The New York State Department of Financial Services (DFS) has released new guidance for regulated entities regarding cybersecurity risk assessments.
Announced by DFS Acting Superintendent Kaitlin Asrow on Sept. 10, 2026, the guidance does not establish new requirements. Instead, it provides clarification regarding compliance obligations under New Yorkās cybersecurity regulation, 23 NYCRR Part 500.
āRisk assessments are the foundation of a strong cybersecurity program,ā Asrow said. āAs cybersecurity risks evolve and institutionsā risk profiles change, it is critical that their cybersecurity programs adapt, and this guidance outlines those expectations.ā
Under 23 NYCRR Part 500, covered financial services entities are required to review and update their cybersecurity risk assessments at least annually. Risk assessments must also be updated when a change in business or technology results in a material change to the entityās cybersecurity risk.Ā Ā
The new DFS guidance outlines best practices and identifies key elements of an effective cybersecurity risk assessment. These include the assessmentās methodology, scope, documentation, governance, and integration with the organizationās broader cybersecurity program.Ā
Factors to Consider in a Cybersecurity Risk AssessmentĀ
The guidance identifies several factors that regulated entities should consider when conducting or updating a cybersecurity risk assessment.Ā
Material Technology Changes: Entities should consider reassessing cybersecurity risks before or after significant technology changes, such as a major system migration, merger or acquisition, significant outsourcing arrangement, or implementation of a new critical system.Ā
Third-Party Risk: Risk assessments should consider whether multiple critical functions rely on the same cloud provider, managed service provider, software platform, or other common third-party dependency.Ā
Emerging Risks: Entities should evaluate how the adoption of artificial intelligence and other emerging technologies may affect their threat exposure, data risks, access controls, and third-party dependencies.Ā
Risk-Informed Controls: Identified risks should be evaluated to determine whether existing controls, policies, monitoring practices, or risk acceptance decisions require strengthening or updating.
Additional Guidance
The guidance also addresses governance, documentation, asset coverage, supply-chain risks, cyber interdependencies and concentration risk. DFS noted that risk assessments should be appropriately tailored to an entityās size, complexity, operations, assets, and risk profile.Ā Ā
The guidance further states that risk assessments should be integrated into an entityās broader cybersecurity program and used to inform cybersecurity policies, procedures, controls, and testing plans.Ā
A copy of the DFS Guidance on How to Conduct and Use Risk Assessments Required by the DFS Cybersecurity Regulation is available from this hyberlink or on the New York State Department of Financial Services website.
The DFS Cybersecurity Resource Center also provides access to cybersecurity guidance, frequently asked questions and other compliance resources.Ā
Author:Ā Jennifer Evancic
Jennifer.Evancic@ResourceManagement.com
Jennifer Evancic is a third-party auditor valued by creditors and large organizations for her knowledge in call monitoring within the collections industry. With meticulous attention to detail and a firm grasp of regulatory requirements, she ensures compliance with clientsā criteria and state and federal regulations.
Jennifer audits collections calls, ensuring they meet client-specific criteria and comply with regulations, providing valuable insights and maintaining industry standards.
Beyond her auditing responsibilities, Jennifer takes the lead in organizing and facilitating monthly call calibrations. These sessions serve as a collaborative forum where clients and their vendors come together to discuss call monitoring results and address any findings or areas for improvement. Jenniferās guidance fosters open communication and ensures alignment between clients and vendors, driving continuous improvement in collections practices.
Jennifer stays up-to-date with compliance and industry best practices by participating regularly in peer meetings, regulatory updates and industry webinars. This keeps her informed about emerging issues and ensures she remains a knowledgeable leader in collections compliance.
Third Party Auditing and Custom Consulting Available
With expertise and experience inĀ collections, oversight and compliance, we understand the challenges faced by creditors in managing collections and recoveries while adhering to ever-evolving regulatory standards.Ā Ā
Thatās why our team of seasoned experts is dedicated to providing tailor solutions that address your unique collection and compliance requirements.Ā
FromĀ comprehensive consulting services
toĀ specialized training programs
andĀ meticulous oversight of third-party vendors,
we offer a comprehensive suite of services designed to empower your team and optimize your compliance strategies.Ā
Contact our blog authors or Write to us atĀ info@resourcemanagement.comĀ for more information.
www.resourcemanagement.com
Sign Up for theĀ Twice Monthly Complimentary Newsletter
Just enter your email address at the top orange bar at:
Collection Compliance Experts ā āThe Power of Expertise: Oversight Perfectedā
Itās that easy!Ā Twice a month ā we provide blog updates and Resources for the Collection and Industry Professional.Ā
Your email is just for this newsletter.Ā We never sell your information.Ā No fee.Ā Opt-out at any time.



