshed Risk Assessment process demonstrate greater adaptability and resilience by aligning cybersecurity controls with evolving threats and business changes.
Conclusion
The Department encourages Covered Entities to review their Risk Assessments and Risk Assessment procedures in light of this Guidance. During this review, Covered Entities should consider, among other things, whether the appropriate personnel are actively engaged in the Risk Assessment process. They should also review the scope and methodology to confirm the assessments are appropriate based on the entity’s size and risk. Additionally, they should determine whether the assessments are responsive to material changes in business operations, technology, Information Systems, data handling, third-party relationships, and threats and vulnerabilities to the organization. By maintaining strong, risk-based assessment practices, Covered Entities will better position themselves to meet the requirements of Part 500 and, as a result, strengthen their resilience and operational integrity in the face of evolving cyber risks.
1 A Covered Entity is defined as “any person operating under or required to operate under a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law, regardless of whether the covered entity is also regulated by other government agencies.” N.Y. Comp. Codes R. & Regs. tit. 23, § 500.1(e) (2025). References to Sections hereinafter refer to those in the Cybersecurity Regulation. Capitalized terms used hereinafter are defined in the Cybersecurity Regulation.
2 § 500.2.
3 § 500.1(i).
4 § 500.1(k).
5 § 500.1(p).
6 § 500.9(a).
7 § 500.9(a).
8 § 500.9(b).
9 See, §§ 500.2 and 500.9.
10 § 500.1(d).
11 § 500.1(s).
12 § 500.1(r).
13 § 500.1(q).
14 § 500.1(c). The Department recognizes that some Covered Entities are exempt from the requirement to appoint a CISO. In such cases, effective governance may involve designating other individuals, such as a Senior Officer or external expert, to exercise appropriate oversight and to ensure Risk Assessments are informed by sufficient cybersecurity and IT risk knowledge.
15 E.g., Fig. 7 of NIST SP 800-221 (November 2023) demonstrates a common risk scoring methodology based on a risks likelihood and predicted impact. Available at https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-221.pdf.
16 For example, three common cybersecurity risk frameworks are NIST’s Cybersecurity Framework 2.0 (February 2024) (available at https://www.nist.gov/cyberframework), Cyber Risk Institute’s Profile v2.2 (April 2026) (available at https://cyberriskinstitute.org/), and ISO 27005:2022, Edition 4 (October 2022) (available at https://www.iso.org/standard/80585.html). Note that ISO materials are generally available for purchase only.
17 § 500.1(a).
18 § 500.13(a).
19 § 500.2.
20 § 500.9(a).
22 Material changes to a Covered Entity’s cyber risk necessitate updates to its Risk Assessment; however, a heightened cybersecurity threat environment may warrant additional measures beyond the minimum requirements of Part 500. See https://www.dfs.ny.gov/industry-guidance/industry-letters/20260521-guidance-on-measures-reg-entities-should-consider-in-a-hcte.