Orrick, Herrington & Sutcliffe·CYBERSECURITY

NYDFS Flags Common Flaws in Cyber Risk Assessments

New York's financial regulator detailed common deficiencies in required cybersecurity risk assessments, clarifying its expectations for governance, scope, and methodology.

The New York Department of Financial Services (NYDFS) has issued an industry letter clarifying its expectations for cybersecurity risk assessments required under Part 500 of its regulations. The guidance does not establish new rules but signals what examiners will focus on, drawing from common deficiencies found in recent investigations.

Sophisticated counsel and their financial-services clients should care because the letter provides a clear roadmap of regulatory priorities. NYDFS specifically called out frequent gaps, including incomplete asset inventories, weak methodologies that fail to distinguish between inherent and residual risk, and inadequate consideration of emerging threats like AI, quantum computing, and third-party concentration risk. The guidance also stresses the need for better governance, such as assigning ownership for risks and integrating assessment results into enterprise-wide decision-making.

Covered entities should promptly review their risk assessment programs against the five key areas outlined in the guidance, which cover governance, methodology, scope, documentation, and integration. This is a critical opportunity to remediate potential weaknesses before the next examination cycle.

nydfscybersecurityrisk-assessmentfinancial-regulationpart-500regulatory-guidance
Read the original firm alert → Wednesday, September 23, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.