NYDFS Releases New Cybersecurity Risk Assessment Guidance
New guidance from the New York Department of Financial Services details specific expectations for cybersecurity risk assessments required under its Part 500 regulations.
The New York Department of Financial Services (NYDFS) has published extensive new guidance for covered entities regarding the cybersecurity risk assessments required under 23 NYCRR Part 500. The guidance clarifies and significantly details the regulator’s expectations, providing a more granular framework than the original rule for how firms should identify and assess their cybersecurity risks.
This development is important for the wide range of banks, insurers, and other financial services firms regulated by NYDFS, as it establishes a heightened standard that examiners will likely use to scrutinize compliance. Given that NYDFS cybersecurity standards often serve as a model for other state and federal regulators, the guidance may also influence compliance expectations well beyond New York.
Regulated entities should promptly review their existing risk-assessment methodologies and documentation against the new guidance to identify any gaps. Counsel should be prepared to advise clients on updating their processes to incorporate the more specific components and analytical approaches now expected by the department ahead of future examinations.