Guidance on Managing Risks Related to Third-Party Service Providers
On October 21, 2025, the New York State Department of Financial Services (NYSDFS) issued updated third-party service provider guidance focused on a range of cybersecurity and technology issues. The guidance was prompted by department examiners finding that some firms needed to strengthen how they monitor, assess, and manage third-party service provider cybersecurity risk. Although the refreshed guidance does not impose any new formal obligations on the institutions supervised by the Department, taken as a whole, the guidance provides an extremely useful template even for non-financial services firms.