Skip to content
RiskTemplates · The Daily Brief Tuesday, August 4, 2026
Wire Gotbit SEC Settlement: The Crypto Wash-Trading Controls That Matter Now AUG 3

Feature Data Privacy

NYDFS's First 2026 Cybersecurity Fine Wasn't About the MOVEit Hack. It Was About What Happened After.

On April 29, 2026, NYDFS issued a $2.25 million consent order against Delta Dental of New York—its first 2026 cybersecurity enforcement action. The underlying breach was a 2023 MOVEit zero-day. The violations were late notification, inadequate data disposal, and insufficient incident response plan detail. And the consent order bars insurance reimbursement. Here's what the enforcement record tells your program.

By Rebecca Leung · August 2, 2026 ·
Table of Contents

TL;DR

  • NYDFS issued its first 2026 cybersecurity enforcement action on April 29: a $2.25 million consent order against Delta Dental of New York for a 2023 MOVEit breach
  • The violations were not the hack itself—they were late notification (well beyond the 72-hour rule), inadequate data disposal policies, and insufficient incident response plan detail
  • The consent order bars Delta Dental from seeking insurance reimbursement, indemnification, or tax deduction for the penalty—the financial hit is direct
  • SEC Regulation S-P’s 30-day customer notification requirement became mandatory for smaller entities on June 3, 2026, and is a named 2026 SEC examination priority
  • Multiple parallel notification clocks are now active for most regulated financial entities; most programs are under-documented on at least one

Delta Dental didn’t create the MOVEit vulnerability. Progress Software shipped it. The Clop ransomware group exploited it globally in May 2023, hitting thousands of organizations across industries. Delta Dental was one of them.

None of that insulated it from NYDFS. The $2.25 million fine wasn’t about the breach. It was about data Delta Dental retained longer than it should have, a notification the organization sent weeks or months late, and an incident response plan that didn’t have enough operational detail to function under real conditions.

That’s the enforcement architecture regulators across frameworks are now building: the breach is the predicate event, but the violations are the response.

NYDFS’s First 2026 Cybersecurity Enforcement Action

On April 29, 2026, the New York Department of Financial Services announced a consent order against Delta Dental of New York and Delta Dental Insurance Co., assessing a $2.25 million civil monetary penalty.

The underlying incident was the 2023 MOVEit zero-day—the Progress Software file transfer tool vulnerability that CISA rated critical and that affected government agencies, universities, financial institutions, and healthcare organizations worldwide. Delta Dental’s data was compromised through its use of MOVEit.

NYDFS found three violations, each independent of whether the breach was preventable:

Violation 1: Late notification. Delta Dental did not notify NYDFS until mid-December 2023—well beyond the 72-hour window required by 23 NYCRR Part 500. The MOVEit vulnerability became public in late May 2023 when Progress Software disclosed it. The gap between when the breach occurred and when NYDFS was notified spanned months.

Violation 2: Inadequate data disposal policies. NYDFS Part 500.13 requires covered entities to maintain policies for the secure disposal of nonpublic information no longer necessary for business operations. Delta Dental’s disposal policies were inadequate. The practical consequence: data that should have been deleted was still retained when the breach occurred, expanding the scope of what was exposed.

Violation 3: Insufficient incident response plan detail. Delta Dental’s IR plan lacked the specificity NYDFS considers necessary for operational effectiveness. A generic plan—phases, roles, a CISO named as overall owner—is not the same as a plan detailed enough to actually use during a real incident.

One additional term: the consent order expressly prohibits the companies from seeking insurance reimbursement, indemnification, or any federal or state tax deduction or tax credit for the $2.25 million penalty. The financial deterrent is uninsurable and non-deductible by design.

Delta Dental did not admit or deny the findings.

The 72-Hour Rule: What “Determines” Actually Means

The notification timing violation in the Delta Dental case turns on a single statutory word: determines.

