Mayerbrown NYDFS Releases Guidance on Cybersecurity Risk Assessments for Financial Entities
Article Content
- •NYDFS issued guidance on cybersecurity risk assessments on September 10, 2026.
- •Risk assessments are crucial for cybersecurity programs, not just compliance.
- •Common deficiencies in risk assessments include incomplete asset inventories and weak methodologies.
On September 10, 2026, the New York State Department of Financial Services (NYDFS) published new guidance on conducting cybersecurity risk assessments for regulated financial services entities. The guidance emphasizes that risk assessments are essential for effective cybersecurity programs and not just compliance. It identifies common deficiencies observed in risk assessments, including incomplete asset inventories and weak methodologies. Covered entities are required to conduct risk assessments at least annually and update them with any significant changes in business or technology. The guidance follows previous advisories addressing heightened cyber threats, particularly from advanced artificial intelligence models. Although it does not impose new legal obligations, it sets expectations for NYDFS supervision and enforcement.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…