Feature Data Privacy
NYDFS Just Published a 'How-To' for Cyber Risk Assessments. Most of Yours Still Won't Pass.
On September 10, 2026, NYDFS issued comprehensive guidance on how to conduct risk assessments under Part 500. It identifies common failures and what 'based on' actually means. Here's what every covered entity needs to review.
Table of Contents
TL;DR
- On September 10, 2026, NYDFS published detailed guidance on how to conduct cybersecurity risk assessments under Section 500.2 of Part 500 — with explicit identification of common failures and best practices.
- The key requirement: the cybersecurity program must be demonstrably “based on” the risk assessment. An assessment that exists but doesn’t actually drive program design is non-compliant — and examiners know how to spot the gap.
- Common failures identified by NYDFS: scope too narrow, methodology undocumented, assessment not updated after material changes, and findings not reflected in controls decisions.
- Even limited-exempt entities must conduct a risk assessment. The Order Express consent order ($250K, August 2026) confirmed this.
If you are a covered entity under New York’s Part 500 cybersecurity regulation, you already knew you needed a cybersecurity risk assessment. Section 500.2 has required one since the regulation’s initial effective dates. What you may not have known — at least not precisely — is what NYDFS actually expects when it says the program must be “based on” that assessment.
On September 10, 2026, NYDFS published an industry letter that removes most of the ambiguity. The letter, “Guidance on How to Conduct and Use Risk Assessments Required by the DFS Cybersecurity Regulation,” is not a new rule. It is a detailed articulation of exactly how examiners have been evaluating risk assessments since the regulation took effect — and what gaps they have been finding.
Read it as an advance copy of your next exam question set.
The August Context: Two Enforcement Actions Before the Guidance Dropped
The September 10 guidance did not emerge from a vacuum. Two enforcement actions in the months prior set the stage:
Order Express, Inc. — August 5, 2026 ($250,000)
NYDFS entered a consent order with Order Express, a money transmitter licensed under Part 500, for three core violations: an inadequate cybersecurity risk assessment, a cybersecurity program not designed based on the risk assessment, and missing written cybersecurity policies. The notable element: Order Express qualified for the Part 500 limited exemption — the one that reduces the scope of required controls for smaller covered entities. NYDFS made clear the exemption did not touch the Section 500.2 assessment obligation.
The lesson the guidance reinforces: having a risk assessment document is not the same as having a compliant risk assessment. Order Express had something. It wasn’t sufficient.
Delta Dental Insurance Company — May 2026 ($2.25 million)
NYDFS’s first 2026 Part 500 enforcement action, the Delta Dental settlement — $2.25 million, arising from the 2023 MOVEit Transfer breach — included findings related to cybersecurity program gaps. The case established NYDFS’s willingness to hold licensed entities accountable for program deficiencies, not just incident response failures.
For a more complete breakdown of the Delta Dental findings, see our earlier post on NYDFS Delta Dental enforcement and IR plan gaps.
What Section 500.2 Actually Requires
Section 500.2(b)(1) requires each covered entity to maintain a cybersecurity program designed to protect the confidentiality, integrity, and availability of its information systems. That program must be “based on” a risk assessment.
What does “based on” mean in practice? NYDFS’s guidance answers this directly: the program’s policies, controls, and resource allocation decisions must demonstrably derive from the assessment’s specific findings. Not just correlate with them. Not just coexist with them in the same compliance binder.
If your risk assessment finds that privileged access management is a high-risk area, your cybersecurity program must include controls directly responsive to that finding — and your documentation must be able to show the connection. If your program has strong privileged access controls but your risk assessment never identified privileged access as a priority, you have a documentation problem either way: either the controls were designed without the assessment’s input, or the assessment failed to identify a material risk area.
NYDFS examiners look for the chain of logic from assessment finding → program design decision → implemented control. If that chain breaks anywhere, it raises questions about whether the assessment is actually driving the program.
