On September 10, 2026, the New York Department of Financial Services published guidance on how covered entities should conduct and use the risk assessments required under 23 NYCRR Part 500. It does not invent a brand-new regulation. It does something more practical, and more uncomfortable: it tells you what “good” looks like when examiners look at your assessment — and where firms commonly fall short.
I work with Hudson Valley insurance agencies, brokers, and smaller financial services firms every week. When this guidance landed, my first question was not “what’s the new checkbox?” It was: if a principal in Dutchess or Orange County has to put their name on the next annual certification, does their risk assessment actually support that signature?
Often, the honest answer is “not yet.”
What Changed (and What Did Not)
Part 500 already required a periodic risk assessment that informs the cybersecurity program, reviewed at least annually and whenever a material change in business or technology changes your cyber risk. The September guidance clarifies expectations, calls out common deficiencies seen in exams and investigations, and spells out best practices for governance, methodology, scope, documentation, and integration.
That last word matters. The cybersecurity program is supposed to be based on the risk assessment — policies, controls, and resource decisions should trace back to identified risks. A PDF that sits in a shared drive until April certification week is not a program. It is a liability.
The Five Gaps I See Most Often
Industry summaries of the guidance highlight deficiencies that match what I find locally:
If your “risk assessment” is a generic MSP questionnaire with the same answers as last year, you are in that list.
Material Changes Are Not Only Mergers
The guidance reinforces updates after material changes — and the examples are broader than people expect: major system migrations, significant outsourcing, adoption of or exposure to frontier AI developments, shifts in threat actor capability, critical vulnerability exploitation, and geopolitical pressure on the threat landscape.
For a twenty-person agency, that can look like: moving to a new AMS, switching MSPs, rolling out Microsoft 365 Copilot or another GenAI tool that touches client data, or discovering a critical vulnerability in a remote-access stack you depend on. Those are assessment triggers, not “we’ll catch it next April” events.
What I Want You to Do This Week
Pick one afternoon. Do not try to rebuild the whole program in a day. Do this:
- Name an owner for the risk assessment (CISO function — on staff or fractional).
- List where NPI actually lives — AMS, email, shared drives, backups, portals, vendor systems. If you cannot name it, you cannot assess it.
- List your critical third parties and mark which ones could stop you from serving clients if they failed.
- Write down three material changes from the last twelve months (tools, vendors, AI, org changes). Note whether the assessment was updated.
- Connect three top risks to controls you actually run (MFA, backups, IR plan, vendor review). If you cannot draw the line, that is your gap list.
A Note for Schools and Local Government
Schools and local governments are not all Part 500 covered entities — but the same discipline helps: know your critical data, test backups, and own the risk conversation at the board or board of education level. CISA’s K-12 Cybersecurity Foundations package is the parallel lane for districts; we will cover that on the CSF blog.
How Security Medic Helps
If you want a calm second set of eyes on whether your current assessment would survive an exam conversation, we can walk the five gaps above against your environment and leave you with a prioritized fix list — not a shelfware binder.
Start with that one-week pass. If you want help turning it into a living Part 500–aligned assessment and evidence pack, reach out via Hudson Valley CISO / Security Medic.