Skip to content
RiskTemplates · The Daily Brief Wednesday, September 2, 2026
Wire Lugano Diamonds SEC Fraud Case: How $1B in Alleged Fake Revenue Beat the Control Stack SEP 1

Feature Data Privacy

NYDFS Fined a Money Transmitter $250K for Its Risk Assessment, Not the Ransomware. What Even Limited-Exempt Entities Must Have.

On August 5, 2026, NYDFS fined Order Express $250,000 for failing to build a cybersecurity program on an adequate risk assessment — even though the company qualified for the limited exemption. Here's what the consent order means for every small covered entity under Part 500.

By Rebecca Leung · August 29, 2026 ·
Table of Contents

TL;DR

  • On August 5, 2026, NYDFS fined Order Express, Inc. — a licensed money transmitter — $250,000 for cybersecurity violations under 23 NYCRR Part 500
  • The violations: inadequate risk assessment, cybersecurity program not designed based on the risk assessment, and absent written cybersecurity policies
  • Order Express qualified for NYDFS’s “limited exemption” — but the exemption doesn’t cover risk assessments, written policies, or breach notification
  • The enforcement wasn’t about getting hit by ransomware. It was about what wasn’t built before the attack.

When Order Express’s servers started acting strangely in September 2022, the company eventually figured out what was happening: ransomware was encrypting half its infrastructure. They notified NYDFS.

What NYDFS found when they looked wasn’t primarily a response problem. It was a program problem that existed before the first byte was encrypted. The consent order — signed August 5, 2026, three and a half years after the attack — reflects that.

The fine is $250,000. The lesson is worth more than that.


Order Express, Inc. is a money transmitter licensed by the New York Department of Financial Services. As a covered entity under 23 NYCRR Part 500, it is subject to NYDFS’s cybersecurity regulation — though with reduced obligations because it meets the limited exemption criteria under Section 500.19(a).

NYDFS investigators found three distinct violations after the ransomware incident:

1. An inadequate risk assessment. Order Express had conducted a risk assessment, but NYDFS concluded it didn’t meet the regulatory standard. Specifically, the assessment failed to “consider cybersecurity risks and threats specific to the Company,” failed to “consider the adequacy of the controls the Company did have in place,” and as a result was not “sufficient to inform the design of its cybersecurity program.” The problem wasn’t that no assessment existed — it was that the assessment didn’t do what it was supposed to do.

2. A cybersecurity program not grounded in the risk assessment. Because the risk assessment was inadequate, the company’s cybersecurity program was not “designed based on the Company’s risk assessment” and was not “sufficient to identify and assess risks to NPI” (nonpublic personal information). In NYDFS’s view, these two violations are causally linked: a bad assessment produces a misaligned program.

3. Missing written cybersecurity policies. Order Express failed to “implement and maintain written cybersecurity policies addressing systems and network security.” Not inadequate policies — missing ones. For system updates specifically, the company lacked documented policies covering that area.

Three violations. One $250,000 penalty. No charge related to how the company responded to the ransomware.


What the Limited Exemption Actually Does (and Doesn’t) Cover

Here’s where the Order Express case has the broadest implications for the industry. Order Express qualified for the limited exemption under 23 NYCRR § 500.19(a)(2) — specifically, the revenue threshold: less than $7.5 million in gross annual revenue in each of the last three fiscal years from all business operations.

The limited exemption is real, and it meaningfully reduces what NYDFS requires. Exempt entities are not required to implement:

  • Penetration testing (§ 500.5)
  • Vulnerability scanning (§ 500.5)
  • Audit trail requirements (§ 500.6)
  • Application security requirements at the full standard (§ 500.8)
  • Security awareness training requirements beyond the baseline (§ 500.14(a)(1) and (a)(2))
  • Encryption in all circumstances (§ 500.15)
  • Incident response plans at the full standard (§ 500.16)

That’s a substantial reduction in regulatory burden for a small operator. But the exemption has a hard floor.

What limited-exempt entities must still maintain:

RequirementSectionRequired Even with Exemption?
Cybersecurity program§ 500.2Yes
Written cybersecurity policy§ 500.3Yes
Risk assessment§ 500.9Yes
Third-party service provider oversight§ 500.11Yes
Multi-factor authentication§ 500.12Yes
Access privilege limits§ 500.7Yes
72-hour incident notification§ 500.17Yes
Annual compliance certification§ 500.17Yes

Every violation in the Order Express consent order falls into the “must still maintain” column. The exemption is not a low-cost substitute for program fundamentals. It’s a reduction in the most technically demanding implementation requirements.


