NEW York’s Department of Financial Services (DFS) issued new cybersecurity guidance on 10 September 2026 setting out its expectations for risk assessments by DFS-regulated financial entities. The guidance covers their scope, frequency and role in shaping cybersecurity programmes. Under the state’s cybersecurity regulation, entities must review and update risk assessments at least annually, and whenever a business or technology change materially alters their cybersecurity risk.
DFS Acting Superintendent Kaitlin Asrow said risk assessments are the foundation of a strong cybersecurity programme and must adapt as risks and institutions’ profiles change. The department said the guidance creates no new obligations, but clarifies existing regulatory requirements and identifies practices entities should consider. It addresses governance and oversight, methodology, scope, documentation and the integration of assessment results into cybersecurity programmes.
DFS advises entities to reassess risk before or after major system migrations, acquisitions or the introduction of critical systems. Assessments should also examine concentration among third parties, such as reliance on one cloud provider, managed service provider or software platform for multiple critical functions.
The guidance highlights emerging technologies including artificial intelligence, and calls for consideration of their effects on threat exposure, data risks, access controls and third-party dependencies. Entities should use identified risks to decide whether controls, policies, monitoring or risk-acceptance decisions need updating. The DFS regulation took effect in March 2017, with an amendment fully in force from November 2025.