Skip to content
Home » News » New York tells financial firms to update cyber risk assessments at least annually

New York tells financial firms to update cyber risk assessments at least annually

New York tells financial firms to update cyber risk assessments at least annually

Banks, insurers and other financial businesses regulated by New York must review and update their cybersecurity risk assessments at least once a year and whenever major business or technology changes alter their exposure. The state Department of Financial Services issued guidance Thursday clarifying how those assessments should shape each regulated entity’s cybersecurity program.

The guidance addresses the scope, frequency, governance, methodology and documentation of risk assessments. DFS said it does not create new obligations but explains requirements under the department’s existing cybersecurity regulation and identifies practices firms should consider.


Acting Superintendent Kaitlin Asrow said changing threats and shifting institutional risk profiles require cybersecurity programs to adapt. DFS described risk assessments as the foundation for determining which controls and policies an organization needs.

The department said a firm should reassess its risk before or after a material technology change, including a major system migration, acquisition or rollout of a new critical system. Those reviews are intended to identify new vulnerabilities before they become embedded in routine operations.

Regulated entities should also examine concentrated third-party risk, according to the guidance. That includes determining whether multiple critical functions depend on the same cloud provider, managed service provider, software platform or other shared service.

DFS said assessments should account for emerging technology as well. A firm adopting artificial intelligence or another new tool should evaluate how it changes threat exposure, data risk, access controls and reliance on outside vendors.

The agency also expects companies to connect identified risks to decisions about cybersecurity controls. Firms should determine whether existing policies, monitoring systems, safeguards or formal risk-acceptance decisions need to be strengthened or updated.

Effective assessments should include documented governance and oversight, a defined methodology and a scope broad enough to cover the entity’s operations and technology, DFS said. The results should be integrated into the organization’s broader cybersecurity program rather than treated as a stand-alone compliance exercise.

New York’s financial-services cybersecurity regulation took effect in March 2017. An amended version was fully in effect by November 2025 and was designed to strengthen cybersecurity governance and protections for New York businesses and consumers.

The new guidance and related compliance resources are available through the department’s Cybersecurity Resource Center. DFS said the center has been refreshed to make guidance, frequently asked questions and other materials easier to navigate.