NYDFS Readiness Assessment


First Name

Last Name





Company Name

Have you appointed a “Chief Information Security Officer (CISO)?

The CISO of each Covered Entity shall report in writing at least annually to the Covered Entity’s board of directors or equivalent governing body. If no such board of directors or equivalent governing body exists, such report shall be timely presented to a Senior Officer of the Covered Entity responsible for the Covered Entity’s cybersecurity program

Have your security personnel received training or instruction on the NYDFS?

Software alone cannot sufficiently counter all threats to data protection. Security personnel training should cover data processing obligations as well as the identification of breaches and risks.

Have your senior management been briefed on the NYDFS?

NYDFS compliance programme should involve senior stakeholders as it will require input from all departments

Have all staff received NYDFS awareness training?

Many staff are unaware of their contribution to protecting private information and what is expected of them. The NYDFS requires privacy awareness training to be provided to all employees

Have you reviewed and updated your privacy policies?

You will need to review all existing data protection and privacy policies to ensure they comply with the new requirements

Have you assessed all points of data collection to ensure that explicit consent is properly requested in each case?

The NYDFS implements more stringent requirements for obtaining consent when collecting data from individuals. Data collection will have to adhere to just-in-time notification of “reason for data collection” and communicating to data subjects “how their data will be processed” and procedures for “further engagement in terms of enhanced privacy rights.

Have you prepared, documented and communicated processes for managing subject data access requests?

Have data retention and destruction procedures been reviewed for all data (including offline) as used by your organization?

Have you re-assessed your suppliers and supplier contracts in relation to the NYDFS?

Have you made preparations to detect and report breaches as part of a response plan?

Have you prepared data breach notification procedures for informing data subjects?

Have you prepared for regular compliance audits or reviews to identify and fix issues?

Have you made preparations to abide by the NYDFS codes for ‘Privacy by Design and by Default’?

How can Risk Cognizance assist you?

NYDFS Self Assessment Questionnaire NYDFS Cybersecurity Regulation and its implications for financial institutions in Data Protection. DFS has emphasized working with its licensees and regulated persons to improve their programs, and licensees should embrace opportunities to improve and advance their cybersecurity readiness and systems.