Paul Hastings·CYBERSECURITY

NYDFS Issues New Guidance on Cybersecurity Risk Assessments

The guidance details regulatory expectations for the required periodic risk assessments under New York's pioneering cybersecurity regulation for financial institutions.

The New York State Department of Financial Services (NYDFS) has issued new guidance on the risk assessments required under its landmark Cybersecurity Regulation (23 NYCRR 500). The guidance, released September 10, 2026, clarifies regulatory expectations for how financial institutions should conduct these foundational assessments, which must be performed periodically to inform their entire cybersecurity program.

Sophisticated counsel and their clients care because the NYDFS regulation is a critical compliance framework for thousands of banks, insurers, and other financial services companies operating in New York. The risk assessment is not a check-the-box exercise; it is the basis for the entity’s security controls, policies, and procedures. Failure to conduct an adequate assessment is a primary target in regulatory examinations and enforcement actions. This guidance provides a clearer roadmap for meeting DFS expectations and defending the methodology. Covered entities should immediately review the guidance with their legal and technology teams to identify any gaps in their current risk assessment processes and prepare for heightened supervisory scrutiny.

nydfscybersecurityfinancial-regulationrisk-assessmentnew-yorkcompliance
Read the original firm alert → Saturday, September 12, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.