Under 23 NYCRR 500.17, a covered entity must notify the NYDFS Superintendent as promptly as possible, and within 72 hours, after determining that a cybersecurity event has occurred. Not after completing a forensic investigation. Not after quantifying the full population of affected individuals. Not after confirming that data was actually exfiltrated.

After determining.

NYDFS has made clear through prior guidance and enforcement actions that “determining” occurs when the covered entity has sufficient information to conclude a reportable event has occurred. For a widely-publicized zero-day vulnerability like MOVEit: if your organization used MOVEit and you learned in late May 2023 that MOVEit was being actively exploited to exfiltrate customer data, that’s the moment you have sufficient information.

The argument that you needed to wait for investigation completion—to know exactly how many records were affected, exactly what data was taken, exactly who is at risk—is not an adequate justification for a notification that arrives months late. NYDFS and other regulators have consistently rejected this logic. Investigation continues after notification; notification doesn’t wait for investigation to finish.

Your incident response decision log should document the specific moment when the organization’s determination of a cybersecurity event occurs—the evidence available, who made the determination, and who approved the notification. That document is the first thing regulators ask for when they’re assessing whether notification timing was appropriate.

The Parallel Notification Landscape in 2026

The Delta Dental case is specifically about NYDFS Part 500. But most regulated financial entities are operating under multiple parallel notification obligations, each with its own clock, trigger definition, and reporting mechanism.

FrameworkWho It CoversClockTrigger Event
NYDFS 23 NYCRR 500NY-licensed banks, insurers, mortgage servicers, fintechs72 hours”Determines” cybersecurity event occurred
Bank regulators (OCC/FDIC/Fed)Banks and service providers to banks36 hours”Computer-security incident” determination
SEC Regulation S-PBroker-dealers, RIAs, funds, transfer agents30 days (customer notification)Unauthorized access to sensitive customer info
FTC Safeguards RuleNon-bank financial institutions30 days (FTC notification)Breach of 500+ consumers’ unencrypted info
SEC Item 1.05 (8-K)Public companies4 business daysMaterial incident determination
State breach notification lawsVaries by state30–90 days (varies)Unauthorized acquisition of personal info

These clocks are independent of each other. A single incident at a registered investment adviser that holds New York licenses may trigger NYDFS (72 hours after determination), SEC Reg S-P (30-day customer notification), and potentially state notification laws covering affected customers in other jurisdictions—all with different trigger definitions running simultaneously.

The SEC Regulation S-P deadline matters specifically right now: smaller SEC-regulated entities—RIAs below $1.5 billion in AUM and funds below $1 billion—had a compliance deadline of June 3, 2026. Firms that relied on the extended deadline and haven’t built out a written incident response program and customer notification procedures are now operating without required controls. The SEC has named Regulation S-P compliance as a named 2026 Division of Examinations priority. That means exam staff are actively looking for it.

The Data Disposal Violation: The Part That Multiplies Your Risk

The data disposal violation doesn’t generate as many headlines as the notification timing failure, but it’s arguably the more consequential operational lesson.

Here’s why it matters. NYDFS found that Delta Dental’s data disposal policies were inadequate—meaning the organization retained nonpublic customer information beyond the point where it was necessary for business operations. When the MOVEit breach occurred, more data was exposed than needed to be available.

This is data disposal failure as a force multiplier: the policy gap doubled as a breach scope gap. Every piece of customer data retained beyond its legitimate retention period is incremental breach exposure that wouldn’t exist if the disposal program worked correctly.

The framework requirements are explicit. NYDFS Part 500.13 requires covered entities to include in their cybersecurity program policies and procedures for the secure disposal of nonpublic information no longer necessary for business operations, except where retention is required by law or regulation. The FTC Safeguards Rule includes a comparable data retention limitation. SEC Regulation S-P, in its amended form, includes data security provisions that touch retention and disposal practices.

