On August 5, 2026, the New York Department of Financial Services (NYDFS) entered into a consent order with Order Express, Inc., a money transmitter licensed by NYDFS. Although Order Express qualified for a limited exemption under the NYDFS cybersecurity regulation, NYDFS found that the company violated the regulation’s applicable requirements in three ways: (1) failure to “conduct a risk assessment sufficient to inform the design of its cybersecurity program”; (2) as a result of the risk assessment’s deficiencies, failure “to design a cybersecurity program based on the Company’s risk assessment and sufficient to identify and assess risks to NPI”; and (3) failure “to implement and maintain written cybersecurity policies addressing systems and network security.” Order Express agreed to pay $250,000.
Although this consent order pertains to a limited exemption licensee, it remains relevant to larger covered entities not exempted from the full scope of the cybersecurity regulation; the Department’s expectations for an adequate risk assessment and cybersecurity program for limited exemption licensees likely serve as a bare minimum baseline for larger organizations.
Background
This matter began in September 2022, when Order Express noticed server connectivity issues that ultimately proved to be ransomware encrypting half of its servers. Order Express notified NYDFS. The consent order notes that Order Express is partially exempt from the cybersecurity regulation’s requirements under 23 NYCRR § 500.19(a)(2) (including as revised in 2023): Order Express has “less than $7,500,000 in gross annual revenue in each of the last three fiscal years from all business operations of the covered entity and the business operations in this State of the covered entity’s affiliates.”
The partial exemption relieves Order Express of many of the cybersecurity regulation’s requirements, but companies that qualify for the limited exemption must still comply with their obligations relating to risk assessments, third-party service provider security policies, asset management and data retention, and notices to the Superintendent of NYDFS. NYDFS designed the limited exemption to relieve small, low-revenue entities of Part 500’s full administrative burden—not to excuse them from the foundational discipline of knowing their own risks and reporting promptly when something goes wrong. That last requirement is why Order Express provided notice of its security incident.
After receiving the notice, NYDFS began an investigation.
Consent Order
According to the consent order, Order Express prepared a risk assessment, but NYDFS found that it did not “conduct a risk assessment sufficient to inform the design of its cybersecurity program.” Specifically, NYDFS found that the risk assessment did not “consider cybersecurity risks and threats specific to the Company.” In addition, “the risk assessment did not consider the adequacy of the controls the Company did have in place.”
Second, because the risk assessment did not meet the requirements of the cybersecurity regulation, the consent order found that “the Company’s cybersecurity program was not based on an adequate risk assessment and not designed to identify and assess risks to” nonpublic personal information (NPI).
Third, with respect to third-party service providers, NYDFS found that Order Express’s “policies and procedures relating to application and system updates, including deployment of patches, covered only a small number of the third-party applications and software products Order Express uses.” The consent order states that this gap “left the Company exposed to known vulnerabilities that could be exploited by threat actors.”
Our Take
There are several practical lessons in this consent order that go beyond the usual compliance checklist:
- A generic risk assessment is unlikely to meet the cybersecurity regulation’s requirements—it needs to be specific to the company. The regulation requires the assessment to reflect the company’s own systems, its own third-party relationships, and its own NPI footprint, not a generic industry profile.
- If the risk assessment does not meet the regulation’s standards, the company’s cybersecurity program is unlikely to meet the regulatory requirements either. NYDFS treats that as a separate violation, and companies should expect that treatment to continue. A flawed foundation predictably produces a flawed structure, and NYDFS consistently charges both failures because each independently exposes consumers’ nonpublic information to risk.
- As AI increasingly surfaces vulnerabilities in IT systems, having (and actually following) policies and procedures to address those vulnerabilities is an important element of compliance. Third-party patch management, in particular, has been a recurring focus area in examinations; a policy that covers only a handful of vendors, as Order Express’s did, will not withstand scrutiny once an incident forces a closer look.
- Discovery of the incident itself is instructive. Order Express first noticed server connectivity issues before realizing the underlying cause was ransomware- a pattern common among smaller, resource-constrained companies that lack mature continuous-monitoring or intrusion-detection capabilities. Covered companies should consider whether to treat unexplained operational anomalies as a potential cybersecurity event until ruled out, rather than as a routine IT issue, so that the 72-hour notice clock under 23 NYCRR § 500.17(a) is not inadvertently missed while the cause is being diagnosed.
Note that the $250,000 payment represents approximately 3.3% of Order Express’s global revenue, and likely a higher percentage still, since the exemption threshold is annual revenue of less than $7,500,000 and the Company’s actual revenue is not disclosed. A $250,000 penalty may look modest next to the multi-million-dollar consent orders NYDFS has entered against larger insurers and banks, but relative to Order Express’s size, it is a serious sanction and a clear signal that limited-exemption status is not a safe harbor from real accountability.
Recent Comments