Skip to content
NYDFS Releases Guidance on Cybersecurity Risk Assessments for Financial Entities

NYDFS Releases Guidance on Cybersecurity Risk Assessments for Financial Entities

First seen 15 Sep 2026, 02:22 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 04:21 UTC
  • NYDFS issued guidance on cybersecurity risk assessments on September 10, 2026.
  • Risk assessments are crucial for cybersecurity programs, not just compliance.
  • Common deficiencies in risk assessments include incomplete asset inventories and weak methodologies.

On September 10, 2026, the New York State Department of Financial Services (NYDFS) published new guidance on conducting cybersecurity risk assessments for regulated financial services entities. The guidance emphasizes that risk assessments are essential for effective cybersecurity programs and not just compliance. It identifies common deficiencies observed in risk assessments, including incomplete asset inventories and weak methodologies. Covered entities are required to conduct risk assessments at least annually and update them with any significant changes in business or technology. The guidance follows previous advisories addressing heightened cyber threats, particularly from advanced artificial intelligence models. Although it does not impose new legal obligations, it sets expectations for NYDFS supervision and enforcement.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-05-01
NYDFS issues industry letters
The NYDFS sent letters to the industry addressing heightened cyber threats and risks from frontier AI models.
Mayerbrown
2026-09-10
NYDFS publishes cybersecurity guidance
The NYDFS released guidance outlining expectations for conducting cybersecurity risk assessments for financial services entities.
Mayerbrown

More articles in this cluster (2)