{"publisher":"NovaCopilot","source":{"name":"New York State Senate Open Legislation","url":"https://www.dfs.ny.gov/system/files/documents/2023/12/rf23_nycrr_part_500_amend02_20231101.pdf"},"license":"https://legal.exploreworldai.com/revision","id":"us-new-york:nydfs-risk-assessment","jurisdiction":"United States","state":"New York","level":"state","question":"How often must an NYDFS covered entity assess cyber risk?","answer":"The covered entity must conduct a periodic risk assessment sufficient to inform the design of its cybersecurity program and update it as reasonably necessary when business or technology changes cause a material change in cyber risk.","reference":"23 NYCRR § 500.9","authority":"New York State Department of Financial Services","legalKind":"regulation","status":"In force at the reading date","readAt":"2026-09-22","relatedRules":[],"relatedCases":[],"canonical":"https://legal.exploreworldai.com/us/new-york/questions/nydfs-risk-assessment","version":"us-new-york-v1.0.0","hash":"sha256:85857911eb5a573bb2119c5333610a4afd8f2f98e16c7096508ab8a44b10496c"}