The Risk Assessment Standard: What “Sufficient to Inform the Design” Means

This phrase — “sufficient to inform the design of its cybersecurity program” — is the operative test in the Order Express enforcement and in 23 NYCRR § 500.9 generally. It’s worth unpacking precisely what NYDFS expects it to mean, because “we did a risk assessment” is not the same as meeting this standard.

A risk assessment that satisfies NYDFS’s requirements does three things:

1. It identifies threats specific to the organization. Generic threat categories (ransomware, phishing, insider threat) are a starting point, not a product. The assessment must connect threat vectors to the company’s specific technology environment, data types, transaction flows, customer base, and operational dependencies. A money transmitter moving funds internationally faces threat-actors differently than a bank with wire controls and clearing relationships. The assessment needs to reflect that.

2. It evaluates existing controls against those threats. Listing controls you have is not an assessment — it’s an inventory. The assessment must ask: are these controls adequate given the threats we’ve identified? Where are the gaps? Where are we over-controlled relative to risk? If the ransomware found its way in because a patch management process was missing from both the assessment and the program, that’s the definitional failure NYDFS cited.

3. It drives decisions about the program. The assessment must be a living input, not a checkbox. If the assessment identified a gap and the program wasn’t updated to address it, the assessment didn’t “inform the design” — it just informed a document. NYDFS will look at the causal chain from assessment finding to program change.

The 2022 ransomware attack is context, not the charge. What NYDFS found when they looked backward through the assessment record was a program not designed from genuine risk analysis. That’s the violation that generated the $250,000 penalty.


Why This Is Different from the Delta Dental Case

Earlier in 2026, NYDFS entered into a $2.25 million consent order with Delta Dental of New York for its response to the MOVEit file transfer vulnerability exploitation in 2023. The Delta Dental violations were squarely about response: late notification to NYDFS (the 72-hour clock was missed), inadequate data disposal that left old customer records exposed in the system the attacker accessed, and an insufficient incident response plan.

Order Express is different in kind. The violations predate the attack. There is no allegation that Order Express responded inadequately — the charge is that it never built an adequate program to begin with.

This distinction matters because it clarifies what NYDFS is testing:

  • Before the incident: Do you have an adequate risk assessment? Is your program designed based on it? Do you have written policies?
  • During and after the incident: Did you notify within 72 hours? Did you follow your IR plan? Is your data disposal process defensible?

Both tracks are independently enforceable. Getting one right doesn’t credit you on the other.


Who Needs to Be Reading This Right Now

NYDFS Part 500 applies to covered entities — any person operating under a license, registration, charter, certificate, permit, accreditation, or similar authorization under New York Banking Law, Insurance Law, or Financial Services Law. That’s a broad universe.

It includes money transmitters (like Order Express), licensed lenders, mortgage companies, foreign banks doing business in New York, insurance companies, and many fintech operators that hold a New York money transmission license.

The limited exemption ($7.5M revenue, 20 employees, or $15M assets) applies to many small fintechs and specialty lenders. If your leadership team has concluded that the limited exemption means NYDFS cybersecurity is “essentially handled,” this case should prompt a closer look.

Three questions to answer before your next board compliance update:

  1. Does your risk assessment meet the “sufficient to inform design” standard? Can you trace specific controls in your cybersecurity program back to specific findings in your last risk assessment?

  2. Are your written cybersecurity policies complete and current? Do they cover systems and network security at the level of specificity NYDFS expects — not just a general information security policy, but documented standards for the areas the Order Express consent order flagged?

  3. Have you documented your limited exemption eligibility? If you’re relying on the exemption, you should have documented analysis of which threshold you meet, which requirements you’re exempt from, and which you must still satisfy — updated for your current revenue and headcount.

NYDFS Part 500 compliance is not optional because you’re small. It’s scaled because you’re small.


So What?

The Order Express enforcement action does something useful for the compliance community: it makes explicit what NYDFS will find when it examines a cybersecurity incident at a small covered entity.