The Five Elements NYDFS Now Defines
The September 2026 guidance provides specific expectations across five assessment elements. These are, in effect, the rubric NYDFS uses to evaluate whether a risk assessment is substantively compliant:
1. Governance and Oversight
Risk assessment processes should have defined ownership — a designated person or team responsible for conducting, reviewing, and acting on the assessment. Senior management should receive findings and be involved in decisions about risk prioritization and mitigation. The board (or equivalent) should receive meaningful risk reporting connected to assessment outcomes.
A risk assessment that is completed by an analyst, filed in a folder, and never reviewed by senior management fails this standard — regardless of the quality of the assessment content.
2. Methodology
The methodology for identifying, evaluating, and scoring risks must be documented and consistently applied. Ad hoc risk assessments — where different teams evaluate risk using different standards each cycle — do not meet this requirement. The guidance expects a repeatable process with documented criteria for likelihood, impact, and risk scoring.
This is the gap that catches organizations that outsource their risk assessment to a third-party consultant each year with no continuity. Different consultants applying different methodologies produce results you cannot compare cycle-over-cycle, and which don’t demonstrate the iterative improvement NYDFS expects.
3. Scope
The risk assessment must cover the full scope of information systems, data, and operations that are relevant to the covered entity’s cybersecurity risk profile. Common scope failures include:
- Assessments that cover internal systems but not vendor-hosted systems processing covered entity data
- Assessments that cover technology but not people and process risks
- Assessments scoped only to systems under direct IT control, excluding shadow IT, employee-owned devices used for work, or SaaS applications
This connects directly to NYDFS’s separate guidance on third-party cybersecurity, published September 7, 2026 — covered in our earlier analysis of the NYDFS third-party vendor cyber guidance. If third-party service providers are out of your risk assessment scope, your program design will have gaps your examiners will find.
4. Documentation
The assessment and its conclusions must be documented in a way that allows NYDFS to review the process and verify that findings informed the program. This means:
- Documentation of what was assessed (scope)
- Documentation of how risk was evaluated (methodology)
- Documentation of findings by risk area
- Documentation of decisions made based on findings (including decisions to accept residual risk)
- Documentation of follow-up actions taken and their status
Verbal risk assessments do not exist for regulatory purposes. If you cannot produce a documented record of the assessment process and its findings, you do not have a compliant assessment.
5. Integration into the Cybersecurity Program
The assessment’s findings must actually change what the cybersecurity program does. New findings must result in new or modified controls, resource allocation shifts, or documented risk acceptance decisions. If the risk assessment produces no changes to the program year after year, that is an examiner red flag — not evidence of a stable environment.
High-risk findings that sit open without remediation or formal risk acceptance also fall here. NYDFS expects to see a clear connection between identified risks and either implemented controls or formally accepted residual risk with documented rationale and approval.
The Annual Review and Material Change Triggers
Part 500 requires risk assessments to be reviewed and updated at least annually. The guidance adds specificity: the annual review should not just be a rubber stamp of the prior year’s document. It should be a genuine reassessment that accounts for changes in threat landscape, the entity’s technology environment, regulatory developments, and lessons learned from incidents and near-misses.
Material changes trigger reassessment outside the annual cycle. What constitutes a material change? The guidance does not provide an exhaustive list, but examples consistent with NYDFS’s enforcement posture include:
- Major new system deployments or migrations (including cloud migrations)
- Acquisition of a new business or material expansion into new products
- Significant changes to the vendor ecosystem (adding or replacing critical third parties)
- Significant changes to workforce or organizational structure affecting IT access
- New product launches that introduce new customer data types or processing activities
- Discovery of a cybersecurity incident or near-miss that reveals an unaddressed risk
The practical implication: organizations that conduct a risk assessment in January and then have a major cloud migration in July need to reassess. “Annual review” is the floor, not the ceiling.
What This Means for Your Compliance Program
The September 2026 guidance translates into a specific set of action items for NYDFS-covered entities:
Review your risk assessment documentation for the five elements. Does your assessment document its methodology? Does it show governance review by senior management? Does it cover third-party systems? Does it connect findings to program changes?
Trace the connection between your last risk assessment and your current program. Can you show, for each major control area in your cybersecurity program, which assessment finding it responds to? If you cannot draw that map, you have a documentation gap at minimum — and potentially a substantive program gap.
