
On September 10, 2026, the New York State Department of Financial Services (“NYDFS”) published an Industry Letter (the “Letter”) to regulated entities (“Covered Entities”) addressing what is probably the most frequently asked Part 500 question: “How to Conduct and Use Risk Assessments Required by the DFS Cybersecurity Regulation.” The risk assessment is, by all accounts, the core benchmark of Part 500. It permeates nearly every other substantive requirement of Part 500. Let’s start with … [Read more] about NYDFS Issues Guidance on the Million Dollar Question—How to Conduct Cybersecurity Risk Assessments Under Part 500