A defensible data disposal program answers four questions:

What retention periods apply to each category of nonpublic information? Not a generic “7-year retention policy” but category-specific schedules tied to the business purpose and applicable regulatory requirements for each data type.

Who executes disposal at end-of-retention? A retention schedule that no one is actually running is not a disposal program—it’s a document. There needs to be an operational process with a specific owner.

What documentation exists that disposal occurred? When a breach happens and a regulator asks “why was this data still available?”, the answer needs to be documented evidence of disposal execution—not an assertion that the policy would have required disposal.

How does disposal interact with litigation holds and regulatory holds? Data on litigation hold or regulatory hold cannot be disposed of even if the retention period has passed. Your disposal program needs a mechanism to check for active holds before executing disposal.

The privacy impact assessment process includes data inventory and retention mapping precisely because the disposal obligation is only operationalizable when you know what data you have and what retention schedule applies to it.

The Incident Response Plan Specificity Gap

The third violation—insufficient IR plan detail—reflects a pattern NYDFS has been flagging for years.

Generic IR plans look adequate until they’re actually used. They describe phases: Identification, Containment, Eradication, Recovery, Lessons Learned. They name a CISO as owner. They reference outside counsel. They satisfy a checkbox review.

What they don’t do—and what NYDFS’s enforcement record consistently finds missing—is answer the operational questions that arise in the first six hours of a real incident:

At what point is the organization “determining” a cybersecurity event under 23 NYCRR 500? Who makes that determination? What evidence standard applies? Is there a written decision framework that produces a documented record?

Where does the NYDFS notification go and what does it include? Who drafts it, who approves it, who submits it to the NYDFS online portal? What information must the notification contain? Does anyone on your incident response team have the NYDFS portal credentials tested and ready?

How does the plan handle a third-party-originated breach? The MOVEit scenario is now a template case: the breach originates in a vendor’s software, the vendor’s investigation produces the forensic evidence, and the financial institution is responsible for regulatory notification based on evidence it doesn’t control the timeline of. Your IR plan should specify how you handle that dependency.

What evidence is preserved at the moment of determination? Digital forensic evidence can be altered by the same remediation steps that stop the breach. The plan should sequence evidence preservation before remediation—and specify who makes that call.

The NYDFS Part 500 Class A requirements post covers the full examination-readiness landscape. The IR plan specificity standard—detailed enough to be operationally useful under real incident conditions, not just documentation for its own sake—is one of the examination gaps that shows up most consistently.

The Insurance Prohibition Signal

The non-reimbursement term in the Delta Dental consent order—prohibiting insurance reimbursement, indemnification, or tax deduction for the penalty—has become increasingly standard in NYDFS cybersecurity enforcement since 2024.

It’s worth understanding what this term is doing. If a regulatory penalty is fully recoverable through D&O insurance or cyber insurance, the regulated entity bears none of the economic consequence—the insurer does. That model doesn’t deter the conduct regulators are targeting. The non-reimbursement term ensures the fine is a direct cost to the institution: borne by the people making governance decisions about notification timing, data disposal investment, and IR plan quality.

For risk and compliance teams working with insurance brokers and carriers: the increasing prevalence of non-reimbursement terms in regulatory consent orders changes the calculus on regulatory penalty coverage. Policies priced on the assumption that NYDFS penalties are recoverable may be overstating their protective value for the specific risk category they’re ostensibly covering.

By October 2025, NYDFS had issued 27 consent orders totaling more than $144 million in cybersecurity fines under Part 500 since Superintendent Harris took office. The Delta Dental consent order is the opening of the 2026 enforcement cycle. First doesn’t mean only.

So What?

The Delta Dental enforcement action established something that every regulated financial institution with a New York license needs to internalize: the breach creates the regulatory attention, but the violations are in the response.

You can be hit by a widely-publicized zero-day in third-party software you didn’t write, exploited by a criminal ransomware group you didn’t invite. You can remediate the technical issue completely and experience no downstream data misuse. And you can still receive a multi-million dollar regulatory penalty because your notification was late, your data disposal policy was inadequate, and your incident response plan wasn’t specific enough to actually use.

