
A while back I sat across from an agency owner who told me, confidently, that his cybersecurity risk assessment was done. His IT company had it handled. I asked him for the document. He called them. They said they'd done it, but they couldn't give him a report. So, he'd gone out and bought separate software to do it himself, which is how I ended up in his office.
I've thought about that conversation a lot today, because this morning the New York Department of Financial Services sent a letter to every business it regulates; insurance agencies and mortgage companies included, about cybersecurity risk assessments. And it essentially describes that owner.
What DFS Actually Sent
The letter is guidance on how to design, conduct, and update the risk assessment that Part 500 has required since 2017. It's signed by Acting Superintendent Kaitlin Asrow. And it says, in its own words, that it creates no new obligations.
I want to be clear about that before anyone else muddies it. There are no new rules. There's no deadline. You will see posts this week calling it "new DFS requirements." It isn't. Read it yourself; the link is at the bottom of this blog.
Why "Nothing New" Is The Part That Should Worry You
DFS didn't write a new rule. It wrote down the ways it has watched businesses fail the existing one. The letter lists what examiners keep finding when they read risk assessments, and the list is specific. That's not a regulation. That's the answer key.
Here's what they listed, and what each one looks like when I walk into an agency.
You don't know what you have. Outdated or missing asset inventory. In real life: the laptop the producer who left in March still has, and nobody's sure what's on it.
You don't know where your client data lives. In real life: the benefits census in someone's Downloads folder, the tax return attached to an email from 2023, the carrier portal password saved in a browser.
You didn't look at what's new. DFS names AI specifically. In real life: your team started using Copilot or ChatGPT this year, and your assessment is from last year. More on that in a minute.
Nobody owns anything. No name next to any risk, no record of what you decided to fix and what you decided to live with. In real life: the assessment is a PDF nobody has opened since it was filed. It didn't change anything. The letter says your program must be demonstrably based on the assessment. In real life: you did the assessment, and your security is exactly the same as before you did it.
The AI Sentence
One line in this letter connects to what we've spent this year seeing. DFS says the risk assessment has to be updated whenever a change in your business or technology materially changes your cyber risk, and it lists adopting AI as an example of that kind of change.
We've been doing a lot of AI planning with agencies lately. What we keep finding is that employees turned it on and started using it. Sometimes without permission, usually without any precautions. Client information going into tools nobody vetted. If that describes your shop, then by DFS's own definition your last risk assessment is already out of date, whatever the date it says.
What Happens In The Exam
I've been part of enough DFS examinations to tell you how they start. The risk assessment is the first thing they ask for. Not one of the things. The first.
And it can't be any document with that title. It must follow a real methodology, written down and repeatable, with criteria for how you rate risks and a record of how the results drove your decisions. DFS doesn't mandate a specific framework; most people use NIST. What it does require is that you can show your work.
If you can't produce that, the rest of the exam gets uphill fast, because every other question comes back to it. Why is this control and not that one? What did the assessment say? Who decided to accept this risk, and where is that written down?
The owner I mentioned couldn't answer any of that. Not because he didn't care. Because someone told him it was handled.
The Test
Ask whoever handles your IT for your risk assessment. Not "did we do it." The document. When it arrives, check three things.
1. Does it name a methodology? Is there a name next to each risk and a decision recorded? Is it dated after your team started using AI?
2. If the answer to any of those is no, you now know what DFS will find. The difference is that you found it first.
3. If you're a mortgage company that also falls under the FTC Safeguards Rule, the same written risk assessment sits at the center of that rule too. Same test.
One More Thing
Every April you sign a certification saying your program meets the requirements. The risk assessment is one of them. We've been telling brokers about this for nine years, and I'll say it again: you can't certify what you can't produce.
If you're a member of the insurance or mortgage associations we work with, the assessment is already included for you. If you're not and you want to know what you actually have, write to info@motiva.net. We walk through the findings live, never by email, for reasons that will be obvious once you've read the section on where your client data lives.
The letter: dfs.ny.gov/industry_guidance/industry_letters/il20260910-cyber-risk-assessment
— Walter
New York Insurance EXAM READINESS
Think you're covered? Find out if you're exam-ready.
Your IT may be working. Your examiner may still find gaps. Get a free NY Insurance Exam Readiness Review and see what your agency can actually prove — from documentation and access reviews to training records and supervision.
Get My Exam Readiness Review →
Subscribe to the monthly newsletter and I'll send you a free AI
Acceptable-Use Policy template — the one I give agencies to get
visibility before a regulator asks for it.
Plus one short email a month with what I actually find inside agencies. No pitch.
No spam, unsubscribe anytime. We'll never share your email.