New York State Department of Financial Services Acting Superintendent Kaitlin Asrow announced today that Order Express, Inc., a licensed money transmitter, will pay a $250,000 penalty for violations of DFS’s cybersecurity regulation (23 NYCRR Part 500). DFS investigators identified deficiencies in the company’s cybersecurity program and controls required under the regulation, including a failure to maintain adequate cybersecurity policies for system updates and inadequate risk assessments, leaving the company exposed to vulnerabilities that could be exploited by threat actors.
“New York’s cybersecurity regulation sets the standard nationally, requiring financial institutions to maintain strong safeguards for New Yorkers’ personal data,” said Acting Superintendent Asrow. “As bad actors grow more sophisticated, the Department remains committed to ensuring institutions are held accountable for protecting consumers.”
Order Express has remediated the deficiencies the Department’s investigation identified. Based on its limited revenue, Order Express is exempt from many of Part 500’s requirements.
The DFS cybersecurity regulation became effective in March 2017, with an updated amendment effective as of November 2023 designed to enhance cyber governance, mitigate risks, and strengthen protections for New York businesses and consumers against cyber threats. It has served as a model for other regulators, including the U.S. Federal Trade Commission, multiple states, the National Association of Insurance Commissioners, and the Conference of State Bank Supervisors Nonbank Model Data Security Law.
Read the Order Express consent order on the Department’s website.