Feature Data Privacy
NYDFS Fined a Money Transmitter $250K for Its Risk Assessment, Not the Ransomware. What Even Limited-Exempt Entities Must Have.
On August 5, 2026, NYDFS fined Order Express $250,000 for failing to build a cybersecurity program on an adequate risk assessment — even though the company qualified for the limited exemption. Here's what the consent order means for every small covered entity under Part 500.
Table of Contents
TL;DR
- On August 5, 2026, NYDFS fined Order Express, Inc. — a licensed money transmitter — $250,000 for cybersecurity violations under 23 NYCRR Part 500
- The violations: inadequate risk assessment, cybersecurity program not designed based on the risk assessment, and absent written cybersecurity policies
- Order Express qualified for NYDFS’s “limited exemption” — but the exemption doesn’t cover risk assessments, written policies, or breach notification
- The enforcement wasn’t about getting hit by ransomware. It was about what wasn’t built before the attack.
When Order Express’s servers started acting strangely in September 2022, the company eventually figured out what was happening: ransomware was encrypting half its infrastructure. They notified NYDFS.
What NYDFS found when they looked wasn’t primarily a response problem. It was a program problem that existed before the first byte was encrypted. The consent order — signed August 5, 2026, three and a half years after the attack — reflects that.
The fine is $250,000. The lesson is worth more than that.
The Consent Order: What NYDFS Actually Charged
Order Express, Inc. is a money transmitter licensed by the New York Department of Financial Services. As a covered entity under 23 NYCRR Part 500, it is subject to NYDFS’s cybersecurity regulation — though with reduced obligations because it meets the limited exemption criteria under Section 500.19(a).
NYDFS investigators found three distinct violations after the ransomware incident:
1. An inadequate risk assessment. Order Express had conducted a risk assessment, but NYDFS concluded it didn’t meet the regulatory standard. Specifically, the assessment failed to “consider cybersecurity risks and threats specific to the Company,” failed to “consider the adequacy of the controls the Company did have in place,” and as a result was not “sufficient to inform the design of its cybersecurity program.” The problem wasn’t that no assessment existed — it was that the assessment didn’t do what it was supposed to do.
2. A cybersecurity program not grounded in the risk assessment. Because the risk assessment was inadequate, the company’s cybersecurity program was not “designed based on the Company’s risk assessment” and was not “sufficient to identify and assess risks to NPI” (nonpublic personal information). In NYDFS’s view, these two violations are causally linked: a bad assessment produces a misaligned program.
3. Missing written cybersecurity policies. Order Express failed to “implement and maintain written cybersecurity policies addressing systems and network security.” Not inadequate policies — missing ones. For system updates specifically, the company lacked documented policies covering that area.
Three violations. One $250,000 penalty. No charge related to how the company responded to the ransomware.
What the Limited Exemption Actually Does (and Doesn’t) Cover
Here’s where the Order Express case has the broadest implications for the industry. Order Express qualified for the limited exemption under 23 NYCRR § 500.19(a)(2) — specifically, the revenue threshold: less than $7.5 million in gross annual revenue in each of the last three fiscal years from all business operations.
The limited exemption is real, and it meaningfully reduces what NYDFS requires. Exempt entities are not required to implement:
- Penetration testing (§ 500.5)
- Vulnerability scanning (§ 500.5)
- Audit trail requirements (§ 500.6)
- Application security requirements at the full standard (§ 500.8)
- Security awareness training requirements beyond the baseline (§ 500.14(a)(1) and (a)(2))
- Encryption in all circumstances (§ 500.15)
- Incident response plans at the full standard (§ 500.16)
That’s a substantial reduction in regulatory burden for a small operator. But the exemption has a hard floor.
What limited-exempt entities must still maintain:
| Requirement | Section | Required Even with Exemption? |
|---|---|---|
| Cybersecurity program | § 500.2 | Yes |
| Written cybersecurity policy | § 500.3 | Yes |
| Risk assessment | § 500.9 | Yes |
| Third-party service provider oversight | § 500.11 | Yes |
| Multi-factor authentication | § 500.12 | Yes |
| Access privilege limits | § 500.7 | Yes |
| 72-hour incident notification | § 500.17 | Yes |
| Annual compliance certification | § 500.17 | Yes |
Every violation in the Order Express consent order falls into the “must still maintain” column. The exemption is not a low-cost substitute for program fundamentals. It’s a reduction in the most technically demanding implementation requirements.
The Risk Assessment Standard: What “Sufficient to Inform the Design” Means
This phrase — “sufficient to inform the design of its cybersecurity program” — is the operative test in the Order Express enforcement and in 23 NYCRR § 500.9 generally. It’s worth unpacking precisely what NYDFS expects it to mean, because “we did a risk assessment” is not the same as meeting this standard.
A risk assessment that satisfies NYDFS’s requirements does three things:
1. It identifies threats specific to the organization. Generic threat categories (ransomware, phishing, insider threat) are a starting point, not a product. The assessment must connect threat vectors to the company’s specific technology environment, data types, transaction flows, customer base, and operational dependencies. A money transmitter moving funds internationally faces threat-actors differently than a bank with wire controls and clearing relationships. The assessment needs to reflect that.
2. It evaluates existing controls against those threats. Listing controls you have is not an assessment — it’s an inventory. The assessment must ask: are these controls adequate given the threats we’ve identified? Where are the gaps? Where are we over-controlled relative to risk? If the ransomware found its way in because a patch management process was missing from both the assessment and the program, that’s the definitional failure NYDFS cited.
