

On September 10, 2026, the New York State Department of Financial Services issued new guidance explaining what a strong cybersecurity risk assessment should look like under 23 NYCRR Part 500.
The message in this NYDFS cybersecurity risk assessment guidance is straightforward: an assessment cannot be created once and filed away. It should be a living management tool that changes as the organization, technology, and threat landscape change. It must actively guide cybersecurity decisions, controls, budgeting, and priorities.
For regulated organizations—and the professional firms that support them—the guidance offers a useful roadmap for building a defensible security program.
Concerned About Your Risk Assessment?
Book a quick 15-minute call to see whether your organization qualifies for a complimentary cybersecurity assessment.
Risk Assessments Must Guide Cybersecurity Decisions
NYDFS describes the risk assessment as the foundation of a cybersecurity program. Organizations should identify the systems, data, people, locations, and third parties that support business operations, then evaluate the threats and vulnerabilities affecting those assets.
The assessment should be updated at least annually and whenever a material change occurs, such as a major acquisition, new technology platform, cloud migration, change in business operations, or significant cybersecurity event.
Common Weaknesses NYDFS Identified
NYDFS highlighted several recurring problems:
- Incomplete inventories of systems, applications, data, personnel, and vendors
- Risk ratings that are assigned without a documented method
- Assessments that list vulnerabilities but do not explain business impact
- Failure to track remediation, responsible parties, and deadlines
- Security controls that do not clearly connect back to identified risks
In other words, a spreadsheet full of technical findings is not automatically a meaningful risk assessment. Leadership should be able to understand what could happen, how likely it is, what the business impact would be, and what will be done about it.
Five Elements of an Effective Assessment
A practical assessment should:
- Define its scope. Include the information systems, data, employees, facilities, vendors, and business processes that matter.
- Identify threats and vulnerabilities. Consider ransomware, phishing, unauthorized access, system failure, insider risk, third-party exposure, and physical threats.
- Estimate likelihood and impact. Use a consistent, documented method to determine inherent risk.
- Evaluate existing safeguards. Review controls such as multifactor authentication, endpoint protection, backups, monitoring, access restrictions, and incident response.
- Document residual risk and action plans. Assign owners and deadlines to improvements, then track them through completion.
What Organizations Should Do Now
Organizations subject to Part 500 should review their latest assessment against this guidance and confirm that it is complete, current, repeatable, and tied to remediation. Even businesses outside NYDFS jurisdiction can use the guidance as a practical benchmark for improving cybersecurity governance.
InnerPC helps CPA firms and professional-services organizations assess risk, strengthen safeguards, secure Microsoft 365 and Azure environments, protect backups, and build practical incident-response plans. Learn more about our cybersecurity services and cyber risk assessments.
Read the complete NYDFS cybersecurity risk-assessment guidance.
This article provides general information and is not legal or regulatory advice. Organizations should consult qualified counsel regarding their specific compliance obligations.
Would Your Cybersecurity Risk Assessment Stand Up to Scrutiny?
Book a quick 15-minute call with InnerPC to see whether your organization qualifies for a complimentary cybersecurity assessment. We will discuss your current environment, regulatory concerns, and the most important risks your organization should evaluate.