Overview
To safeguard financial services organizations and protect the confidential information of New Yorkers, DFS uses a multi-pronged, risk-based approach to monitor cybersecurity and information technology (IT) risk. The cybersecurity supervision program supplements traditional examinations with new types of information gathering and analysis capabilities, enabling a more holistic and forward-looking view of the cybersecurity risk posture of the thousands of New York financial services firms regulated by DFS.
Among other factors, DFS considers the following components when monitoring cybersecurity and IT risk:
Regulatory Examinations and Data Analysis
DFS will continue to conduct regular, risk-based examinations that include a focus on cybersecurity and IT risk management and compliance. It will also assess Covered Entities for cybersecurity risk based on their previous examination reports, annual cybersecurity notification submissions, reported Cybersecurity Incidents, and other regulatory submissions.
Cybersecurity Assessment Questionnaires
DFS asks many Covered Entities to complete assessment questionnaires, such as the Cybersecurity and Information Technology Baseline Risk Questionnaire (CIBRiQ). Such questionnaires are independent of the examination process and are informed by assessment methodologies commonly used by industry and insurers to evaluate risk for financial services companies.
External Data Collection and Analysis
To better and faster assess cyber risk facing Covered Entities, DFS conducts data gathering and analysis through its dedicated Cyber Intelligence Unit, which draws on a combination of DFS-held data, publicly available information, and commercial scanning and threat analysis capabilities. This analysis supports risk identification, trend analysis, and supervisory awareness across the regulated population.