The New York State Department of Financial Services will collect a $250,000 civil penalty from Order Express, a Chicago-based money service business licensed to operate in New York, resolving charges that the company violated the state’s first-in-the-nation cybersecurity regulation, according to a consent order.
The enforcement action traces back to a September 2022 ransomware attack. According to the consent order, Order Express discovered server connectivity problems and shut down its network the same day. Two days later, the company found a text file on one of its servers claiming that data had been encrypted and exfiltrated. A subsequent investigation revealed that just over half of the company’s servers had been encrypted by ransomware.
Order Express reported the incident to the Department in a timely manner, but the investigation that followed uncovered three violations of the state’s cybersecurity regulation. First, the company’s annual risk assessment considered operational and information technology risks but failed to address cybersecurity risks and threats specific to the company, or to evaluate the adequacy of existing controls, a violation of Section 500.9(a). Second, because the risk assessment fell short, the company’s broader cybersecurity program was not designed to identify and assess risks to nonpublic information, violating Section 500.2(b). Third, the company’s patching and update policies covered only a small number of the third-party applications it used, leaving it exposed to known vulnerabilities in violation of Section 500.3(g).
Notably, Order Express qualified for a limited exemption from certain Part 500 requirements based on its revenue, and it continues to qualify under the regulation as amended in 2023. The case is a reminder that exempt status does not shield smaller licensees from enforcement over the core requirements that still apply, including risk assessments and written security policies.
The Department said it weighed the company’s cooperation and its size and revenue in setting the penalty, which must be paid within 10 days and cannot be offset by tax deductions or insurance reimbursement. The Department noted the company has remediated the identified deficiencies.
.




