The New York State Department of Financial Services issued guidance clarifying how regulated entities should conduct risk assessments that inform their cybersecurity programs. The guidance does not create new obligations but explains existing requirements for assessments to be reviewed and updated at least annually and whenever business or technology changes materially alter an entity’s cybersecurity risk. Effective assessments should address governance and oversight, methodology, scope and documentation, with findings integrated into cybersecurity controls and risk decisions. Entities should reassess risks around major system migrations, acquisitions and new critical systems, evaluate concentrations among third-party providers, consider how artificial intelligence and other emerging technologies affect their exposure, and determine whether controls, monitoring or risk acceptance decisions require updates.