Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should financial services firms build an effective…
Governance, Ownership & Risk

How should financial services firms build an effective cybersecurity program under NY DFS rules when data inventories are incomplete?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Governance, Ownership & Risk

Start with a risk-based data inventory, not a checklist of controls. Firms should identify where data lives, who can access it, and which data sets could cause material harm if exposed. That means scanning structured and unstructured sources, mapping data flows, and continuously updating classifications so access controls, monitoring, and protection follow the highest-risk data first.

Why Incomplete Inventories Still Support a Defensible Cybersecurity Program

Under NY DFS, the practical answer is to build the program around what you can already verify, then expand coverage as inventory quality improves. A partial inventory is still useful if it identifies the most material data stores, the systems that move data between them, and the access paths most likely to create harm. The goal is prioritisation, not perfection on day one.

For firms with limited visibility, the first useful distinction is between known assets and known risk. Even when discovery is incomplete, you can classify high-value repositories, external data-sharing points, and business processes that depend on them. That lets security teams align monitoring and protection to where exposure would matter most, rather than waiting for a fully complete catalog before acting.

Risk-based inventories also work better because they connect data discovery to control decisions. Once a dataset is identified as sensitive or business-critical, firms can decide whether it needs stronger authentication, tighter access review, encryption, logging, retention limits, or a separate approval path for exceptions. The inventory therefore becomes an operating input, not a compliance spreadsheet.

What to Inventory First When Coverage Is Missing

The most effective starting point is not every record in the estate, but the data classes and flows that can cause material harm if exposed, altered, or unavailable. That usually includes customer information, credentials or tokens, payment or trading data, regulated records, and repositories that can be used to pivot into other systems. Scan both structured and unstructured sources, because the highest-risk content is often in file shares, email, collaboration platforms, and exports rather than core databases.

Firms should also map who can access the data and how that access is used. Incomplete inventories often fail because they list locations without showing the business owners, system owners, or service relationships that actually move the data. A usable inventory should capture source, destination, classification, owner, access path, and the reason the data exists in the first place. That is enough to start risk ranking and control placement.

As the inventory matures, classification should be continuously updated when data moves, when new feeds are added, or when a repository becomes accessible to a broader population. That matters because the security program needs to track the current state of exposure, not the state that existed when the first scan was run. Firms should treat changes in data location or access pattern as triggers for review, not as background noise.

How NY DFS Expectations Translate into Program Design

The NY DFS approach is effective when governance, monitoring, and protection are tied to the firm’s actual risk profile. A firm with an incomplete inventory can still show control maturity by proving it has a repeatable process for discovery, escalation, remediation, and review. That process should cover how data is found, how it is rated, who approves exceptions, and how unresolved gaps are tracked.

In practice, that means the program should not wait for perfect central visibility before deploying controls. High-risk data should be protected first through segmentation, access restriction, alerting, and evidence retention. Lower-risk or lower-confidence areas can follow later, but they still need a defined path into the inventory lifecycle. This is the difference between a static register and a functioning cybersecurity program.

The stronger the connection between inventory and control, the easier it is to demonstrate that the firm is acting on its most material exposures. A good program shows that data discovery drives action, action creates measurable reduction in exposure, and the remaining gaps are visible to management. That posture is usually more defensible than broad policy language with no operational prioritisation.

Risk and Threat Considerations

Incomplete inventories create blind spots that can leave sensitive data overexposed, unmonitored, or governed by the wrong control. That becomes a real security issue when unknown repositories or untracked copies retain high-value information, especially if access is broader than intended or if the data can be used to reach other systems.

Failure mechanism: Discovery gaps prevent the firm from applying the right controls to the right places, so sensitive data may remain outside classification, logging, review, or retention processes until an incident or audit forces the gap into view.

Impact: The result can be delayed detection, excessive access, weak accountability, and a larger blast radius if the exposed data is later stolen, misused, or copied into unmanaged locations.

Practitioner Guidance

What to measure: Track the percentage of high-risk repositories with assigned owners, current classifications, and validated access mappings. Those measures are more useful than a raw discovery count because they show whether the inventory is actually supporting protection.

Decision rule: If a dataset is not fully inventoried but it is plausibly material to customers, operations, or regulatory exposure, treat it as high priority for interim controls and review. Do not wait for perfect discovery before limiting access or increasing monitoring.

Practitioner takeaway: The operational test is whether unknowns are shrinking the exposure surface faster than the business is creating new ones; if not, the inventory process is not yet mature enough to support the program.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0ID.AM-01 — Physical Devices and Systems InventoryRisk-based inventories depend on knowing what systems and data stores exist.
ID.AM-02 — Software Platforms and Applications InventoryApplication and platform inventories expose where unstructured and structured data can reside.
ID.AM-07 — Inventories of Data and Assets are maintainedThe subject is directly about maintaining an incomplete but improving data inventory.
Recommendation — Inventory the systems that store or move sensitive data before expanding to lower-risk assets. Map applications and platforms that create or expose sensitive datasets. Maintain and continuously update the data inventory as classifications and flows change.
ISO/IEC 27001:2022A.5.9 — Inventory of information and other associated assetsIncomplete inventories are central to asset and information governance under the ISMS.
Recommendation — Build and maintain an inventory that identifies information assets, owners, and business importance.

Practitioner Guidance

What to prioritise: Start with the data sets most likely to cause customer harm, regulatory issues, or lateral exposure if exposed. If the inventory is incomplete, focus first on repositories with broad sharing, external transfer, legacy access, or weak ownership, because those are the areas most likely to undermine the whole program.

What to verify: Confirm that every high-risk dataset has an owner, a current classification, a known access path, and a documented reason it must exist. If any of those are missing, treat the dataset as a control gap, not just a discovery gap.

Practitioner takeaway: Under NY DFS, an incomplete inventory is acceptable as a starting point only if it is already driving risk-based decisions; the program fails when firms wait for completeness before protecting the data that matters most.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org