NYDFS issues guidance on cyber risk assessments under Part 500, highlights common deficiencies
On September 10, NYDFS issued an industry letter providing guidance on how covered entities should conduct and use cybersecurity risk assessments required under Part 500 of the DFS Cybersecurity Regulation. Based on its examinations and investigations, NYDFS identified “common gaps” in covered entities’ risk assessments, including: (i) incomplete asset scope and visibility, such as outdated inventories and failure to identify where nonpublic information resides or flows; (ii) weak or inconsistent methodologies that fail to distinguish between inherent and residual risk; (iii) failure to account for evolving and interconnected risks, including emerging technologies and concentration risk; (iv) insufficient governance and risk treatment, such as failing to assign ownership or integrate results into enterprise governance; and (v) failure to use risk assessment results to inform the cybersecurity program’s policies, controls and resource decisions.
The guidance outlined five key areas for effective risk assessments: (i) governance and oversight, including cross-functional involvement from business units, compliance and legal; (ii) a defined and repeatable methodology for identifying, analyzing and prioritizing risks; (iii) comprehensive scope covering all assets, emerging risks such as AI and quantum computing, third-party and supply chain risk, and cyber interdependencies and concentration risk; (iv) documentation and traceability linking identified risks to specific controls or compensating measures; and (v) integration of risk assessments into the broader cybersecurity program with updates at least annually or whenever material changes occur. NYDFS encouraged covered entities to review their risk assessments and procedures in light of the guidance, noting that risk assessments should be tailored to the entity’s size, complexity and risk profile. The department stated the guidance does not create new obligations but clarifies existing regulatory requirements and highlights best practices.