Skip to Primary Navigation

NYDFS issues guidance on conducting cybersecurity risk assessments

Image of laptop computer, computer parts, and the word "cyber" on the laptop screen.
Photo: Jens Schlueter/Getty Images

The guidance explains how covered firms can conduct risk assessments that evaluate, identify, analyze and prioritize cybersecurity risks.


New guidance to clarify cybersecurity-related regulatory requirements “and highlight best practices when designing, conducting, and updating risk assessments” has been issued by the New York State Department of Financial Services (NYDFS).

The guidance explains what the agency means when it mandates that a businesses it oversees has a risk assessment under its signature cybersecurity regulation, 23 NYCRR Part 500. The Part 500 regulations set mandatory cybersecurity standards for banks, insurance companies, and other financial institutions licensed by NYDFS.

The agency noted that this new guidance does not create any new obligations for covered firms.

Risk assessment as evaluation

The guidance states that a risk assessment is “an evaluation that identifies, analyzes, and prioritizes cybersecurity risks taking into account the Covered Entity’s size, complexity, and risk profile. Risk Assessments must be “sufficient to inform the design of the Covered Entity’s cybersecurity program.”

They must be reviewed and updated at least annually and whenever a change in the entity’s business or technology capabilities “causes a material change to [its] cyber risk.” 

NYDFS says the assessments must be carried out in accordance with written policies and procedures and should include:

  • “criteria for evaluating and categorizing identified cybersecurity risks or threats facing the Covered Entity;”
  • “criteria for assessing the confidentiality, integrity, security, and availability of the Covered Entity’s Information Systems and NPI [non-public information], including the adequacy of existing controls in the context of identified risks;”
  • “requirements describing how identified risks are addressed by the cybersecurity program, as based on the Risk Assessment.”

To accomplish this, the agency says the risk assessment “must inform and support the Covered Entity’s decisions regarding control selection, compensating controls, and risk acceptance,” or phrased a different way, the covered firms must be able to show how its risk assessment “informed cybersecurity controls, compensating controls, and risk acceptance decisions.”

In so doing, the firm should craft a risk assessment that it is “tailored to its size, complexity, unique risks, operations, assets, and other circumstances.”

Gaps to remedy

in its guidance, the agency notes some of the common gaps in risk assessments that have “contributed to deficient cybersecurity programs.” These gaps include:

  • Incomplete asset scope and visibility. This includes “having outdated or incomplete asset inventories; failing to identify where NPI resides or flows; and omitting critical business processes, Third-Party Service Providers, cloud environments, or other external dependencies.”
  • Weak or inconsistent methodologies. This would include “failing to consistently identify, analyze, prioritize, and document cybersecurity risks; evaluate the effectiveness of existing controls; or distinguish between inherent and residual risk.”
  • Failure to account for evolving and interconnected risks. This encompasses “emerging technologies, changes in the threat landscape, interdependencies, concentration risk, and single points of failure that could materially affect the Covered Entity’s operations.”
  • Insufficient governance and risk treatment. NYDFS says this would include “failing to assign ownership, document risk response decisions, integrate Risk Assessment results into enterprise governance, or update Risk Assessments following material changes to the business, technology, or threat environment.”
  • Failure to account for or inform the cybersecurity program. The agency said this can result “in policies, controls, and resource decisions that are not demonstrably based on the Covered Entity’s identified cyber risks.”

The agency said stronger cybersecurity programs are designed using “dynamic, data-driven” risk assessments that are integrated into the business’s governance apparatus and are “appropriately scoped, documented, and reviewed.”

The agency reminds firms that its Part 500 cybersecurity regulations requires covered entities to have their written policies and procedures approved at least annually by a senior officer or the covered entity’s “senior governing body.” And the agency notes that “[w]here applicable, Covered Entities must designate a Chief Information Security Officer or a Senior Officer to oversee the Risk Assessment process.”

Scoping the risk assessment

The agency says an effective risk assessment will cover all of the business’s assets (such as hardware, software, and human capital) and address all emerging risks, third-party risks, and concentration risk.

Examples of emerging risk include “adoption or use of artificial intelligence, advances in quantum computing that may affect future cryptographic protections, increasing software supply chain attacks, evolving ransomware techniques, and significant geopolitical tensions or conflict that result is increased nation-state cyber activity.”

The third parties to evaluate for the risks associated in working with them could include “cloud service providers, managed security service providers, software vendors, and payment processors,” among others, says NYDFS.

And, in terms of concentration risk, the guidance notes that concentration risk must be specifically addressed, and it occurs “when multiple critical systems or business functions rely on common infrastructure, cloud service providers, software platforms, managed service providers, or other shared dependencies.”

To manage the risk, entities “should identify potential single points of failure, assess concentration risk, and evaluate how a Cybersecurity Event affecting one dependency could impact other Information Systems or critical business functions,” NYDFS states.

Finally, the agency reminds covered firms to document their findings and actions taken in specific terms and make regular (at least annual) updates to their risk assessment processes as part of their cybersecurity program. A change to the business or to its technology could serve as a material change to their cyber risk, such as a merger or acquisition, a major system migration or a significant and new outsourcing arrangement.

Recent NYDFS cyber guidance

NYDFS has issued several guidance documents and alerts this year, including its August N-Central Vulnerability Alert, which warned covered entities of software exploitation risks, requiring immediate checks on Managed Service Providers (MSPs), patching verification, and incident reporting.

And in May it issued its Guidance on Measures Regulated Entities Should Consider that addressed geopolitical tensions and expanding attack surfaces.

Also in May, the agency published an advisory on Heightened Cybersecurity Risks Associated with Frontier AI Models outlining secure coding, input validation, and human oversight for AI-generated code.

And back in February, it warned of malicious social engineering campaigns where attackers spoof IT help desk caller IDs to deploy malicious links.


Get full access, free for a month

This is a free article. Try Premium free for 28 days to get every article on GRIP and more – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience