On September 10, 2026, the New York State Department of Financial Services (“NYDFS”) published an Industry Letter (the “Letter”) to regulated entities (“Covered Entities”) addressing what is probably the most frequently asked Part 500 question: “How to Conduct and Use Risk Assessments Required by the DFS Cybersecurity Regulation.”
The risk assessment is, by all accounts, the core benchmark of Part 500. It permeates nearly every other substantive requirement of Part 500.
Let’s start with the basics. A risk assessment—by NYDFS’s definition—is “the process of identifying, estimating and prioritizing cybersecurity risks to organizational operations (including mission, functions, image and reputation), organizational assets, individuals, customers, consumers, other organizations and critical infrastructure resulting from the operation of an information system. Risk assessments incorporate threat and vulnerability analyses and consider mitigations provided by security controls planned or in place.” And how will it be used? NYDFS states it plainly: “The Department expects each Covered Entity to be able to demonstrate how its Risk Assessment informed cybersecurity controls, compensating controls, and risk acceptance decisions.”
This is, as with all things, easier said than done. And while the Letter states that it does not create new legal obligations, it does provide specificity surrounding NYDFS’s expectations, flags common issues, and identifies best practices. Regardless of whether the Letter does or does not identify net new obligations, it is safe to assume that NYDFS will rely heavily on this interpretation in future examinations and investigations.
What NYDFS Says Gets Missed
Leveraging its historical examinations and investigations, NYDFS has identified certain “gaps” in risk assessments that, in its view, contribute to a “deficient” program:
- Incomplete asset scope and visibility, including outdated or incomplete asset inventories; failing to identify where NPI resides or flows; and omitting critical business processes, Third-Party Service Providers,11 cloud environments, or other external dependencies.
- Weak or inconsistent methodologies, including failing to consistently identify, analyze, prioritize, and document cybersecurity risks; evaluate the effectiveness of existing controls; or distinguish between inherent and residual risk.
- Failure to account for evolving and interconnected risks, including emerging technologies, changes in the threat landscape, interdependencies, concentration risk, and single points of failure that could materially affect the Covered Entity’s operations.
- Insufficient governance and risk treatment, including failing to assign ownership, document risk response decisions, integrate Risk Assessment results into enterprise governance, or update Risk assessments following material changes to the business, technology, or threat environment.
- Failure to account for or inform the cybersecurity program, resulting in policies, controls, and resource decisions that are not demonstrably based on the Covered Entity’s identified cyber risks.
The Risk Assessment NYDFS Says It Wants
The Letter hones in on five core areas of the risk assessment that are integral, in its assessment, to a successful, mature program: (1) Governance and Oversight; (2) Defined and Repeatable Methodology; (3) Scope and Coverage; (4) Documentation and Traceability; and (5) Integration and Updates to Risk Assessments.
Governance and Oversight
Second to maybe only AI, the Letter starts with recommendations regarding the top buzzword of 2026: Governance. The Department’s guidance here is simple: risk management is a collective responsibility. While the risk assessment process must be overseen by the top security official, it should be cross-functional in nature to ensure there is a comprehensive understanding of risk enterprise wide.
Though not mandatory, the Letter also strongly encourages reporting to senior management and using the risk assessment to help “make informed decisions regarding resource allocation, cybersecurity investments, control selection, and risk acceptance.”
Defined and Repeatable Methodology
A recurring theme throughout the Letter is the need for a documented, repeatable methodology. Process, process, process. NYDFS expects covered entities to establish a structured mechanism for identifying, analyzing, and prioritizing risks using consistent criteria. Among the inputs to be considered, NYDFS identifies the following:
- Threat intelligence, incident trend analysis, vulnerability scans, and penetration testing;
- Findings from audits or prior risk assessments;
- Technical threats (whether internal or external), including malicious actors, system misconfigurations, insider misuse, and process failures;
- Administrative controls;
- Natural disasters that could cause power outages, disrupt data centers, and impair system availability;
- Third party dependencies that could be exploited by bad actors.
