Invest1 publisher3 min readPublished
NYDFS tells supervised firms to make every control traceable to the risk assessment
Acting Superintendent Kaitlin Asrow's September 10 letter restates duties Part 500 has carried since 2017. Examiners want a written line from each finding to the control it bought or the risk someone accepted.
The Investor · Invest desk

What happened
- Acting Superintendent Kaitlin Asrow released an NYDFS industry letter on September 10, 2026 setting out what a legally adequate cyber risk assessment looks like under the state's cybersecurity rule, Part 500.
- The letter adds no new duties, restating obligations already in the rule and describing practices department examiners have watched work and fail at supervised firms.
- Part 500 defines the assessment as a structured process for identifying, estimating and ranking threats to operations, assets, customers and critical infrastructure.
- The guidance groups its expectations under five themes: governance, methodology, scope, documentation, and the link between findings and the controls a firm runs.
- Examiners have flagged assessments that sit in a silo and never inform a budget or policy decision at the firm that produced them.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- decision Residual risk has to be accepted where leadership can see it, so a board that used to inherit a security budget now signs for what the firm is choosing not to fix.
- constraint Oversight sits with a senior officer or designated CISO who has to pull in operations, legal, compliance and the business lines. That coordination consumes hours that are not on the security team's payroll.
- cost Keeping likelihood and impact estimates, penetration test results and prior incidents in one reusable form is recurring work, and that is where the spend lands when no new control is required.
- precedent The rule mandates no framework, only that the method fit the firm's size and complexity. So fit becomes an examiner's judgement, and a small firm's borrowed enterprise template is arguable either way.
The operative sentence is about evidence. DFS has told firms that controls, monitoring and documented risk-acceptance decisions should be traceable back to the assessment [17]. It has also told them that a program is not risk-informed if a finding is ignored or a compensating control is never recorded [18]. A firm can own the right control and still fail that question, because the question is whether the record connects the finding to the spend.
Part 500 requires every covered organization to keep a cybersecurity program designed around its own risk assessment [3]. The rule sets the refresh floor at once a year, plus any time a business or technology change materially alters exposure [5]. The letter says a material technology event, such as a core-system migration or an acquisition, should trigger a fresh look before or soon after go-live [16]. A firm that migrates its core and closes an acquisition in the same year owes at least three passes in twelve months [24].
Asrow described risk assessments as the base of a durable security program. As threats and institutional profiles change, controls and policies have to change with them, she said, according to Crowdfund Insider's account of the letter [7]. The rule also requires written procedures setting criteria for classifying threats, judging the confidentiality and availability of systems and nonpublic information, and showing how the program will treat residual risk [6]. The guidance is posted on the department's refreshed Cybersecurity Resource Center, next to earlier letters on third-party providers and heightened-threat environments [20].
Scope is where the letter reaches past the security team's own kit. Assessments should rest on a complete, current asset inventory, should map where nonpublic information lives and how it moves, and should capture third-party concentration such as heavy reliance on a single cloud vendor or managed service [14]. They should also cover emerging issues including artificial intelligence, quantum-related cryptography concerns, supply-chain attacks and geopolitical tension [15].
The alignment expectation predates the letter. Part 500 was fully updated as of November 2025 and already required the program to line up with the assessment [19]. That puts the letter roughly ten months after that update [22].
The letter adds no new duty [2], so a firm that already writes its decisions down absorbs this in document control and its budget does not move. For the firms whose assessment is an annual paper exercise, naming the evidence raises what an examination costs. Crowdfund Insider writes that those entities now have a clearer picture of what examiners will ask to see [21]. In my view the first findings will come from traceability. It is the cheapest thing an examiner can check: put a finding next to a budget line and see whether one moved the other. If the department's next round of published findings cites methodology and scope more often than missing documentation, that expectation is wrong.
What to watch
- Whether DFS's next published examination findings cite missing documentation more often than weak methodology.
- Whether the Cybersecurity Resource Center adds a letter turning the AI and quantum-cryptography items into expectations of their own.
- Whether any Part 500 enforcement action after September 10 rests on an assessment that never reached a budget decision.