← All News

New York Regulator Tells Financial Firms To Update Cyber Risk Assessments As AI Threats Evolve

By CU Today Staff —

NEW YORK— New York’s top financial regulator is warning banks, credit unions, insurers and other financial institutions to keep cybersecurity risk assessments current as artificial intelligence and other emerging technologies rapidly change the threat landscape.

The New York State Department of Financial Services said regulated entities must review and update their assessments at least annually—and whenever business or technology changes materially alter their cyber risk. The guidance does not impose new requirements but clarifies expectations under the state’s Part 500 cybersecurity regulation.

The guidance specifically identifies developments involving frontier AI models as among the events that could warrant a new assessment, along with major system migrations, mergers and acquisitions, significant outsourcing arrangements, exploitation of critical vulnerabilities and changes in cybercriminal capabilities. DFS also said assessments should account for AI, quantum computing, software supply-chain attacks, evolving ransomware techniques and geopolitical threats. The department has previously warned that advanced AI models could increase the speed and scale at which attackers identify and exploit vulnerabilities.

“Risk assessments are the foundation of a strong cybersecurity program,” DFS Acting Superintendent Kaitlin Asrow said. “As cybersecurity risks evolve and institutions’ risk profiles change, it is critical that their cybersecurity programs adapt, and this guidance outlines those expectations.”

DFS said examinations have identified shortcomings including incomplete asset inventories, failure to adequately account for third-party and cloud dependencies, inconsistent methods for evaluating risks and cybersecurity controls that cannot be clearly tied to risks identified in an institution's assessment.

The regulator is also putting greater emphasis on third-party concentration risk, telling institutions to identify potential single points of failure when multiple critical operations depend on the same cloud provider, managed service provider, software platform or other vendor. The latest guidance builds on DFS's May warning about frontier AI and its 2024 guidance on AI-related cyber risks, which said institutions should consider their own use of AI as well as AI deployed by vendors and other third parties.

Originally reported by CU Today.