By Yiddy Lemmer, CEO – CompuConnect, Inc.

For financial firms, cybersecurity compliance requires more than installing a firewall, endpoint protection, multifactor authentication, backups, and automated updates. Regulators increasingly expect organizations to demonstrate that their cybersecurity programs are risk-based, documented, comprehensive, and consistent with what is actually happening across their IT environment.

A recent 2026 enforcement action involving a regulated financial business provides a useful reminder. After a ransomware incident encrypted a significant portion of the organization’s servers, regulators investigated the cybersecurity program behind the incident. The investigation identified deficiencies involving the company’s cybersecurity risk assessment, the relationship between that assessment and its security program, and written policies for managing software and system security.

The lesson for financial firms is important: a cybersecurity incident can become more than an IT problem. It can expose weaknesses in the policies, assessments, processes, and documentation supporting the organization’s overall cybersecurity program.

What Can Regulators Examine After a Cybersecurity Incident?

When ransomware, unauthorized access, or another cybersecurity event occurs, the investigation may extend well beyond determining how the attacker entered the network.

Regulated financial organizations may need to demonstrate that they had an appropriate cybersecurity program in place before the incident occurred.

That can include questions such as:

  • Was a meaningful cybersecurity risk assessment performed?
  • Did the assessment identify risks specific to the business?
  • Were existing safeguards evaluated for effectiveness?
  • Were identified risks connected to cybersecurity controls and remediation plans?
  • Did written cybersecurity policies accurately reflect the organization’s technology environment?
  • Were vulnerabilities and software updates being managed across the systems and applications the organization actually uses?
  • Can the organization provide documentation showing that cybersecurity responsibilities were being carried out?

New York's financial cybersecurity framework, for example, requires covered organizations to maintain risk-based cybersecurity programs and conduct risk assessments that inform those programs. Regulators also maintain guidance emphasizing that regulated entities should continually evaluate cybersecurity risks as threats and technology environments change.

A Risk Assessment Should Be More Than an Annual Checklist

One of the most important lessons from recent cybersecurity enforcement is the difference between having a risk assessment and having an assessment that meaningfully informs the cybersecurity program.

A generic IT checklist may document servers, computers, software, or operational concerns. But a cybersecurity risk assessment should go further.

Financial firms should be able to answer questions such as:

What cybersecurity threats are relevant to our organization?

Every business has a different combination of employees, systems, applications, vendors, remote access, sensitive information, and operational dependencies.

The assessment should reflect the organization that actually exists, rather than relying exclusively on a generic template.

Which systems and information could be affected?

Organizations should understand where sensitive and nonpublic information resides, which systems support important business functions, and what could happen if those systems become unavailable or compromised.

What controls are already protecting those systems?

The assessment should consider safeguards such as access controls, multifactor authentication, endpoint security, email protection, backups, vulnerability management, monitoring, network security, and other controls relevant to the environment.

Are those safeguards actually sufficient?

This is where risk assessments become particularly valuable.

Simply documenting that a security control exists does not necessarily establish that the organization has adequately addressed the underlying risk.

The stronger question is:

Is the control appropriate, properly configured, consistently maintained, and effective for the risk it is intended to address?

Your Cybersecurity Program Should Follow the Risks You Identify

A risk assessment should not live in a folder and disappear until next year.

It should help drive the cybersecurity program.

If an assessment identifies an outdated system, unsupported application, excessive user permissions, weak remote-access process, unprotected third-party application, or another significant vulnerability, the organization should have a clear process for determining what happens next.

That may include remediation, additional safeguards, documented acceptance of the risk, further investigation, or a technology replacement plan.

This connection between risk assessment and action is fundamental to a mature cybersecurity program.

Regulatory guidance continues to reinforce the importance of updating risk assessments when threats change and using those assessments to guide vulnerability management and other defensive measures.

Patch Management Means More Than Windows Updates

Another important reminder for financial firms is that patch management should account for the broader technology environment.

Businesses frequently think about patching primarily in terms of operating-system updates.

But most organizations use many additional technologies, including:

  • Accounting and financial software
  • PDF and document-management applications
  • Web browsers
  • Remote-access tools
  • Server applications
  • Database software
  • Backup applications
  • Security products
  • Line-of-business applications
  • Vendor utilities
  • Cloud-connected software
  • Network-device firmware

Each can introduce vulnerabilities.

A cybersecurity program should therefore have a clear method for identifying applicable systems and applications, monitoring vulnerabilities, determining patching priorities, deploying updates, and confirming that remediation actually occurred.

This becomes especially important when software falls outside the organization's normal automated patching process.

A patch-management policy that covers only a small portion of the technology environment can create blind spots, even if the systems included in the policy are being updated correctly.