Check your material-change triggers. What has changed about your business or technology environment since your last full assessment? Have those changes been assessed?
Confirm limited-exempt entities are included. If your organization has affiliates or subsidiaries that qualify for Part 500’s limited exemption, they still need risk assessments. The exemption reduces what controls are required — it does not eliminate the Section 500.2 obligation.
Review your KRI program for cyber metrics. A well-designed cybersecurity risk assessment connects directly to the key risk indicators you use to monitor the program between assessment cycles. If your KRI program is not tracking the cyber risks your assessment identifies as highest priority, the two programs are running in parallel rather than integrated.
The FTC Safeguards Rule requires similar risk assessments for non-bank financial institutions. If you are managing both programs, the FTC Safeguards Rule requirements breakdown covers the parallels and the key differences between what FTC and NYDFS each expect.
So What?
The September 2026 NYDFS guidance is not a new rule. It is an examiner’s handbook published in advance. Every element it describes — governance, methodology, scope, documentation, integration — is something NYDFS has already been testing in examinations. The guidance just makes explicit what was implicit.
The organizations that will perform well in their next exam are the ones that read this guidance as a self-assessment checklist and work through it before the examiners arrive. The organizations that will struggle are the ones that have risk assessment documents that satisfy the optics but can’t demonstrate the chain of logic from assessment finding to program design.
The Order Express and Delta Dental enforcement actions were not edge cases. NYDFS has made clear it will find and act on cybersecurity program deficiencies. The September 2026 guidance is the regulator’s way of saying: here is exactly what we are looking for.
External Sources:
- NYDFS Guidance on How to Conduct and Use Risk Assessments Required by the DFS Cybersecurity Regulation (September 10, 2026)
- NYDFS Issues Extensive Guidance on Cybersecurity Risk Assessments — Mayer Brown
- NYDFS Clarifies How Financial Firms Must Use Cyber Risk Assessments — Crowdfund Insider
- NYDFS Levies $250,000 Fine on Licensee for Inadequate Cyber Risk Assessment — Data Protection Report
- New York DFS Fines Delta Dental $2.25 Million for Cybersecurity Rule Violations — Pillsbury Law
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did NYDFS publish on September 10, 2026?
What does 'based on' mean in Section 500.2 of Part 500?
How often does Part 500 require cybersecurity risk assessments to be updated?
What are the most common problems NYDFS has found with cybersecurity risk assessments?
Does the guidance apply to limited-exempt entities under Part 500?
Which NYDFS enforcement actions relate to cybersecurity risk assessment failures?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Keep reading
Related posts.
Data Privacy
The FTC Safeguards Rule's 9 Requirements Have Been Enforceable for Three Years. Here's What Non-Bank Financial Institutions Are Still Getting Wrong.
The FTC Safeguards Rule's 9 information security requirements became fully enforceable in June 2023, and breach notification requirements kicked in May 2024. Enforcement is now active across mortgage brokers, auto dealers, personal finance apps, and tax preparers. Here's what the 9 elements actually require and what FTC examiners are finding.
Sep 12, 2026
Data Privacy
FTC Chairman Ferguson Says a Privacy Enforcement Surge Is Coming in H2 2026. Here's What Financial Services Companies Need in Place.
FTC Chairman Andrew Ferguson publicly warned that reporters covering the FTC will 'have a hard time keeping up' with the number of privacy enforcement cases coming in the second half of 2026. The Kochava settlement and new Section 5 standalone data-security cases telegraph exactly what's in the crosshairs. Here's what financial services companies need to have documented before the cases start landing.
Sep 9, 2026
Data Privacy
CalPrivacy Has Issued Eight Data Broker Fines and Is Still Going. What the September 2026 Enforcement Advisory Means for Your Fintech.
California's Privacy Protection Agency issued Enforcement Advisory 2026-01 on September 3, making clear that inaccurate data broker registration is a live $200-per-day penalty risk. Two August 2026 settlements and eight prior enforcement actions signal that CalPrivacy is done with warnings. Here's what fintech compliance teams need to know.
Sep 7, 2026