DFS Issues New Cybersecurity Guidance on Risk Assessments for Financial Services Entities
Guidance Emphasizes Importance of Ongoing Risk Assessments and Reminds Entities of Compliance Obligations Under Nation-Leading Cybersecurity Regulation
New York State Department of Financial Services (DFS) Acting Superintendent Kaitlin Asrow today issued new cybersecurity guidance outlining the Department’s expectations for DFS-regulated entities’ on conducting risk assessments sufficient to inform their cybersecurity programs. The guidance outlines requirements regarding scope, frequency, and the role of risk assessments in informing entities cybersecurity programs. Under the Department’s nation-leading cybersecurity regulation, regulated entities are required to review and update risk assessments at least annually and whenever a change in the business or technology causes a material change to the entities’ cybersecurity risk.
“Risk assessments are the foundation of a strong cybersecurity program,” said Department of Financial Services Acting Superintendent Kaitlin Asrow. “As cybersecurity risks evolve and institutions’ risk profiles change, it is critical that their cybersecurity programs adapt, and this guidance outlines those expectations.”
The guidance does not impose new obligations or requirements on regulated entities. Rather, the guidance is intended to clarify regulatory requirements under the Department’s cybersecurity regulation and share best practices that entities should consider implementing. The guidance outlines key elements of effective risk assessment, including expectations related to governance and oversight, methodology, scope, documentation, and the need to integrate assessments into cybersecurity programs. Factors entities should consider when performing a risk assessment include:
Third-Party Risk: Evaluating whether multiple critical functions depend on the same cloud provider, managed service provider, software platform, or other common dependency.
Emerging Risk: Considering how adoption of AI or other emerging technologies changes the entity’s threat exposure, data risks, access controls, or third-party dependencies.
Risk-Informed Controls: Assessing identified risks to determine whether existing controls, policies, monitoring, or risk acceptance decisions need to be strengthened or updated.
A copy of the guidance is available on the Department’s newly refreshed Cybersecurity Resource Center, a streamlined, easier-to-navigate hub for cybersecurity guidance, resources, and frequently asked questions.
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.