The CISO owns the cybersecurity program end to end. This piece is about regulated financial services in the United States: firms licensed by the New York State Department of Financial Services under New York's Banking Law, Insurance Law or Financial Services Law, and companies that report to the Securities and Exchange Commission. The common reference standard is the NIST Cybersecurity Framework, published by the National Institute of Standards and Technology. Its taxonomy and referenced practices are not country-specific, and earlier versions have been used by governments and other organizations inside and outside the United States, so a firm in Bermuda or the United Kingdom can apply it as written.
Ownership here means accountability: the person who answers for the results.
Governance has a named owner
NIST's Cybersecurity Framework is meant to help organizations understand and improve how they manage cybersecurity risk, and version 2.0 is written for industry, government and other organizations trying to reduce that risk. Its primary audience is narrower: the individuals responsible for developing and leading cybersecurity programs.
The Core of CSF 2.0 organizes outcomes under six Functions: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER. GOVERN sits at the center because it shapes how an organization carries out the other five. Version 2.0 gave governance and supply chains more weight than earlier versions did.
Inside GOVERN, the framework says organizational leadership is responsible and accountable for cybersecurity risk. That outcome is GV.RR-01, where GV is the Govern Function and RR is its Roles, Responsibilities, and Authorities category. A companion outcome, GV.RR-03, asks that resources be allocated in proportion to the cybersecurity risk strategy, roles, responsibilities and policies. A third, GV.OC-03, requires that legal, regulatory and contractual cybersecurity requirements, including privacy and civil liberties obligations, be understood and managed.
The resourcing outcome sits next to the accountability outcome. A committee can approve a risk appetite and adjourn. Someone still has to explain why a control the risk strategy called for went unfunded for three quarters and why the residual risk was accepted in the meantime. When governance is spread across a group, that explanation turns into a discussion and nobody makes a decision.
A named regulator draws the outer boundary
The New York State Department of Financial Services issued 23 NYCRR Part 500 on 1 March 2017 and called it the first cybersecurity regulation of its kind in the United States for financial services companies. The citation refers to title 23 of the New York Codes, Rules and Regulations, the state rulebook for the firms the department licenses. It covers any individual or organization operating under a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, Insurance Law or Financial Services Law, whether or not other agencies also regulate it.
The regulation calls these licensed firms Covered Entities. They must implement and maintain risk-informed cybersecurity policies and programs, and Section 500.1 defines the terms. The department monitors cybersecurity and information technology risk through a multi-pronged, risk-based approach.
Its expectations keep changing. On 21 May 2026 the department sent regulated entities an industry letter on the cybersecurity risks of Frontier AI Models. On 10 September 2026 it issued guidance on designing, conducting and updating Risk Assessments. It also enforces: it announced a $2.25 million cybersecurity settlement with Delta Dental on 30 April 2026 and issued a consent order to Order Express, Inc. in August 2026.
Someone inside each licensed firm has to track those changes as they happen.
Disclosure puts the program on a clock
The Securities and Exchange Commission's cybersecurity disclosure amendments took effect on 5 September 2023. A registrant must file a Form 8-K under Item 1.05 within four business days of determining that a cybersecurity incident is material. Form 8-K is the current report a United States public company files when investors need to know something promptly, and Item 1.05 is reserved for material cybersecurity incidents. The Commission said that an incident with no quantifiable harm is not necessarily immaterial, because reputational harm can be material too.
- The Commission declined to adopt proposed Item 407(j), which would have required registrants to describe their directors' cybersecurity expertise in the proxy statement, so board-level expertise is not a required disclosure.
- Smaller reporting companies were not exempted from the final rules; issuers of asset-backed securities were.
- Foreign private issuers, meaning non-United States companies that report to the Commission, furnish material incident information on Form 6-K, the report used for material information they release abroad, and make governance disclosures in Item 16K of Form 20-F, their annual report.
- The Commission identified one conflict with another United States federal rule, the Federal Communications Commission's notification rule for breaches of customer proprietary network information, and added a limited delay for registrants subject to it.
Once an incident is under way there is no time to decide who makes the materiality call. The CISO has to set that process up in advance, name and rehearse the legal, finance and security people in it, and answer for how it runs.
The framework states outcomes and leaves methods open
CSF 2.0 is a taxonomy of high-level outcomes that any organization can use, whatever its size, sector or maturity. It does not prescribe how to achieve them. An Organizational Profile describes current or target posture against the Core's outcomes. Building one takes five steps, the last of which is carrying out the action plan and updating the Profile, and the cycle can repeat as often as needed.
The framework describes rigor with four Tiers: Partial, Risk Informed, Repeatable and Adaptive. NIST encourages moving to a higher Tier when risks or mandates are greater, or when a cost-benefit analysis shows a feasible and cost-effective reduction in risk. At Tier 3, Repeatable, risk management practices are formally approved and written as policy, and senior cybersecurity and non-cybersecurity executives talk regularly about cybersecurity risk.
NIST does supply material to work from. A Community Profile is a published baseline of outcomes, usually for a sector, subsector, technology or threat type, and an organization can use one as the starting point for its own Target Profile. NIST publishes templates for creating and using profiles, and the Informative References Quick-Start Guide explains how to find, filter and apply informative references with NIST tools.
That material keeps growing. The NIST National Cybersecurity Center of Excellence published the final NIST Interagency Report 8576, a Transit Cybersecurity Framework Community Profile for United States transit agencies. CSF 2.0 has been translated into more languages, including Arabic, and turned two on 24 February 2026. A draft quick-start guide covers ways to use artificial intelligence when analyzing, planning, implementing and monitoring progress toward CSF 2.0 outcomes.
The program reaches past the security team
Cybersecurity supply chain risk management, GV.SC, is one of the six Govern Categories. Its Subcategories link cybersecurity outcomes to supply chain outcomes. One of them, GV.SC-05, says requirements for supply chain cybersecurity risk should be established, prioritized and written into contracts and other agreements with suppliers and relevant third parties.
The Functions, Categories and Subcategories apply to all the information and communications technology an organization uses, including information technology, the Internet of Things and operational technology, and to cloud, mobile and artificial intelligence environments. Cybersecurity risk management also covers privacy risks from the loss of confidentiality, integrity or availability of people's data, although some privacy risks have nothing to do with a cybersecurity incident.
Reporting cyber risk as enterprise risk
The CSF helps organizations translate cybersecurity terms into the general risk language executives use. Those executives are responsible for fitting cybersecurity risk management into enterprise risk management and into lower-level risk programs. Practitioners give managers and executives information such as key performance indicators and key risk indicators, so leadership can judge the organization's posture, make decisions and keep or adjust the risk strategy.
Under the framework, priorities should fit the organization's mission, its legal and regulatory requirements, and its expectations for risk management and governance.
In practice this is a reporting duty, and its test is whether the indicators change what the board funds, defers or accepts.
The program never stops
The framework treats its Functions as concurrent. GOVERN, IDENTIFY, PROTECT and DETECT run all the time, and RESPOND and RECOVER stay ready and run when incidents occur. Cybersecurity risks keep growing, so managing them is continuous work at every level of maturity. Organizations may adopt the CSF voluntarily or because a government policy or mandate requires it.
The program never stops, so someone has to answer for its results at any time, including the day an incident is found to be material. That person is the CISO, who owns the program end to end.