The agency will look at what existed before the incident. If the risk assessment was inadequate — if it wasn’t specific, wasn’t linked to controls, and didn’t drive program design — that’s a violation independent of whatever happened to your systems.

For any covered entity operating with the limited exemption, the compliance calculus is clear: the core requirements are non-negotiable. Risk assessment. Written policy. Third-party oversight. Breach notification. These aren’t the expensive parts of Part 500 compliance — they’re the floor.

Get the floor right before the incident. NYDFS will be looking at it afterward either way.


The Data Privacy Compliance Kit includes a data inventory template, NYDFS Part 500 alignment checklist, breach notification timeline tracker, and written policy templates pre-built for financial services teams managing PII and nonpublic information under state and federal requirements.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did NYDFS find wrong with Order Express's cybersecurity program?
NYDFS identified three specific violations: (1) Order Express failed to conduct a risk assessment sufficient to inform the design of its cybersecurity program — the assessment didn't consider cybersecurity risks and threats specific to the company or evaluate the adequacy of existing controls; (2) as a result, its cybersecurity program was not designed based on a risk assessment and wasn't sufficient to identify and assess risks to nonpublic information; and (3) the company failed to implement and maintain written cybersecurity policies addressing systems and network security. The $250,000 penalty reflects all three violations together.
What is the NYDFS Part 500 limited exemption, and who qualifies?
Section 500.19(a) of 23 NYCRR 500 provides a limited exemption to covered entities that meet any one of three thresholds: fewer than 20 employees and independent contractors (across the entity and affiliates), less than $7.5 million in gross annual revenue from all business operations in each of the last three fiscal years, or less than $15 million in year-end total assets. Order Express qualified under the revenue threshold. Critically, the limited exemption reduces the regulatory burden — it exempts covered entities from penetration testing, vulnerability scanning, audit trail requirements, and certain training and monitoring requirements — but it does not exempt them from the core obligations: risk assessment, written cybersecurity policy, third-party service provider security, and 72-hour incident notification.
If a company has a limited exemption, what cybersecurity requirements still apply?
Even with the limited exemption under 500.19(a), covered entities must still: maintain a cybersecurity program (§ 500.2); maintain a written cybersecurity policy (§ 500.3); conduct periodic risk assessments (§ 500.9); oversee third-party service providers (§ 500.11); implement multi-factor authentication for remote access and privileged accounts (§ 500.12); limit access privileges (§ 500.7); notify NYDFS of cybersecurity incidents within 72 hours (§ 500.17); and certify compliance annually. Order Express was charged for failing to meet three of these non-exempt requirements.
What does 'sufficient to inform the design of its cybersecurity program' actually mean?
NYDFS's standard requires that the risk assessment do three things: consider the cybersecurity risks and threats specific to the organization (not just generic categories); evaluate the adequacy of existing controls against those threats; and produce outputs that actually drive decisions about what the cybersecurity program needs to include. An assessment that audits a template checklist without connecting findings to control gaps, or that is conducted once and never used to adjust the program, doesn't meet this standard. The test is whether the assessment genuinely informs what you build — not just whether the assessment exists.
How does the Order Express case differ from the NYDFS Delta Dental enforcement action earlier in 2026?
The Delta Dental case (April 2026, $2.25M penalty) focused on response failures: late breach notification, inadequate data disposal, and insufficient incident response planning after a third-party vendor's MOVEit breach. Order Express's violations are entirely pre-breach: the company's risk assessment program and written policies were inadequate before the ransomware hit. The lesson from Delta Dental was that how you respond is independently enforceable. The lesson from Order Express is that what you build before an incident is also independently enforceable — and regulators will examine both tracks.
What should a small fintech or money transmitter do after the Order Express case?
Three immediate actions: First, confirm whether you are a covered entity under NYDFS Part 500 — money transmitters licensed by NYDFS are covered entities, and the exemption thresholds are lower than many operators assume. Second, if you qualify for the limited exemption, document which requirements you are exempt from and which still apply to you — and ensure your risk assessment, written policy, and incident notification procedures are current and compliant. Third, stress-test your risk assessment against NYDFS's standard: does it identify threats specific to your operations? Does it evaluate the adequacy of your current controls? Does it drive updates to your cybersecurity program? If the honest answer to any of these is no, it needs to be rebuilt, not supplemented.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.