- Key insight: The department says the guidance creates no new obligations. It describes how examiners read requirements already in Part 500.
- Supporting data: The department fined Order Express $250,000 under an Aug. 3 consent order, after a September 2022 ransomware attack encrypted just over half the company's servers.
- Forward look: An exemption from parts of Part 500 did not spare Order Express the risk-assessment charge, which is the point smaller licensees should take from the enforcement record.
Overview bullets generated by AI with editorial review.
On Thursday, New York's financial regulator told each financial services company it regulates to find the places where several of the company's critical operations run through a single outside provider.
The instruction came in
The Thursday industry letter says it "does not create new obligations" under
Firms should "identify potential single points of failure, assess concentration risk," and work out how an incident at one third party could hit other systems or critical business functions, according to the guidance. Doing that lets them "better assess systemic cyber risk," the letter states.
The guidance reaches every firm the department licenses, which includes banks, credit unions, insurers, mortgage brokers, money transmitters and virtual currency companies.
NYDFS has penalized a company over an inadequate risk assessment before; it happened most recently in August, when it
"Risk assessments are the foundation of a strong cybersecurity program," said Kaitlin Asrow, the department's acting superintendent, in a Thursday
"As cybersecurity risks evolve and institutions' risk profiles change, it is critical that their cybersecurity programs adapt, and this guidance outlines those expectations," she said in the release.
The department does not publish a count of how many firms Part 500 reaches or how many hold the limited exemption that spares smaller ones some of its requirements.
A NYDFS spokesperson did not immediately respond to a request for comment.
What the guidance asks for
The new guidance says technologies, platforms or vendors "that present limited risk when evaluated independently may collectively create significant cyber risk when multiple critical systems or business functions rely on" shared dependencies.
Those dependencies include common infrastructure, cloud providers, software platforms and managed service providers.
Banks are well aware of the risks these shared dependencies present and have, in the past,
In the Thursday guidance, NYDFS provided a list of common shortcomings it sees in risk assessments, built from examinations, investigations and interviews with employees at the firms it supervises.
One of those common shortcomings is a "failure to account for evolving and interconnected risks, including emerging technologies, changes in the threat landscape, interdependencies, concentration risk, and single points of failure," according to the guidance.
Another is "incomplete asset scope and visibility." The guidance describes that as outdated or incomplete asset inventories, a failure to track where customer data sits, and the omission of critical business processes,
The concentration instruction goes a step past where NYDFS left the subject last year; its
The earlier letter asked firms to document the lock-in risk and put other safeguards around it. The new one asks them to work out what a failure at one of these locked-in service providers would do.
The guidance also tells firms to weigh emerging risks; it named artificial intelligence, quantum computing's eventual threat to encryption, software supply chain attacks, changing ransomware techniques and nation-state activity.
What it costs to get it wrong
The August consent order that fined Order Express $250,000 followed a September 2022 ransomware attack on the money transmitter that left just over half the company's servers encrypted. The first violation the department listed in that order was an inadequate risk assessment.
"Although Order Express's annual risk assessment considered operational and information technology risks, the risk assessment failed to consider cybersecurity risks and threats specific to the company," the consent order said.
The assessment also "did not consider the adequacy of the controls the company did have in place," according to the order.
Those failures violated the regulation's
Order Express was exempt from parts of Part 500 because of its limited revenue. The department said it weighed that in setting the penalty. It charged the risk-assessment violation to the ransomware victim anyway.











