Go-To Guide: - On May 21, 2026, the New York Department of Financial Services (NYDFS) published two companion industry letters: a guidance on measures regulated entities should consider in a heightened cybersecurity threat environment, and an advisory on the cybersecurity risks posed by frontier AI models. - The Heightened Threat Environment Guidance catalogs specific measures across three categories: reducing the attack surface, improving threat detection and readiness, and strengthening resilience and response. - The Frontier AI Advisory directs CISOs to particular sections of the Heightened Threat Environment Guidance and layers on AI-specific recommendations for vulnerability management, secure coding, and third-party coordination. - Neither publication creates new legal requirements under 23 NYCRR Part 500. Both articulate DFS’s expectations for how regulated entities should calibrate their existing cybersecurity programs when threat conditions escalate. Still, both publications preview examination expectations. On May 21, 2026, NYDFS published two related industry letters addressing cybersecurity preparedness for DFS-regulated financial institutions, insurers, and money transmitters. The first, titled Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment (the Guidance), provides a structured menu of defensive measures entities should consider when cybersecurity risks become significantly elevated. The second, titled Heightened Cybersecurity Risks Associated with Frontier AI Models (the Advisory), warns that certain AI models capable of identifying vulnerabilities and exploits at unprecedented speed and scale will soon become more widely available, and directs entities to prepare now. The two documents are designed to work together: the Advisory identifies the threat, and the Guidance provides recommendations on how to respond. Neither publication creates binding requirements. Both documents state explicitly that they do not alter the obligations under Part 500. The Guidance frames its recommendations as measures entities “should consider” adopting based on their “unique circumstances and operations.” The Advisory states it is “intended to inform
NYDFS Issues Dual Guidance on Heightened <b>Cybersecurity</b> Threats, Frontier AI Risks
Read the original article
natlawreview.com →