New York tells banks to find their single points of failure

1762371387331.jpeg
Kaitlin Asrow, acting superintendent of the New York Department of Financial Services
NYDFS
  • Key insight: The department says the guidance creates no new obligations. It describes how examiners read requirements already in Part 500.
  • Supporting data: The department fined Order Express $250,000 under an Aug. 3 consent order, after a September 2022 ransomware attack encrypted just over half the company's servers.
  • Forward look: An exemption from parts of Part 500 did not spare Order Express the risk-assessment charge, which is the point smaller licensees should take from the enforcement record.

Overview bullets generated by AI with editorial review.

Processing Content

On Thursday, New York's financial regulator told each financial services company it regulates to find the places where several of the company's critical operations run through a single outside provider.

The instruction came in guidance from the New York State Department of Financial Services, or NYDFS, on how to conduct the cybersecurity risk assessment that the state has required of licensed firms for years.

The Thursday industry letter says it "does not create new obligations" under Part 500, the state's cybersecurity regulation, but rather describes how NYDFS reads an existing obligation.

Firms should "identify potential single points of failure, assess concentration risk," and work out how an incident at one third party could hit other systems or critical business functions, according to the guidance. Doing that lets them "better assess systemic cyber risk," the letter states.

The guidance reaches every firm the department licenses, which includes banks, credit unions, insurers, mortgage brokers, money transmitters and virtual currency companies.

NYDFS has penalized a company over an inadequate risk assessment before; it happened most recently in August, when it fined money transmitter Order Express $250,000.

"Risk assessments are the foundation of a strong cybersecurity program," said Kaitlin Asrow, the department's acting superintendent, in a Thursday press release announcing the guidance.

"As cybersecurity risks evolve and institutions' risk profiles change, it is critical that their cybersecurity programs adapt, and this guidance outlines those expectations," she said in the release.

The department does not publish a count of how many firms Part 500 reaches or how many hold the limited exemption that spares smaller ones some of its requirements.

A NYDFS spokesperson did not immediately respond to a request for comment.

What the guidance asks for

The new guidance says technologies, platforms or vendors "that present limited risk when evaluated independently may collectively create significant cyber risk when multiple critical systems or business functions rely on" shared dependencies.

Those dependencies include common infrastructure, cloud providers, software platforms and managed service providers.

Banks are well aware of the risks these shared dependencies present and have, in the past, complained about the risk presented by the concentration in these verticals — for example, the domination of cloud services by Microsoft, Amazon and Google.

In the Thursday guidance, NYDFS provided a list of common shortcomings it sees in risk assessments, built from examinations, investigations and interviews with employees at the firms it supervises.

One of those common shortcomings is a "failure to account for evolving and interconnected risks, including emerging technologies, changes in the threat landscape, interdependencies, concentration risk, and single points of failure," according to the guidance.

Another is "incomplete asset scope and visibility." The guidance describes that as outdated or incomplete asset inventories, a failure to track where customer data sits, and the omission of critical business processes, outside service providers and cloud environments.

The concentration instruction goes a step past where NYDFS left the subject last year; its October 2025 guidance on third-party service providers mentioned vendor concentration once — as something that can make a provider hard to leave.

The earlier letter asked firms to document the lock-in risk and put other safeguards around it. The new one asks them to work out what a failure at one of these locked-in service providers would do.

The guidance also tells firms to weigh emerging risks; it named artificial intelligence, quantum computing's eventual threat to encryption, software supply chain attacks, changing ransomware techniques and nation-state activity.

What it costs to get it wrong

The August consent order that fined Order Express $250,000 followed a September 2022 ransomware attack on the money transmitter that left just over half the company's servers encrypted. The first violation the department listed in that order was an inadequate risk assessment.

"Although Order Express's annual risk assessment considered operational and information technology risks, the risk assessment failed to consider cybersecurity risks and threats specific to the company," the consent order said.

The assessment also "did not consider the adequacy of the controls the company did have in place," according to the order.

Those failures violated the regulation's risk-assessment requirement, per the order.

Order Express was exempt from parts of Part 500 because of its limited revenue. The department said it weighed that in setting the penalty. It charged the risk-assessment violation to the ransomware victim anyway.


For reprint and licensing requests for this article, click here.
Cyber Security Regulation and compliance State regulators Enforcement Technology
MORE FROM AMERICAN BANKER
Load More