New York State Department of Financial Services (DFS) Acting Superintendent Kaitlin Asrow has issued new cybersecurity guidance clarifying the Department’s expectations for regulated entities when conducting risk assessments that inform their cybersecurity programmes.
The guidance addresses the scope, frequency, and practical role of risk assessments in shaping cybersecurity strategies. Under New York’s cybersecurity regulation, DFS-regulated entities must review and update their risk assessments at least once every year and whenever a business or technology change materially alters their cybersecurity risk profile.
“Risk assessments are the foundation of a strong cybersecurity program,” said Asrow. “As cybersecurity risks evolve and institutions’ risk profiles change, it is critical that their cybersecurity programs adapt, and this guidance outlines those expectations.”
Guidance clarifies existing cybersecurity obligations
DFS said the guidance does not introduce new obligations or regulatory requirements. Instead, it is intended to clarify existing expectations under the Department’s cybersecurity regulation while highlighting best practices that regulated entities should consider adopting.
The document identifies several core components of an effective risk assessment, including governance and oversight, assessment methodology, scope, documentation, and the integration of findings into wider cybersecurity programmes.
Among the factors regulated entities should consider are:
- Material technology changes: Reviewing cybersecurity risks before or after major system migrations, acquisitions, or the deployment of new critical systems.
- Third-party risk: Assessing whether several critical functions rely on the same cloud provider, managed service provider, software platform, or other shared dependency.
- Emerging risks: Evaluating how artificial intelligence and other emerging technologies may affect threat exposure, data security, access controls, and third-party dependencies.
- Risk-informed controls: Determining whether identified risks require updates to existing controls, policies, monitoring arrangements, or risk acceptance decisions.
Updated regulation strengthens cybersecurity oversight
New York’s DFS cybersecurity regulation took effect in March 2017. An updated amendment, which became fully effective in November 2025, was designed to strengthen cybersecurity governance, mitigate emerging risks, and improve protections for businesses and consumers across the state.
A copy of the new guidance is available through DFS’s refreshed Cybersecurity Resource Center, which provides a more streamlined platform for cybersecurity guidance, resources, and frequently asked questions.
Comments