New York financial regulators have spelled out how banks, insurers, and other supervised firms should measure cyber risk so those findings actually shape day-to-day security programs.
On September 10, 2026, Acting Superintendent Kaitlin Asrow of the New York State Department of Financial Services (NYDFS) released an industry letter explaining what a legally adequate risk assessment looks like under the state’s cybersecurity rule, 23 NYCRR Part 500.
The letter does not add new duties.
It restates existing obligations and shares practices DFS examiners have seen work—and fail—in the field.Under the regulation, every covered organization must keep a cybersecurity program that is designed around its own risk assessment.
That assessment is defined as a structured process for identifying, estimating, and ranking threats to operations, assets, customers, and critical infrastructure.
Firms must revisit the analysis at least once a year and whenever a business or technology shift materially changes their exposure.
Written procedures must set criteria for classifying threats, judging the confidentiality and availability of systems and nonpublic information, and showing how the program will treat residual risk.
Asrow described risk assessments as the base of a durable security program.
As threats and institutional profiles change, she said, controls and policies have to change with them.
The guidance walks through five practical themes: governance, methodology, scope, documentation, and the link between findings and controls.
On governance, DFS expects senior officers or a designated CISO to oversee the work, with input from operations, legal, compliance, and business units.
Results should reach executive leadership so boards can allocate resources and accept residual risk with eyes open.
Examiners have flagged assessments that sit in a silo and never inform budget or policy decisions.
Methodology should be repeatable.
Organizations need a consistent way to estimate likelihood and impact, distinguish inherent from residual risk, and fold in threat intelligence, scans, penetration tests, and prior incidents.
The department does not mandate a particular framework, but it expects the chosen method to fit the firm’s size and complexity and to stay current.
Scope is another common weak point.
Assessments should rest on a complete, current asset inventory and should map where nonpublic information lives and how it moves.
They should also capture third-party concentration—such as heavy reliance on a single cloud vendor or managed service—and emerging issues, including artificial intelligence, quantum-related cryptography concerns, supply-chain attacks, and geopolitical tension.
Material technology events, such as a core-system migration or an acquisition, should trigger a fresh look before or soon after go-live.
DFS has told firms that controls, monitoring, and documented risk-acceptance decisions should be traceable back to the assessment.
If a finding is ignored or a compensating control is never recorded, the program is not risk-informed.
The original 2017 rule, fully updated as of November 2025, already required this alignment; the new letter simply makes the expectation harder to miss.
The guidance is posted on the department’s refreshed Cybersecurity Resource Center, alongside earlier letters on third-party providers and heightened-threat environments. Supervised entities that treat the annual exercise as a paperwork ritual rather than an operating tool now have a clearer picture of what examiners will ask to see.