New York DFS Tells Financial Firms to Treat Cyber Risk Assessments as Living Documents
The New York State Department of Financial Services has spent enough time examining cybersecurity programs to know where risk assessments tend to go wrong. Asset inventories are incomplete. Methodologies change from one assessment to the next. Third parties are considered individually without much thought for the fact that several critical functions may depend on the same provider. Risks are identified, put into a document and then fail to leave much evidence that they influenced the cybersecurity program at all.
