Free guide · For New York agency owners

Everyone tells me they have a risk assessment.
Almost nobody does.

DFS has written to every regulated business in New York about risk assessments — and listed what keeps going wrong with them. The guide shows what a real one contains, and three questions that tell you whether yours would hold up.

Sept 10The DFS letter, in plain English — below
Walter Contreras
New York State approved cybersecurity instructor · teaches this for Big I New York · CEO, Motiva Networks

Get the free guide.

Eleven pages, plain English. Sent straight to your inbox.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
What a risk assessment actually is

It is not a scan. It is not a checklist. It is not the report a tool printed out.

A risk assessment is a written document, built on a methodology like NIST: what you have, where client data lives, what could go wrong, who owns it, and what you decided. Dated. Updated when something changes.

If it does not name a methodology, it is not a risk assessment. It is a piece of paper.
Risk Register
AssetOwnerStatus
Client AMSJ. DiazReviewed
Email archiveUnowned
AI / CopilotNot assessed
01
What you have
Every device, account, and system — named.
02
Where the data lives
AMS, email, downloads, carrier portals — and how each is protected.
03
What could go wrong
Every risk rated for likelihood and impact, on the same scale.
04
What you decided
An owner and a decision for every risk. Examiners read this part first.
September 10, 2026

What DFS said, inplain English.

No new rule.DFS says so, and so do I. Don't let anyone sell you a deadline off the back of it.

What it does say: the risk assessment isthe first thing they ask for, they keep findingthe same five gaps, and if your team started using AI this year,your last assessment is probably out of date.

Applies to agencies with the limited exemption too. Section 500.9 was never on the exempt list.

Exam Checklist
Asset inventory
Data location map
Owner sign-off
Methodology named
GAP 1
No inventory
The laptop a producer who left in March still has — nobody's sure what's on it.
GAP 2
Data never traced
The benefits census in a Downloads folder. The tax return in a 2023 email.
GAP 3
New risks ignored — DFS names AI specifically
Your team started using Copilot this year. Your assessment is from last year. DFS calls that a material change.
GAP 4
Nobody owns anything
No name next to any risk. No record of what got fixed or accepted.
GAP 5
Nothing changed
The program isn't demonstrably based on it. The document exists; nothing follows.
The piece-of-paper test

Three questions. If any one is a no,you do not have a risk assessment.

Check what you have against these. Five minutes — the same three things DFS keeps flagging.

1
QUESTION 1
Does it name the methodology it was built on?
A passing answer:NIST CSF, NIST 800-30, or another named framework, with risks rated on that scale.
2
QUESTION 2
Does every risk have a name and a decision recorded?
A passing answer:an owner for each risk, marked “fixed, and how” or “accepted, and why.”
3
QUESTION 3
Is it dated after your team started using AI?
A passing answer:a date this year, and a line on what changed. Predates Copilot? It's out of date.

The guide walks through all three — and what to do when the answer is no.

Part 500 · §500.17(b)
April 15
Owner's signature, every year.
Signed personally — not delegated.

Every April 15th, the owner signs — personally — certifying material compliance with Part 500.You can't certify what you can't produce.

Everything else in Part 500 — policies, controls, training — is supposed to come from this document. If it's a piece of paper, so is everything built on it, and your signature is on all of it.

Who wrote this
“I've been in the room when DFS asks for a risk assessment — and seen what gets handed over. I wrote this guide so you can check yours first.”
Credential
NY StateApproved instructor — the same material I teach agency staff is what is in the guide.
Compliance
SOC 2 Type IIWe are examined on the same class of controls we ask you to hold.
Experience
25 YearsWith New York independent insurance agencies only. Not general small business.
Complimentarythrough October

Haven't got one at all?We'll build it with you.

The three questions above tell you whether what you have holds up. This is for the owners who already know the answer — the same risk assessment we run for Motiva clients, at no cost while the offer stands.

  • Built on a named methodology — written down and repeatable
  • An inventory of what you have, and where client data actually lives
  • Every risk rated, with an owner and a recorded decision
  • Walked through live with Walter — never emailed to you
Request the risk assessmentAlready have a document and just want it checked? That's the fifteen minutes below.

Find out whether what you have wouldhold up.

Twenty minutes to read. Five minutes to check your own. Free, and I wrote it myself.

Inside the guide
What a NIST-based risk assessment actually contains
The five gaps DFS listed in the letter
The three-question test for the one you have
What to have in hand before April 15
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Rather I take a look myself? Fifteen minutes on Zoom is enough.
Request a conversation with Walter

“Cavallino Risk would not have survived the economic turmoil of the great recession or the disruptive technology that has occurred in the retail insurance marketplace without the support of Motiva.”

Frank CaponiPresident, Cavallino Risk Management

“The thing that sets Motiva apart is that they shine through and are there for you when needed.”

William LibardiPresident, Libardi Service Agency

“They follow up to make sure the issues were handled to our satisfaction; I have never had a tech company do that.”

Robert StoneManaging Director, Stone Insurance