What Is a Cybersecurity Risk Assessment?
A thorough cybersecurity risk assessment typically inventories the systems and data the firm relies on (client portals, custodial platforms, email, file storage), evaluates access controls and authentication practices, reviews third-party vendor security (particularly custodians and software providers with access to client data), and identifies gaps against the firm’s written cybersecurity policy. The output is generally a findings report with prioritized remediation steps, which the CCO uses to update the firm’s policies and, where needed, its technology practices.
Examiners increasingly ask for evidence of a recent risk assessment as part of routine exams, treating it as a baseline expectation rather than an advanced practice.