Why a US regulator’s guidance matters to UK SMEs
The New York Department of Financial Services (NYDFS) has issued extensive guidance on cybersecurity risk assessments, as reported by Mayer Brown. Although this is a US regulatory development, it should not be dismissed as irrelevant by a UK small or medium-sized enterprise (SME).
NYDFS regulates financial services firms in New York, rather than British businesses. It does not create a direct legal duty for a UK retailer, accountancy practice, manufacturer or professional services firm. However, its focus on making risk assessments evidence-based, repeatable and tied to business decisions reflects a wider direction of travel in cyber governance. That direction is highly relevant to UK insurers, brokers, supply-chain partners and larger corporate customers.
For a UK SME, the useful question is not, “Do we have to follow NYDFS guidance?” It is: could we clearly show an insurer, customer or regulator that we understand our cyber risks and have acted proportionately? A credible risk assessment is increasingly the foundation for answering that question.
A risk assessment is more than an annual IT checklist
Many smaller firms treat cyber risk assessment as a compliance document: a spreadsheet completed once a year, perhaps shortly before renewing cyber insurance. That approach is becoming difficult to defend.
A meaningful assessment connects the firm’s actual operations to realistic loss scenarios. It should identify the systems and information that matter most, the threats that could disrupt them, existing safeguards, material gaps and the people responsible for resolving those gaps.
For example, an architecture practice may depend on cloud-hosted project files, email and a small number of staff with authority to approve supplier payments. Its priority risks may include business email compromise, account takeover and loss of access to design files. A small manufacturer may instead need to focus on ransomware affecting production scheduling, remote access to machinery, and the availability of its managed IT provider.
These are not abstract technical concerns. They affect whether the business can trade, pay staff, meet contractual deadlines and protect personal data.
The difference between a vulnerability list and a business risk assessment
A vulnerability scan may report missing software patches. A cyber risk assessment asks what those patches mean in the context of the business:
- Is the affected device exposed to the internet or separated from critical systems?
- Could exploitation lead to theft of customer data, fraudulent payments or operational downtime?
- Is multi-factor authentication (MFA) in place?
- Is there a tested backup that could restore essential data?
- Who owns the decision to remediate the problem, and by when?
This distinction matters because insurers and incident-response specialists do not merely need to know that a tool was purchased. They need to understand whether controls were actually operating and whether management made sensible decisions when risks were identified.
What this means for cyber insurance applications and renewals
Cyber insurance remains an important financial safety net, but it is not a substitute for cyber hygiene. Policies can help fund specialist incident response, legal advice, forensic investigation, data recovery, business interruption losses, notification costs and certain third-party liabilities, subject to the wording, excesses and exclusions. The scope varies significantly between insurers.
The underwriting process is also more detailed than it was several years ago. UK SMEs are commonly asked about MFA, endpoint protection, backups, patching, email security, staff training, privileged access, outsourced IT arrangements and incident-response planning. A business that cannot answer these questions confidently may face a higher premium, restrictive terms, a declined application or a requirement to improve controls before cover is offered.
The broader lesson from the NYDFS focus is that insurers are likely to place increasing value on governance evidence, not simply tick-box declarations. If a proposal form asks whether MFA is enabled for remote access and email, an inaccurate “yes” can create serious problems. If a claim follows a phishing attack and MFA was not deployed as represented, the insurer may investigate whether the disclosure was fair and accurate.
Build evidence before you need to make a claim
A practical risk assessment creates a record that supports both resilience and insurance discussions. SMEs should retain:
- a current inventory of key systems, cloud services and data stores;
- records showing which accounts have administrator privileges;
- MFA deployment reports or settings screenshots;
- backup schedules, restoration test results and retention periods;
- patch-management reports from internal or outsourced IT teams;
- cyber awareness training records and phishing-test results, where used;
- an incident-response plan with current contact details; and
- a risk register recording decisions, deadlines and accountable owners.
