The New York State Department of Financial Services has issued guidance telling every financial services company it regulates to identify where critical operations depend on a single outside provider. The instruction came in an industry letter published Thursday on how firms should conduct the cybersecurity risk assessment required under Part 500, the state’s cybersecurity regulation.

The department said the guidance does not create new obligations. Instead, it describes how NYDFS examiners interpret an existing requirement that licensed firms have followed for years.

What the Guidance Asks Firms to Do

According to the letter, firms should identify potential single points of failure, assess concentration risk, and determine how an incident at one third party could affect other systems or critical business functions. The department said this approach helps firms better assess systemic cyber risk.

The guidance applies to every institution the department licenses, including banks, credit unions, insurers, mortgage brokers, money transmitters, and virtual currency companies.

The letter notes that technologies, platforms, or vendors that present limited risk when evaluated independently may collectively create significant cyber risk when multiple critical systems or business functions rely on shared dependencies. Those dependencies include common infrastructure, cloud providers, software platforms, and managed service providers.

Common Shortcomings in Risk Assessments

NYDFS listed common shortcomings it has observed in risk assessments through examinations, investigations, and interviews with supervised firms. These include:

  • Failure to account for evolving and interconnected risks, such as emerging technologies, changes in the threat landscape, interdependencies, concentration risk, and single points of failure.
  • Incomplete asset scope and visibility, including outdated or incomplete asset inventories, failure to track where customer data resides, and omission of critical business processes, outside service providers, and cloud environments.

The concentration instruction goes further than the department’s October 2025 guidance on third-party service providers, which mentioned vendor concentration only as something that can make a provider difficult to leave. That earlier letter asked firms to document lock-in risk and apply other safeguards. The new guidance asks firms to work out what a failure at a locked-in service provider would mean for their operations.

The guidance also directs firms to weigh emerging risks. It names artificial intelligence, quantum computing’s eventual threat to encryption, software supply chain attacks, changing ransomware techniques, and nation-state activity.

Enforcement Context: The Order Express Penalty

NYDFS has penalized a company over an inadequate risk assessment before. In August, it fined money transmitter Order Express $250,000 under a consent order. The penalty followed a September 2022 ransomware attack that encrypted just over half of the company’s servers.

The first violation listed in the consent order was an inadequate risk assessment. According to the order, Order Express’s annual risk assessment considered operational and information technology risks but failed to consider cybersecurity risks and threats specific to the company. The assessment also did not consider the adequacy of the controls the company had in place. Those failures violated the regulation’s risk-assessment requirement.

Order Express was exempt from parts of Part 500 because of its limited revenue. The department said it weighed that exemption in setting the penalty, but it still charged the risk-assessment violation to the ransomware victim.

Why the Guidance Matters for Smaller Licensees

The enforcement record shows that an exemption from parts of Part 500 does not spare a firm from the risk-assessment charge. That is the point smaller licensees should take from the Order Express case.

Kaitlin Asrow, the department’s acting superintendent, said in a Thursday press release announcing the guidance that risk assessments are the foundation of a strong cybersecurity program.

“As cybersecurity risks evolve and institutions’ risk profiles change, it is critical that their cybersecurity programs adapt, and this guidance outlines those expectations,” she said in the release.

The department does not publish a count of how many firms Part 500 reaches or how many hold the limited exemption that spares smaller ones some of its requirements. A NYDFS spokesperson did not immediately respond to a request for comment.

By Ryan

Leave a Reply

Your email address will not be published. Required fields are marked *