NYS DFS Issues New Cybersecurity Guidance on Risk Assessments for Financial Services Entities
New York DFS issued cybersecurity guidance defining expectations for risk assessments that regulated financial services entities must conduct.
On September 10, 2026, NYS DFS Acting Superintendent Kaitlin Asrow issued new cybersecurity guidance on conducting risk assessments sufficient to inform cybersecurity programs. The guidance covers scope, frequency, and the role of assessments for DFS-regulated financial services entities. It does not describe any incident or vulnerability, but sets regulatory compliance expectations under DFS cybersecurity rules.