NYDFS Sets Out What a Part 500 Risk Assessment Has to Contain
DFS’s September 10, 2026 industry letter on 23 NYCRR 500.9 — what examiners expect a cybersecurity risk assessment to contain, and why it matters before the April 15 certification.
Sosa & Arvelo is a management consulting firm that works where the stakes are public and the record matters — multi-billion-dollar regulatory proceedings, government agency finance and operations, cybersecurity and compliance programs, and the financial infrastructure that boards, funders, and examiners rely on.
Where we work
Our work spans regulated industry, government, and the nonprofit sector. What the engagements have in common is not an industry — it is that somebody else will eventually read the file: a regulator, an auditor, a board, a court, a funder.
Regulatory proceedings with multi-billion-dollar implications, restructuring and oversight matters, and critical-infrastructure and OT security.
Explore
Agency finance and operations, public retirement systems, municipal financial management, federal funds administration, and the transformation programs that have to finish under public scrutiny.
Explore
Examination readiness, internal controls and financial reporting, enterprise risk, cybersecurity programs and annual certification, vendor risk, and incident response designed by someone who has handled the evidence.
How we help
Federal grant compliance, tax-exempt status before the IRS and Hacienda, fund accounting, annual filings, and controls that work with the team you actually have.
How we helpCore services
Security programs, privacy compliance, and modernization for organizations that cannot afford to fail an examination.
Fund accounting, federal financial management, and cost recovery that keeps funders confident and files defensible.
Enterprise risk, regulatory compliance, third-party risk, and internal controls built to be tested — not filed.
Planning, program and project management, and transformations that finish — with the constraints in the first draft.
Insights

DFS’s September 10, 2026 industry letter on 23 NYCRR 500.9 — what examiners expect a cybersecurity risk assessment to contain, and why it matters before the April 15 certification.

Executive Order 14421 declares a national emergency over foreign-produced grid equipment, prohibits covered transactions initiated after August 26, 2026, and puts the Department of Energy on a 120-day rulemaking clock.

On August 11, 2026, FinCEN issued a final rule that permanently removes the requirement for U.S. companies and U.S. persons to report beneficial ownership information under the Corporate Transparency Act.
The firm
Before Sosa & Arvelo, our partners ran them. Between them they have run the financial operation of one of Puerto Rico’s largest municipalities, served as deputy administrator of a government retirement system managing roughly $2 billion, directed a state cybercrime investigative unit, and distributed federal and state grant funding to nonprofit organizations.
Most of that experience was accumulated inside the institutions that write and enforce the rules organizations now live under — which is why the work concentrates where it does.
Regulations are written to be defensible, not clear. Translating them is most of the job.
Most organizations cannot staff a textbook control environment. Controls that ignore that are theater.
We are a small firm with a defined range. When something falls outside it, we say so — and we usually know who is more likely to be right for it.
Next step
A 30-minute conversation, no charge, no obligation. We will tell you whether an assessment is the right next step, whether we are the right firm — and if we are not, who is more likely to be.