The New York Department of Financial Services released guidance on September 10, 2026, detailing how financial institutions must conduct Part 500 cybersecurity risk assessments. Examiners have identified recurring failures, including incomplete asset inventories, inconsistent risk methodologies, and the exclusion of third-party and concentration risks. The guidance emphasizes that cybersecurity programs must be directly traceable to identified risks to ensure regulatory compliance.
Relevant URL: https://www.mayerbrown.com/en/insights/publications/2026/09/nydfs-issues-extensive-guidance-on-cybersecurity-risk-assessments