Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

New York DFS Tells Financial Firms to Treat Cyber Risk Assessments as Living Documents

New York DFS Tells Financial Firms to Treat Cyber Risk Assessments as Living Documents

By
Key Takeaways
  • Risk Assessments Must Evolve: DFS-regulated entities must review and update cybersecurity risk assessments at least annually and whenever business or technology changes materially alter their cyber risk.
  • Assessments Must Drive Action: DFS expects entities to demonstrate how identified risks inform cybersecurity controls, compensating controls, resource decisions and risk acceptance.
  • Concentration Risk Requires Attention: Entities should consider whether multiple critical systems or business functions depend on the same cloud provider, software platform, managed service provider or other shared dependency.
  • Emerging Technology Can Change the Risk Profile: AI, quantum computing developments, software supply chain attacks and evolving threats are among the factors DFS says organizations should consider when assessing cyber risk.
  • Documentation Matters: Entities must maintain sufficient records to show how risks were identified, assessed and addressed, including the reasoning behind risk treatment and acceptance decisions.
Deep Dive

The New York State Department of Financial Services has spent enough time examining cybersecurity programs to know where risk assessments tend to go wrong. Asset inventories are incomplete. Methodologies change from one assessment to the next. Third parties are considered individually without much thought for the fact that several critical functions may depend on the same provider. Risks are identified, put into a document and then fail to leave much evidence that they influenced the cybersecurity program at all.

Those shortcomings are the backdrop to new guidance issued by Acting Superintendent Kaitlin Asrow, which lays out what DFS expects from regulated financial services entities when conducting the cybersecurity risk assessments required under Part 500. The guidance creates no new obligations. Instead, it gives considerably more detail to an existing one: covered entities must maintain cybersecurity programs based on risk assessments that are sufficient to inform how those programs are designed.

“Risk assessments are the foundation of a strong cybersecurity program,” Asrow said in announcing the guidance. “As cybersecurity risks evolve and institutions’ risk profiles change, it is critical that their cybersecurity programs adapt, and this guidance outlines those expectations.”

That word, adapt, does a fair amount of work. Part 500 requires covered entities to review and update their risk assessments at least annually and whenever a change in their business or technology materially changes their cyber risk. DFS is making clear that the annual exercise is a floor, not a calendar appointment that excuses an organization from looking again when something important changes.

The department also expects to see what happened after a risk was identified. A covered entity should be able to demonstrate how its assessment informed the selection of cybersecurity controls and compensating controls, as well as decisions to accept risk. The assessment, in other words, has to survive contact with the cybersecurity program it is supposed to shape.

What DFS Has Been Finding

The guidance is not written in a vacuum. During examinations and investigations, and in interviews with personnel at regulated entities, DFS says it has encountered recurring weaknesses in risk assessments that contributed to deficient cybersecurity programs.

Some are basic but consequential. Asset inventories may be outdated or incomplete. Organizations may fail to identify where nonpublic information resides or how it moves through their systems. Critical business processes, cloud environments, third-party service providers and other external dependencies can disappear from the assessment altogether.

Other weaknesses sit deeper in the process. DFS has found entities that do not consistently identify, analyze, prioritize and document cybersecurity risks, or adequately evaluate whether existing controls are effective. Assessments may fail to distinguish between inherent and residual risk. Emerging technologies, concentration risk, interdependencies and single points of failure may receive insufficient attention. In other cases, responsibility for addressing a risk is unclear or the organization cannot show that assessment findings influenced policies, controls and spending decisions.

DFS contrasts those shortcomings with what it has observed in stronger programs: dynamic, data-driven assessments that are integrated into enterprise governance, follow a defined and repeatable methodology and are properly scoped, documented and reviewed.

A Risk Assessment Cannot Belong Only to Cybersecurity

Governance is where the department begins its prescription. Covered entities must maintain written risk assessment policies and procedures approved at least annually by a senior officer or senior governing body. Where applicable, a CISO or senior officer must oversee the assessment process.

DFS also wants the conversation to extend beyond the security function. Business units, operations, compliance, legal and other relevant stakeholders should participate so that cybersecurity risks are considered alongside the organization’s business activities, data, third-party relationships and regulatory obligations.

The results should travel upward as well. Part 500 requires CISOs to report material cybersecurity risks to the senior governing body, and DFS describes risk assessments as one mechanism for identifying and substantiating those risks. Although the regulation does not require a board or senior management to formally approve the assessment itself, its findings can inform decisions about resources, cybersecurity investments, controls and risk acceptance.