This does not need to become a burdensome corporate bureaucracy. For many SMEs, a well-maintained risk register and quarterly management review can be more valuable than a glossy 80-page policy that nobody uses.
Four actions UK SME leaders should take now
1. Identify the business services that cannot stop
Start with business impact, rather than technology. List the services that must remain available for the company to operate: payment processing, email, customer booking systems, payroll, production planning, client files or e-commerce platforms.
For each service, establish the maximum tolerable outage. Could the business cope without it for four hours, two days or two weeks? This helps prioritise security spending and informs the level of business interruption cover worth considering.
2. Map where critical data and access sit
SMEs often underestimate how widely data is spread. Customer information may exist in Microsoft 365, accounting software, CRM systems, personal laptops, outsourced payroll portals and email inboxes. Map these locations, identify the suppliers involved and remove access that former staff or contractors no longer need.
Pay special attention to administrator accounts, finance-team access and email. These are common routes to high-impact fraud and ransomware incidents.
3. Test controls rather than assuming they work
A backup that has never been restored is not proven recovery capability. MFA that applies only to some staff is not universal MFA. An incident plan without a tabletop exercise is unlikely to work smoothly under pressure.
Set a small number of tests each quarter. Restore a sample file; check leavers’ accounts have been disabled; run a simulated phishing email; confirm the IT provider’s emergency contact route; and rehearse who can authorise a bank-detail change. Document the result and any corrective action.
4. Review policy wording against your actual risks
Do not buy cover solely on the basis of a headline indemnity limit. Ask a broker or insurer how the policy treats ransomware response, social engineering or invoice fraud, business interruption, supplier outages, forensic costs, data restoration and regulatory investigation. Check waiting periods, sub-limits, exclusions and the notification procedure.
If your business relies heavily on a cloud provider or managed service provider, ask specifically how dependent business interruption and third-party service failures are handled. The answer may differ materially between policies.
Governance is a commercial advantage, not just a compliance burden
The most important implication of the NYDFS development is cultural. Cybersecurity risk assessment should be owned by business leadership, with input from IT, finance, operations and any external technology provider. It should not be delegated entirely to an IT contractor and forgotten until the next renewal.
For UK SMEs, this approach can improve more than insurance outcomes. It can support tenders where customers request security assurances, make due diligence easier for investors or acquirers, reduce downtime after an incident and provide directors with a clearer record of decisions made. It also complements UK expectations under the UK GDPR and the Information Commissioner’s Office’s accountability principle, particularly where personal data is involved.
The goal is proportionate control, not enterprise-scale complexity. A ten-person firm does not need the same programme as a global bank. But it does need to know what could stop it trading, what protections are genuinely in place and what it will do in the first hours of a cyber incident.
FAQ
Does NYDFS guidance apply directly to UK SMEs?
No. NYDFS is a New York regulator, and its guidance does not itself impose legal obligations on ordinary UK SMEs. Its relevance is indirect: it illustrates the stronger, more documented approach to cyber risk assessment increasingly expected across financial services, insurance and supply chains.
Will a cyber risk assessment lower my cyber insurance premium?
Not automatically. Premiums depend on revenue, sector, claims history, data holdings, controls and the cover required. However, a robust assessment can reveal weaknesses before an insurer does, help provide accurate application answers and support a stronger underwriting discussion.
What is the first cyber control a small business should prioritise?
There is no universal single control, but MFA for email, remote access, cloud applications and administrator accounts is often a high-value starting point. It should be paired with secure, tested backups, prompt patching and payment-verification procedures.
Should an outsourced IT provider complete the assessment?
An IT provider should contribute technical evidence and recommendations, but business leaders should own the final assessment. They are best placed to judge financial impact, customer commitments, risk appetite and the priority of remediation work.
Source: Mayer Brown — Mon, 14 Sep 2026 23:10:07 GMT