The New York Department of Financial Services has released new cybersecurity guidance emphasizing how regulated entities should manage the growing risks tied to third-party service providers. Acting Superintendent Kaitlin Asrow issued the guidance this week, which falls during Cybersecurity Awareness Month, warning that while vendors bring innovation and efficiency, regulated companies remain ultimately responsible for safeguarding consumer data and maintaining cybersecurity compliance.
The guidance does not introduce new regulatory requirements but clarifies existing obligations under the state’s Cybersecurity Regulation, Part 500, and outlines best practices to strengthen oversight of vendors. DFS noted that many regulated entities rely heavily on third-party service providers for critical functions such as cloud computing, artificial intelligence, and fintech solutions, which expand the potential attack surface for cyber incidents. The Department said senior management and governing bodies must maintain active oversight of vendor-related cyber risks and possess enough understanding to challenge management decisions where necessary.
DFS examiners have found that some covered entities have delegated key cybersecurity compliance tasks to vendors without ensuring adequate supervision. The Department reiterated that regulated entities cannot transfer their compliance obligations to affiliates or third-party service providers. The absence of proper vendor risk management controls could be considered in DFS examinations, investigations, and enforcement actions.
The guidance advises covered entities to adopt a lifecycle approach to third-party risk management, starting with due diligence before engaging a vendor, followed by contractual protections, ongoing oversight, and secure termination practices. It urges firms to classify vendors by risk level and assess factors such as system access, data sensitivity, location, and cybersecurity posture. Contracts should include provisions for encryption, data use restrictions, breach notification, and controls over subcontractors. Entities should also pay close attention to whether vendors use company data to train artificial intelligence models.
Finally, DFS stressed that regulated entities must conduct regular assessments of their vendors’ cybersecurity practices and document risk mitigation efforts. Organizations are expected to integrate third-party risks into incident response and business continuity plans to ensure operational resilience. The Department said the goal is to help companies take a proactive, risk-based approach as they navigate increasingly complex technology environments.
.




