NYDFS PENALIZES SMALLER, EXEMPT MONEY TRANSMITTER $250,000 FOR CYBERSECURITY LAPSES

NYDFS PENALIZES SMALLER, EXEMPT MONEY TRANSMITTER $250,000 FOR CYBERSECURITY LAPSES

·       Enforcement Takeaway: Even smaller entities partially-exempt from the Cybersecurity Regulation (Part 500) may be subject to enforcement.

According to the NYDFS Consent Order:

·       Order Express, Inc. is a regional money services business licensed by NYDFS to engage in money transmission in New York, with a focus on remittances to Mexico, Guatemala, El Salvador, Honduras and Colombia.

·       Order Express qualified for the limited exemption from certain provisions of the Cybersecurity Regulation (23 NYCRR § 500.19(a)(2)) because of its modest revenue.

·       In September 2022, Order Express experienced a ransomware attack, where just over half of its servers became encrypted by ransomware.  Order Express timely reported the Cybersecurity Event to NYDFS.

·       The Department’s subsequent investigation identified deficiencies in the company’s cybersecurity program, particularly around its risk assessment.

·       NYDFS found that although Order Express conducted an annual risk assessment addressing operational and information-technology risks, the assessment failed to consider cybersecurity risks and threats specific to the company and failed to assess the adequacy of the controls that the company already had in place.

·       NYDFS assessed a $250,000 civil monetary penalty. In setting the amount of the penalty, DFS expressly took into account the company’s cooperation, its size and revenue, and the fact that its revenue qualified it for exemptions from certain requirements of the Cybersecurity Regulation.