Skip to content
RiskTemplates · The Daily Brief Thursday, September 17, 2026
Wire SEC's $64 Million Croft & Frost Offering Fraud Case: The Warning Email Compliance Teams Cannot Ignore SEP 14

Feature Data Privacy

NYDFS Just Published a 'How-To' for Cyber Risk Assessments. Most of Yours Still Won't Pass.

On September 10, 2026, NYDFS issued comprehensive guidance on how to conduct risk assessments under Part 500. It identifies common failures and what 'based on' actually means. Here's what every covered entity needs to review.

By Rebecca Leung · September 16, 2026 ·
Table of Contents

TL;DR

  • On September 10, 2026, NYDFS published detailed guidance on how to conduct cybersecurity risk assessments under Section 500.2 of Part 500 — with explicit identification of common failures and best practices.
  • The key requirement: the cybersecurity program must be demonstrably “based on” the risk assessment. An assessment that exists but doesn’t actually drive program design is non-compliant — and examiners know how to spot the gap.
  • Common failures identified by NYDFS: scope too narrow, methodology undocumented, assessment not updated after material changes, and findings not reflected in controls decisions.
  • Even limited-exempt entities must conduct a risk assessment. The Order Express consent order ($250K, August 2026) confirmed this.

If you are a covered entity under New York’s Part 500 cybersecurity regulation, you already knew you needed a cybersecurity risk assessment. Section 500.2 has required one since the regulation’s initial effective dates. What you may not have known — at least not precisely — is what NYDFS actually expects when it says the program must be “based on” that assessment.

On September 10, 2026, NYDFS published an industry letter that removes most of the ambiguity. The letter, “Guidance on How to Conduct and Use Risk Assessments Required by the DFS Cybersecurity Regulation,” is not a new rule. It is a detailed articulation of exactly how examiners have been evaluating risk assessments since the regulation took effect — and what gaps they have been finding.

Read it as an advance copy of your next exam question set.

The August Context: Two Enforcement Actions Before the Guidance Dropped

The September 10 guidance did not emerge from a vacuum. Two enforcement actions in the months prior set the stage:

Order Express, Inc. — August 5, 2026 ($250,000)

NYDFS entered a consent order with Order Express, a money transmitter licensed under Part 500, for three core violations: an inadequate cybersecurity risk assessment, a cybersecurity program not designed based on the risk assessment, and missing written cybersecurity policies. The notable element: Order Express qualified for the Part 500 limited exemption — the one that reduces the scope of required controls for smaller covered entities. NYDFS made clear the exemption did not touch the Section 500.2 assessment obligation.

The lesson the guidance reinforces: having a risk assessment document is not the same as having a compliant risk assessment. Order Express had something. It wasn’t sufficient.

Delta Dental Insurance Company — May 2026 ($2.25 million)

NYDFS’s first 2026 Part 500 enforcement action, the Delta Dental settlement — $2.25 million, arising from the 2023 MOVEit Transfer breach — included findings related to cybersecurity program gaps. The case established NYDFS’s willingness to hold licensed entities accountable for program deficiencies, not just incident response failures.

For a more complete breakdown of the Delta Dental findings, see our earlier post on NYDFS Delta Dental enforcement and IR plan gaps.

What Section 500.2 Actually Requires

Section 500.2(b)(1) requires each covered entity to maintain a cybersecurity program designed to protect the confidentiality, integrity, and availability of its information systems. That program must be “based on” a risk assessment.

What does “based on” mean in practice? NYDFS’s guidance answers this directly: the program’s policies, controls, and resource allocation decisions must demonstrably derive from the assessment’s specific findings. Not just correlate with them. Not just coexist with them in the same compliance binder.

If your risk assessment finds that privileged access management is a high-risk area, your cybersecurity program must include controls directly responsive to that finding — and your documentation must be able to show the connection. If your program has strong privileged access controls but your risk assessment never identified privileged access as a priority, you have a documentation problem either way: either the controls were designed without the assessment’s input, or the assessment failed to identify a material risk area.

NYDFS examiners look for the chain of logic from assessment finding → program design decision → implemented control. If that chain breaks anywhere, it raises questions about whether the assessment is actually driving the program.

The Five Elements NYDFS Now Defines

The September 2026 guidance provides specific expectations across five assessment elements. These are, in effect, the rubric NYDFS uses to evaluate whether a risk assessment is substantively compliant:

1. Governance and Oversight

Risk assessment processes should have defined ownership — a designated person or team responsible for conducting, reviewing, and acting on the assessment. Senior management should receive findings and be involved in decisions about risk prioritization and mitigation. The board (or equivalent) should receive meaningful risk reporting connected to assessment outcomes.