The data disposal gap costs you twice: it expands the breach scope and creates a standalone violation. The notification gap is a pure timing failure—preventable with a documented determination process and tested notification procedures. The IR plan gap is an investment failure—the cost of specificity is measured in hours of plan development; the cost of insufficient specificity is measured in consent order terms.

The Data Privacy Compliance Kit includes a multi-clock notification matrix, data inventory and retention mapping templates, and an incident response checklist structured around the determination moment—the clock-start event that determines whether your notification is timely under NYDFS, SEC Reg S-P, and FTC Safeguards.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did NYDFS find in the Delta Dental cybersecurity consent order?
NYDFS issued a $2.25 million civil monetary penalty against Delta Dental of New York and Delta Dental Insurance Co. on April 29, 2026—its first 2026 cybersecurity enforcement action. The underlying incident was the 2023 MOVEit zero-day vulnerability. NYDFS cited three violations: (1) late notification—Delta Dental did not notify NYDFS until mid-December 2023, well beyond the 72-hour rule; (2) inadequate data disposal policies under 23 NYCRR 500.13; and (3) insufficient detail in the companies' incident response plans. Delta Dental did not admit or deny the findings.
When does the NYDFS 72-hour breach notification clock start?
Under 23 NYCRR Part 500, the 72-hour clock starts when the covered entity 'determines' that a cybersecurity event has occurred. NYDFS has interpreted 'determines' to mean having sufficient information to conclude a reportable event occurred—not completing the full forensic investigation or quantifying every affected customer. Waiting for investigation completion before notifying NYDFS is a compliance failure, as the Delta Dental case demonstrates.
Which institutions are covered by SEC Regulation S-P's 30-day customer notification requirement?
SEC Regulation S-P covers broker-dealers, registered investment advisers, funding portals, investment companies, and transfer agents registered with the SEC. The amended rule requires a written incident response program and, for customer notification, a 30-day clock from when the firm determines unauthorized access to sensitive customer information occurred. Smaller entities (RIAs below $1.5B AUM, funds below $1B AUM) had a compliance deadline of June 3, 2026. The SEC has named Reg S-P compliance a named 2026 examination priority.
What does the Delta Dental consent order say about insurance reimbursement for the penalty?
The consent order expressly prohibits Delta Dental from seeking insurance reimbursement, indemnification, or any federal or state tax deduction or tax credit for the $2.25 million civil monetary penalty. This is an increasingly standard NYDFS enforcement term—it ensures the financial deterrent is borne directly by the institution rather than passed through to a cyber insurance carrier. Organizations that have priced their cyber insurance on the assumption that regulatory penalties are recoverable should reassess that assumption.
What does 'adequate data disposal policy' mean under NYDFS Part 500?
Under 23 NYCRR Part 500.13, covered entities must maintain policies and procedures for the secure disposal of nonpublic information that is no longer necessary for business operations or other legitimate business purposes, except where retention is required by law or regulation. In the Delta Dental case, inadequate disposal policies meant more customer data was exposed in the breach than should have been available—data retained beyond its legitimate retention period became breach exposure that wouldn't exist if disposal had been operating correctly.
What parallel notification obligations might apply to a single breach at a financial institution?
Multiple notification clocks can run simultaneously on a single breach: NYDFS 23 NYCRR 500 (72 hours after determination, for NY-licensed entities); OCC/FDIC/Federal Reserve bank regulator notification (36 hours, for banks and service providers); SEC Regulation S-P (30-day customer notification, for broker-dealers, RIAs, funds, transfer agents); FTC Safeguards Rule (30-day FTC notification for non-bank financial institutions covering 500+ consumers); and SEC Item 1.05 8-K (4 business days, for material incidents at public companies). Each clock has a different trigger definition and reporting mechanism.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.