NYDFS levies $250,000 fine on licensee for inadequate cyber risk assessment
On August 5, 2026, the New York Department of Financial Services (NYDFS) entered into a consent order with Order Express, Inc., a money transmitter licensed by NYDFS. Although Order Express qualified for a limited exemption under the NYDFS cybersecurity regulation , NYDFS found that the company violated the regulation’s applicable requirements in three ways: (1) failure to “conduct a risk assessment sufficient to inform the design of its cybersecurity program”; (2) as a result of the risk assessment’s deficiencies, failure “to design a cybersecurity program based on the Company’s risk assessment and sufficient to identify and assess risks to NPI”; and (3) failure “to implement and maintain written cybersecurity policies addressing systems and network security.” Order Express agreed to pay $250,000. Although this consent order pertains to a limited exemption licensee, it remains relevant to larger covered entities not exempted from t