NYDFS emphasizes the need to provide reasonable estimates of the likelihood and impact of risks and to apply consistent rating criteria to ensure an apples-to-apples comparison over time. And as for what “impacts” should be considered, NYDFS identifies a broad range, including:
- Exposure of sensitive personal information;
- Financial losses;
- Business interruptions;
- Regulatory or legal liability;
- Reputational damage; and
- Costs of recovery and replacement.
Although NYDFS does not mandate any particular framework, it does strongly suggest that the use of an existing, recognized framework (for instance, NIST CSF 2.0, the Cyber Risk Institute Profile, and ISO 27005) leads to a more consistent and repeatable methodology.
NYDFS closes the section with advice on how to bring a program to the next level of maturity—applying a consistent risk criteria beyond just the organization itself, but also to its third-party risk management, IT operations, and BCDR planning.
Scope and Coverage
Once Covered Entities determine the method of conducting their risk assessment, the next step is to consider its scope. The Department recommends focusing on any internal and external factors that may materially affect cyber risk. The Letter specifically highlights four areas of emphasis: all assets, emerging risks, third-party risk, and concentration risk.
- All Assets. NYDFS warns that the failure to account for assets in the risk assessment process in turn leads to an incomplete view of risk and, at times, can result in material gaps in the cybersecurity program.
- Emerging Risks. Consistent with NYDFS’s recent guidance regarding the heightened cybersecurity threat landscape, Covered Entities should be cognizant of advancements in artificial intelligence, evolving ransomware techniques, supply chain threats, and geopolitical developments that may affect the cyber threat landscape.
- Third-Party Risk. Consistent with its prior guidance regarding the risks associated with Third-Party Service Providers, NYDFS recommends that Covered Entities evaluate third-party risk based on factors such as connectivity, data access, operational dependency and the sensitivity of the information involved.
- Concentration Risk. The Department encourages thinking holistically. For example, a company may use the same cloud provider, software platform, identity provider, or managed service provider across multiple business functions. Each relationship may appear low risk on its own, but if that shared provider suffers a cyberattack or outage, it could disrupt numerous critical systems at the same time.
Documentation and Traceability
The Letters places substantial emphasis on documentation. Covered entities should be able to demonstrate not only that risks were identified, but also how those risks informed cybersecurity controls, compensating controls, remediation activities, and risk acceptance decisions.
NYDFS recommends maintaining documentation that links identified risks to specific mitigation measures and preserving the rationale supporting management decisions. The Department also encourages the use of a risk register or similar tracking mechanism to monitor remediation efforts and changes in residual risk over time.
From an examination perspective, this portion of the guidance suggests that regulators will increasingly expect organizations to show evidence of decision-making rather than simply produce policies or assessment reports.
Integration and Updates to Risk Assessments
NYDFS reiterates that risk assessments cannot be treated as static, annual compliance exercises. While annual reviews remain mandatory, covered entities must also update assessments whenever material changes occur. Examples identified by the Department include mergers and acquisitions, major system migrations, significant outsourcing arrangements, adoption of emerging technologies, evolving threat actor tactics, and major geopolitical events.
The Letter strongly favors continuous or regularly refreshed assessment processes that evolve alongside changes in technology, business operations, and the threat environment.
But What Does This Mean?
For regulated entities, the most immediate takeaway is that risk assessments should be reviewed against the Letter to determine whether they:
- Capture all relevant assets and data flows;
- Address emerging and interconnected cyber risks;
- Include robust governance and stakeholder involvement;
- Create a clear linkage between risks and cybersecurity controls; and
- Support ongoing updates in response to changes in business operations and technology.
NYDFS’s latest guidance provides a detailed picture of what the Department considers a mature, defensible cybersecurity risk assessment program. While framed as interpretive guidance, it is likely to serve as a benchmark in future examinations, investigations, and enforcement actions. Organizations subject to Part 500 should view the publication as both a compliance resource and a preview of the standards against which their risk assessments may increasingly be judged.
