New York’s Department of Financial Services is putting regulated financial entities on notice: when the threat environment intensifies, minimum compliance is not enough.
Acting Superintendent Kaitlin Asrow issued guidance identifying specific cybersecurity measures that DFS-regulated organizations should consider adopting during periods of heightened risk. The guidance covers the full spectrum of firms operating under DFS authority, including debt collectors, debt buyers, banks, fintechs, and credit unions.
The guidance does not create new legal obligations. Instead, it signals where regulators expect firms to go beyond the baseline requirements of the state’s foundational cybersecurity regulation, when circumstances demand it.
What counts as a heightened threat environment? DFS points to two primary triggers: geopolitical events that increase the likelihood of cyberattacks, and technological developments that materially shift the risk landscape. The agency specifically called out the release of frontier AI models as an example of the latter, a notable acknowledgment that regulators see AI not only as a tool for defenders but as a force multiplier for threat actors.
The guidance is organized around three pillars. The first is reducing the attack surface, with recommendations that include expedited patching of known vulnerabilities, phishing-resistant multi-factor authentication, network segmentation, and tighter controls around privileged access. For firms managing sensitive consumer financial data, these are not abstract concerns. A breach affecting nonpublic information carries significant legal and reputational exposure.
The second pillar focuses on threat detection and readiness. DFS wants firms to confirm that intrusion detection tools are current and properly deployed, that log data is being actively monitored for anomalies, and that staff are briefed on active threat campaigns, including social engineering tactics that are increasingly sophisticated.
The third area covers resilience and response. Regulators are asking firms to test not just whether backups exist, but whether they can actually be restored within acceptable timeframes. Communication plans covering customers, personnel, and third-party vendors should also be pressure-tested against prolonged outage scenarios.