DFS does not prescribe a particular methodology for conducting the assessment. It does expect the methodology to be clear and repeatable. That means identifying threats and vulnerabilities relevant to the organization’s operations, technology and data, drawing where available from sources such as threat intelligence, incident trends, vulnerability scans, penetration tests, audits and previous assessments. Entities should make reasonable estimates of likelihood and impact and use consistent rating criteria so results can be measured and compared over time.

The range of risks under consideration is deliberately wider than hostile cyber activity. DFS says entities should examine malicious actors alongside system misconfigurations, insider misuse and process failures. Vulnerabilities can arise from administrative controls, human behavior, natural disasters and third-party dependencies as readily as from technical weaknesses. Assessments should consider potential consequences including the loss of nonpublic information, financial losses, operational disruption, legal or regulatory exposure, reputational damage and replacement costs.

Recognized frameworks can help, but adopting one does not settle the matter. DFS says whatever approach an entity chooses must fit its own business model, technology environment and risk profile.

The Risk Hidden Between Vendors

Some of the guidance’s more consequential language concerns third parties and concentration risk. A risk assessment should consider the criticality of services supplied by third parties, the sensitivity of the information they can access or maintain, their connectivity to the covered entity’s systems and the operational consequences if they suffer an incident or disruption. DFS specifically points to cloud providers, managed security service providers, software vendors, payment processors and affiliates among the relationships that may need to be examined.

Looking at those providers one by one is not necessarily enough. DFS says technologies, platforms and vendors that appear to present limited risk when considered independently can create significant exposure when several critical systems or business functions depend on the same infrastructure, cloud provider, software platform or managed service provider. Assessments should therefore identify potential single points of failure and consider how an incident affecting one dependency could reach other systems or critical business functions.

The distinction matters. A company may have a perfectly respectable assessment of Vendor A and another of Vendor B and still miss the larger problem if both ultimately depend on the same underlying service. The risk exists not only inside each relationship but between them.

Emerging technologies add another layer. DFS says assessments should consider whether developments such as artificial intelligence, advances in quantum computing that could affect future cryptographic protections, software supply chain attacks, changing ransomware techniques and geopolitical tensions that increase nation-state cyber activity materially affect an entity’s risk profile.

If the Decision Cannot Be Traced, Expect Questions

The department devotes substantial attention to documentation, and its expectations go beyond retaining the finished assessment. Covered entities must keep enough documentation to demonstrate how cybersecurity risks were identified, assessed and addressed. Effective programs preserve evidence of the methodology used, the information considered and the reasoning behind conclusions and management decisions. Identified risks should be linked to the controls or compensating measures intended to mitigate them. When management accepts a risk, the documentation should capture why and account for the residual risk that remains.

There is a practical consequence to that traceability. When risks are clearly mapped to controls, internal audit and independent testing functions can more efficiently determine whether those controls are configured correctly and operating as intended. DFS says that can make testing more targeted while giving both supervisors and internal stakeholders a clearer account of how cybersecurity decisions were reached.

The department also recommends maintaining a risk register or comparable tracking mechanism to record assessment results, follow remediation work and document changes in residual risk over time. Done properly, the register becomes less a catalog of problems than a record of what the organization decided to do about them.

Annual Is the Minimum

Part 500 requires covered entities to review and update their assessments “as reasonably necessary,” at least annually and whenever a change in business or technology causes a material change to cyber risk. DFS provides a useful sense of what that can mean in practice. Major system migrations, mergers and acquisitions, significant outsourcing arrangements, significant developments in cybersecurity technologies such as frontier AI models, changes in threat actor capabilities and the adoption of emerging technologies may all warrant an updated assessment. Entities should also consider actively exploited critical hardware or software vulnerabilities and geopolitical developments that could increase ideologically motivated cyberattacks.

The important question, then, is not simply whether an organization performed its annual assessment. It is whether the assessment still describes the organization that exists today.

DFS says continuous or regularly refreshed assessment processes demonstrate greater adaptability and resilience because cybersecurity controls remain aligned with changes in threats, technology and the business itself. The department is encouraging regulated entities to review their existing assessments and procedures against the new guidance, including who participates, what falls within scope, how risks are measured and whether assessments respond when circumstances materially change.

The Cybersecurity Regulation has required risk-based cybersecurity programs since Part 500 took effect in March 2017, with its amended requirements fully in effect as of November 2025. The Sept. 10 guidance does not rewrite those rules. Identifying cyber risk is only the beginning. A regulated entity should be able to show what it learned, what it decided and what changed because of it.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong