NYDFS Just Clarified Risk Assessments — What Hudson Valley Firms Should Do This Week

September 10, 2026 Part 500 guidance does not invent a new regulation. It tells you what “good” looks like when examiners look at your assessment.

By Jim Venuto | September 20, 2026 | Hudson Valley CISO

On September 10, 2026, the New York Department of Financial Services published guidance on how covered entities should conduct and use the risk assessments required under 23 NYCRR Part 500. It does not invent a brand-new regulation. It does something more practical, and more uncomfortable: it tells you what “good” looks like when examiners look at your assessment — and where firms commonly fall short.

I work with Hudson Valley insurance agencies, brokers, and smaller financial services firms every week. When this guidance landed, my first question was not “what’s the new checkbox?” It was: if a principal in Dutchess or Orange County has to put their name on the next annual certification, does their risk assessment actually support that signature?

Often, the honest answer is “not yet.”

What Changed (and What Did Not)

Part 500 already required a periodic risk assessment that informs the cybersecurity program, reviewed at least annually and whenever a material change in business or technology changes your cyber risk. The September guidance clarifies expectations, calls out common deficiencies seen in exams and investigations, and spells out best practices for governance, methodology, scope, documentation, and integration.

That last word matters. The cybersecurity program is supposed to be based on the risk assessment — policies, controls, and resource decisions should trace back to identified risks. A PDF that sits in a shared drive until April certification week is not a program. It is a liability.

The Five Gaps I See Most Often

Industry summaries of the guidance highlight deficiencies that match what I find locally:

1. Incomplete asset and data visibility. Outdated inventories; unclear where nonpublic information (NPI) lives or flows; cloud, vendors, and critical business processes left out of scope.
2. Weak or inconsistent methodology. Risks not consistently identified, rated, or documented; little distinction between inherent and residual risk; controls not really evaluated.
3. Emerging and interconnected risk ignored. AI, supply chain, concentration risk, and single points of failure treated as someone else’s problem.
4. Thin governance. No clear owner, no documented risk acceptance, little reporting to senior leadership or the governing body.
5. No line from risk → control → program. Policies and tooling that cannot be shown to flow from the assessment.

If your “risk assessment” is a generic MSP questionnaire with the same answers as last year, you are in that list.

Material Changes Are Not Only Mergers

The guidance reinforces updates after material changes — and the examples are broader than people expect: major system migrations, significant outsourcing, adoption of or exposure to frontier AI developments, shifts in threat actor capability, critical vulnerability exploitation, and geopolitical pressure on the threat landscape.

For a twenty-person agency, that can look like: moving to a new AMS, switching MSPs, rolling out Microsoft 365 Copilot or another GenAI tool that touches client data, or discovering a critical vulnerability in a remote-access stack you depend on. Those are assessment triggers, not “we’ll catch it next April” events.

What I Want You to Do This Week

Pick one afternoon. Do not try to rebuild the whole program in a day. Do this:

  1. Name an owner for the risk assessment (CISO function — on staff or fractional).
  2. List where NPI actually lives — AMS, email, shared drives, backups, portals, vendor systems. If you cannot name it, you cannot assess it.
  3. List your critical third parties and mark which ones could stop you from serving clients if they failed.
  4. Write down three material changes from the last twelve months (tools, vendors, AI, org changes). Note whether the assessment was updated.
  5. Connect three top risks to controls you actually run (MFA, backups, IR plan, vendor review). If you cannot draw the line, that is your gap list.

A Note for Schools and Local Government

Schools and local governments are not all Part 500 covered entities — but the same discipline helps: know your critical data, test backups, and own the risk conversation at the board or board of education level. CISA’s K-12 Cybersecurity Foundations package is the parallel lane for districts; we will cover that on the CSF blog.

How Security Medic Helps

Key distinction: Your managed service provider handles firewalls, patching, and endpoint protection. Your CISO function handles cybersecurity program governance, risk assessment methodology, regulatory filings, and the evidence pack behind the certification your principal signs. Treating those as the same role is one of the most common gaps I see in Hudson Valley agencies.

If you want a calm second set of eyes on whether your current assessment would survive an exam conversation, we can walk the five gaps above against your environment and leave you with a prioritized fix list — not a shelfware binder.

Start with that one-week pass. If you want help turning it into a living Part 500–aligned assessment and evidence pack, reach out via Hudson Valley CISO / Security Medic.

References