3. It drives decisions about the program. The assessment must be a living input, not a checkbox. If the assessment identified a gap and the program wasn’t updated to address it, the assessment didn’t “inform the design” — it just informed a document. NYDFS will look at the causal chain from assessment finding to program change.
The 2022 ransomware attack is context, not the charge. What NYDFS found when they looked backward through the assessment record was a program not designed from genuine risk analysis. That’s the violation that generated the $250,000 penalty.
Why This Is Different from the Delta Dental Case
Earlier in 2026, NYDFS entered into a $2.25 million consent order with Delta Dental of New York for its response to the MOVEit file transfer vulnerability exploitation in 2023. The Delta Dental violations were squarely about response: late notification to NYDFS (the 72-hour clock was missed), inadequate data disposal that left old customer records exposed in the system the attacker accessed, and an insufficient incident response plan.
Order Express is different in kind. The violations predate the attack. There is no allegation that Order Express responded inadequately — the charge is that it never built an adequate program to begin with.
This distinction matters because it clarifies what NYDFS is testing:
- Before the incident: Do you have an adequate risk assessment? Is your program designed based on it? Do you have written policies?
- During and after the incident: Did you notify within 72 hours? Did you follow your IR plan? Is your data disposal process defensible?
Both tracks are independently enforceable. Getting one right doesn’t credit you on the other.
Who Needs to Be Reading This Right Now
NYDFS Part 500 applies to covered entities — any person operating under a license, registration, charter, certificate, permit, accreditation, or similar authorization under New York Banking Law, Insurance Law, or Financial Services Law. That’s a broad universe.
It includes money transmitters (like Order Express), licensed lenders, mortgage companies, foreign banks doing business in New York, insurance companies, and many fintech operators that hold a New York money transmission license.
The limited exemption ($7.5M revenue, 20 employees, or $15M assets) applies to many small fintechs and specialty lenders. If your leadership team has concluded that the limited exemption means NYDFS cybersecurity is “essentially handled,” this case should prompt a closer look.
Three questions to answer before your next board compliance update:
-
Does your risk assessment meet the “sufficient to inform design” standard? Can you trace specific controls in your cybersecurity program back to specific findings in your last risk assessment?
-
Are your written cybersecurity policies complete and current? Do they cover systems and network security at the level of specificity NYDFS expects — not just a general information security policy, but documented standards for the areas the Order Express consent order flagged?
-
Have you documented your limited exemption eligibility? If you’re relying on the exemption, you should have documented analysis of which threshold you meet, which requirements you’re exempt from, and which you must still satisfy — updated for your current revenue and headcount.
NYDFS Part 500 compliance is not optional because you’re small. It’s scaled because you’re small.
So What?
The Order Express enforcement action does something useful for the compliance community: it makes explicit what NYDFS will find when it examines a cybersecurity incident at a small covered entity.
The agency will look at what existed before the incident. If the risk assessment was inadequate — if it wasn’t specific, wasn’t linked to controls, and didn’t drive program design — that’s a violation independent of whatever happened to your systems.
For any covered entity operating with the limited exemption, the compliance calculus is clear: the core requirements are non-negotiable. Risk assessment. Written policy. Third-party oversight. Breach notification. These aren’t the expensive parts of Part 500 compliance — they’re the floor.
Get the floor right before the incident. NYDFS will be looking at it afterward either way.
The Data Privacy Compliance Kit includes a data inventory template, NYDFS Part 500 alignment checklist, breach notification timeline tracker, and written policy templates pre-built for financial services teams managing PII and nonpublic information under state and federal requirements.
Sources:
- NYDFS Press Release — Order Express Cybersecurity Settlement (August 5, 2026)
- NYDFS Consent Order — Order Express, Inc. (August 3, 2026)
- NYDFS Levies $250,000 Fine on Licensee for Inadequate Cyber Risk Assessment — Data Protection Report
- NYDFS Secures $250,000 Cybersecurity Settlement with Money Transmitter — Mondaq
- 23 NYCRR Part 500 — New York Department of Financial Services Cybersecurity Regulation
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did NYDFS find wrong with Order Express's cybersecurity program?
What is the NYDFS Part 500 limited exemption, and who qualifies?
If a company has a limited exemption, what cybersecurity requirements still apply?
What does 'sufficient to inform the design of its cybersecurity program' actually mean?
How does the Order Express case differ from the NYDFS Delta Dental enforcement action earlier in 2026?
What should a small fintech or money transmitter do after the Order Express case?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
SEC Regulation S-P's June 2026 Deadline Has Passed: What Smaller Investment Advisers Still Need to Fix in Their Incident Response Programs
The SEC's Reg S-P amendments required smaller investment advisers and broker-dealers to have written incident response programs and 30-day customer notification procedures by June 3, 2026. Here's what the rule actually requires and where examination is already finding gaps.
Aug 22, 2026
Data Privacy
Global Privacy Control for Financial Services: A State-by-State Scope Test
A practical Global Privacy Control guide for financial services: state scope, GLBA exemptions, signal handling, testing, and evidence.
Aug 17, 2026
Data Privacy
California Just Fined a Data Broker $116K for Making Opt-Out Too Hard. Your Fintech's Data Practices Are Next.
CalPrivacy ordered LocateSmarter to pay $116,490 over registration and opt-out violations, then fined Cybba $52,400 two days later.
Aug 14, 2026