A risk assessment that is completed by an analyst, filed in a folder, and never reviewed by senior management fails this standard — regardless of the quality of the assessment content.

2. Methodology

The methodology for identifying, evaluating, and scoring risks must be documented and consistently applied. Ad hoc risk assessments — where different teams evaluate risk using different standards each cycle — do not meet this requirement. The guidance expects a repeatable process with documented criteria for likelihood, impact, and risk scoring.

This is the gap that catches organizations that outsource their risk assessment to a third-party consultant each year with no continuity. Different consultants applying different methodologies produce results you cannot compare cycle-over-cycle, and which don’t demonstrate the iterative improvement NYDFS expects.

3. Scope

The risk assessment must cover the full scope of information systems, data, and operations that are relevant to the covered entity’s cybersecurity risk profile. Common scope failures include:

  • Assessments that cover internal systems but not vendor-hosted systems processing covered entity data
  • Assessments that cover technology but not people and process risks
  • Assessments scoped only to systems under direct IT control, excluding shadow IT, employee-owned devices used for work, or SaaS applications

This connects directly to NYDFS’s separate guidance on third-party cybersecurity, published September 7, 2026 — covered in our earlier analysis of the NYDFS third-party vendor cyber guidance. If third-party service providers are out of your risk assessment scope, your program design will have gaps your examiners will find.

4. Documentation

The assessment and its conclusions must be documented in a way that allows NYDFS to review the process and verify that findings informed the program. This means:

  • Documentation of what was assessed (scope)
  • Documentation of how risk was evaluated (methodology)
  • Documentation of findings by risk area
  • Documentation of decisions made based on findings (including decisions to accept residual risk)
  • Documentation of follow-up actions taken and their status

Verbal risk assessments do not exist for regulatory purposes. If you cannot produce a documented record of the assessment process and its findings, you do not have a compliant assessment.

5. Integration into the Cybersecurity Program

The assessment’s findings must actually change what the cybersecurity program does. New findings must result in new or modified controls, resource allocation shifts, or documented risk acceptance decisions. If the risk assessment produces no changes to the program year after year, that is an examiner red flag — not evidence of a stable environment.

High-risk findings that sit open without remediation or formal risk acceptance also fall here. NYDFS expects to see a clear connection between identified risks and either implemented controls or formally accepted residual risk with documented rationale and approval.

The Annual Review and Material Change Triggers

Part 500 requires risk assessments to be reviewed and updated at least annually. The guidance adds specificity: the annual review should not just be a rubber stamp of the prior year’s document. It should be a genuine reassessment that accounts for changes in threat landscape, the entity’s technology environment, regulatory developments, and lessons learned from incidents and near-misses.

Material changes trigger reassessment outside the annual cycle. What constitutes a material change? The guidance does not provide an exhaustive list, but examples consistent with NYDFS’s enforcement posture include:

  • Major new system deployments or migrations (including cloud migrations)
  • Acquisition of a new business or material expansion into new products
  • Significant changes to the vendor ecosystem (adding or replacing critical third parties)
  • Significant changes to workforce or organizational structure affecting IT access
  • New product launches that introduce new customer data types or processing activities
  • Discovery of a cybersecurity incident or near-miss that reveals an unaddressed risk

The practical implication: organizations that conduct a risk assessment in January and then have a major cloud migration in July need to reassess. “Annual review” is the floor, not the ceiling.

What This Means for Your Compliance Program

The September 2026 guidance translates into a specific set of action items for NYDFS-covered entities:

Review your risk assessment documentation for the five elements. Does your assessment document its methodology? Does it show governance review by senior management? Does it cover third-party systems? Does it connect findings to program changes?

Trace the connection between your last risk assessment and your current program. Can you show, for each major control area in your cybersecurity program, which assessment finding it responds to? If you cannot draw that map, you have a documentation gap at minimum — and potentially a substantive program gap.

Check your material-change triggers. What has changed about your business or technology environment since your last full assessment? Have those changes been assessed?

Confirm limited-exempt entities are included. If your organization has affiliates or subsidiaries that qualify for Part 500’s limited exemption, they still need risk assessments. The exemption reduces what controls are required — it does not eliminate the Section 500.2 obligation.

Review your KRI program for cyber metrics. A well-designed cybersecurity risk assessment connects directly to the key risk indicators you use to monitor the program between assessment cycles. If your KRI program is not tracking the cyber risks your assessment identifies as highest priority, the two programs are running in parallel rather than integrated.

The FTC Safeguards Rule requires similar risk assessments for non-bank financial institutions. If you are managing both programs, the FTC Safeguards Rule requirements breakdown covers the parallels and the key differences between what FTC and NYDFS each expect.

So What?

