NYS DFS Issues New Cybersecurity Guidance on Risk Assessments for Financial Services Entities
New York DFS issued cybersecurity guidance defining expectations for risk assessments that regulated financial services entities must conduct.
On September 10, 2026, NYS DFS Acting Superintendent Kaitlin Asrow issued new cybersecurity guidance on conducting risk assessments sufficient to inform cybersecurity programs. The guidance covers scope, frequency, and the role of assessments for DFS-regulated financial services entities. It does not describe any incident or vulnerability, but sets regulatory compliance expectations under DFS cybersecurity rules.
- NYS DFS guidance issued September 10, 2026 by Acting Superintendent Kaitlin Asrow
- Defines expectations for risk assessments underlying cybersecurity programs
- Covers scope and frequency requirements for DFS-regulated entities
- Compliance-relevant for New York financial services firms
New York State Department of Financial Services (DFS): September 10, 2026 New York State Department of Financial Services (DFS) Acting Superintendent Kaitlin Asrow today issued new cybersecurity guidance outlining the Department’s expectations for DFS-regulated entities’ on conducting risk assessments sufficient to inform their cybersecurity programs. The guidance outlines requirements regarding scope, frequency, and the role... Source
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at databreaches.net.