Written Cybersecurity Policies Need to Match Reality

Policies are another area where financial firms should exercise caution.

It is possible to have well-written cybersecurity documents that no longer match the business.

Technology changes.

Employees change.

Applications are added.

Vendors are replaced.

Remote-work arrangements evolve.

New cloud services appear.

Older systems remain in production longer than expected.

If cybersecurity policies are not updated alongside these changes, the organization can develop a gap between what the policy says happens and what actually happens.

That is why cybersecurity documentation should not be treated as paperwork created solely for an audit.

Policies should describe real operational processes, responsibilities, security standards, and controls.

Just as importantly, the organization should be able to demonstrate that those processes are being followed.

Smaller or Partially Exempt Firms Should Not Assume Cybersecurity Requirements Disappear

Another important lesson for regulated financial businesses is that qualifying for certain exemptions does not necessarily eliminate every cybersecurity responsibility.

Cybersecurity regulations may contain different requirements depending on factors such as organizational size, revenue, operations, and regulatory status. However, covered organizations can still retain important obligations involving cybersecurity programs, risk assessments, policies, incident reporting, access controls, and other core safeguards depending on the applicable rules.

Financial firms should therefore avoid assuming:

“We're small, so the cybersecurity regulation probably doesn't apply to us.”

A better question is:

“Which requirements apply to our organization, and can we demonstrate that we are meeting them?”

Compliance requirements should always be reviewed with appropriate legal and compliance professionals based on the organization's specific regulatory obligations.

Having Cybersecurity Technology Is Not the Same as Having a Cybersecurity Program

A firm can have:

  • Endpoint protection
  • Firewalls
  • Backups
  • Multifactor authentication
  • Email security
  • Security monitoring
  • Automated patching

and still have significant cybersecurity governance gaps.

Technology is only one part of the equation.

A mature cybersecurity program also requires appropriate processes, documentation, ownership, assessment, monitoring, remediation, planning, and accountability.

This is why businesses should evaluate cybersecurity from a broader perspective:

People + Process + Technology + Documentation + Accountability

All five need to work together.

Questions Financial Firms Should Be Asking Now

Rather than waiting for an incident, examination, insurance renewal, client request, or regulatory inquiry to expose weaknesses, leadership teams can proactively review their cybersecurity posture.

Start with these questions:

  1. When was our last cybersecurity risk assessment?
  2. Was it specific to our actual systems, operations, information, vendors, and cybersecurity threats?
  3. Did we evaluate whether our existing cybersecurity safeguards are effective?
  4. Can we show how identified risks influenced our cybersecurity program?
  5. Does our vulnerability and patch-management process include third-party applications, not just operating systems?
  6. Do our written cybersecurity policies match what our IT team actually does today?
  7. Can we produce documentation showing that important cybersecurity controls are being maintained?
  8. Do we have a process for tracking identified vulnerabilities through remediation?
  9. Have major changes to our business or technology environment been reflected in our cybersecurity planning?
  10. If a ransomware incident happened tomorrow, could leadership clearly explain the cybersecurity program that was in place before the event?

That final question may be the most important.

Cybersecurity Compliance Is Easier to Address Before an Incident

The purpose of proactive cybersecurity planning is not simply to satisfy a regulatory requirement.

It helps create a more stable, secure, and resilient business.

A well-managed cybersecurity program can help financial firms better protect sensitive information, reduce operational disruption, improve business continuity, prepare for compliance reviews, manage technology risk, and make more informed IT decisions.

More importantly, firms should not have to figure all of this out only after something has gone wrong.

CompuConnect works with financial organizations to align managed IT services, cybersecurity, risk management, technology planning, and business continuity around the way the organization actually operates. Our approach combines proactive IT strategy with 100% live human support, so when your team needs help, they reach real people who understand your business and take accountability for helping keep it running.

Is Your Cybersecurity Program Ready for a Closer Look?

If you are unsure whether your risk assessments, security controls, patch-management processes, cybersecurity policies, and IT environment are working together as they should, now is a good time to review them.

Schedule a discovery call with CompuConnect to discuss your current IT and cybersecurity environment, identify areas that may deserve attention, and build a clearer plan for security, compliance, stability, and business continuity.

A proactive review today can help your firm avoid discovering important gaps when the stakes are much higher.

About the Author
Yiddy LemmerYiddy Lemmer is the Founder and CEO of CompuConnect IT, a leading IT support and cybersecurity firm serving small and midsize businesses across New York and New Jersey. With over 18 years of hands-on experience, multiple Microsoft and CompTIA certifications, and deep roots in Brooklyn, Yiddy leads with a passion for technology, service excellence, and helping businesses thrive through secure and efficient IT systems.