The September 2026 NYDFS guidance is not a new rule. It is an examiner’s handbook published in advance. Every element it describes — governance, methodology, scope, documentation, integration — is something NYDFS has already been testing in examinations. The guidance just makes explicit what was implicit.

The organizations that will perform well in their next exam are the ones that read this guidance as a self-assessment checklist and work through it before the examiners arrive. The organizations that will struggle are the ones that have risk assessment documents that satisfy the optics but can’t demonstrate the chain of logic from assessment finding to program design.

The Order Express and Delta Dental enforcement actions were not edge cases. NYDFS has made clear it will find and act on cybersecurity program deficiencies. The September 2026 guidance is the regulator’s way of saying: here is exactly what we are looking for.


External Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did NYDFS publish on September 10, 2026?
NYDFS published an industry letter titled 'Guidance on How to Conduct and Use Risk Assessments Required by the DFS Cybersecurity Regulation.' The guidance details NYDFS's regulatory expectations for cybersecurity risk assessments under Section 500.2, identifies common compliance problems, and provides best practices for governance, methodology, scope, documentation, and program integration. It does not create new legal obligations — it describes how existing obligations will be examined.
What does 'based on' mean in Section 500.2 of Part 500?
Section 500.2 requires that a covered entity's cybersecurity program be 'based on' its risk assessment. NYDFS interprets this to mean that the program's policies, controls, and resource allocation decisions must demonstrably derive from the assessment's specific findings — not just exist in parallel with it. A risk assessment that finds weak access controls but does not result in strengthened access controls is not a compliant use of the risk assessment.
How often does Part 500 require cybersecurity risk assessments to be updated?
Part 500 requires risk assessments to be reviewed and updated at least annually. Additionally, covered entities must conduct reassessments whenever a change in the business or technology causes a material change to their cyber risk profile. This includes events such as significant new system deployments, material acquisitions, major workforce changes, or new product launches.
What are the most common problems NYDFS has found with cybersecurity risk assessments?
Per the September 2026 guidance, NYDFS identified common problems including: assessments that fail to cover the full scope of information systems and data, risk assessments not actually informing cybersecurity program design and controls decisions, methodology not documented or inconsistently applied, and assessments not updated following material changes to the business or technology environment.
Does the guidance apply to limited-exempt entities under Part 500?
The core obligation in Section 500.2 to conduct a risk assessment is not suspended by limited-exempt status. As demonstrated by the Order Express consent order (August 5, 2026), even entities that qualify for the limited exemption from full Part 500 compliance must still maintain a cybersecurity risk assessment sufficient to inform the design of their program. The exemption reduces the scope of required controls, not the assessment obligation.
Which NYDFS enforcement actions relate to cybersecurity risk assessment failures?
Two recent enforcement actions center on risk assessment failures. In August 2026, NYDFS entered a $250,000 consent order with Order Express, Inc. (a money transmitter) for an inadequate cybersecurity risk assessment and a program not designed from the assessment's findings. In May 2026, NYDFS settled with Delta Dental Insurance Company for $2.25 million, in part due to cybersecurity program deficiencies following the 2023 MOVEit Transfer breach.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

KRI Library (132 Key Risk Indicators)

132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.

◆ Keep reading

Related posts.

Data Privacy

The FTC Safeguards Rule's 9 Requirements Have Been Enforceable for Three Years. Here's What Non-Bank Financial Institutions Are Still Getting Wrong.

The FTC Safeguards Rule's 9 information security requirements became fully enforceable in June 2023, and breach notification requirements kicked in May 2024. Enforcement is now active across mortgage brokers, auto dealers, personal finance apps, and tax preparers. Here's what the 9 elements actually require and what FTC examiners are finding.

Sep 12, 2026

Data Privacy

FTC Chairman Ferguson Says a Privacy Enforcement Surge Is Coming in H2 2026. Here's What Financial Services Companies Need in Place.

FTC Chairman Andrew Ferguson publicly warned that reporters covering the FTC will 'have a hard time keeping up' with the number of privacy enforcement cases coming in the second half of 2026. The Kochava settlement and new Section 5 standalone data-security cases telegraph exactly what's in the crosshairs. Here's what financial services companies need to have documented before the cases start landing.

Sep 9, 2026

Data Privacy

CalPrivacy Has Issued Eight Data Broker Fines and Is Still Going. What the September 2026 Enforcement Advisory Means for Your Fintech.

California's Privacy Protection Agency issued Enforcement Advisory 2026-01 on September 3, making clear that inaccurate data broker registration is a live $200-per-day penalty risk. Two August 2026 settlements and eight prior enforcement actions signal that CalPrivacy is done with warnings. Here's what fintech compliance teams need to know.

Sep 7, 2026

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.