A Risk Assessment on Paper Is Not Enough: NYDFS Sends Another $250,000 Warning

NYDFS cybersecurity risk assessment with compliance documents, security policies, patch management, and a warning that paperwork alone is not enough.

A Risk Assessment on Paper Is Not Enough: NYDFS Sends Another $250,000 Warning

Click here to view/listen to our blogcast.

For organizations regulated by the New York State Department of Financial Services, cybersecurity compliance cannot be reduced to a folder full of policies and a risk assessment completed once a year.

On August 5, 2026, NYDFS finalized a $250,000 settlement with Order Express, a money services business licensed in New York. The enforcement action followed a 2022 ransomware incident in which more than half of the company’s servers were encrypted. DFS later found deficiencies in the company’s cybersecurity risk assessment, cybersecurity program, written policies, and patch-management practices.

What makes this case especially important for smaller organizations is that Order Express qualified for a limited exemption from certain Part 500 requirements. DFS still found that the company failed to meet cybersecurity obligations that continued to apply.

A Risk Assessment Must Reflect the Real Environment

Order Express performed an annual risk assessment, but DFS found that it did not sufficiently consider company-specific cybersecurity threats or evaluate whether existing controls were adequate. That is an important distinction.

A risk assessment should not simply ask whether an organization has antivirus, backups, MFA, or a firewall. It should identify actual systems, nonpublic information, business processes, users, vendors, threats, and safeguards, then determine where meaningful gaps remain.

A useful assessment should answer questions such as:

  • What sensitive information does the organization store, and where?
  • Which employees, vendors, and third parties can access it?
  • What systems are essential to daily operations?
  • Are current controls appropriate for the threats the organization actually faces?
  • Have new systems, cloud services, vendors, or workflows changed the risk profile?

If the assessment does not reflect today’s environment, it cannot reliably guide the security program.

Patch Management Has to Cover More Than Windows

DFS also found that Order Express’s update policies covered only a small number of the third-party applications and software products it actually used. This is a common problem. Organizations may have a process for Windows updates while overlooking browsers, PDF software, accounting applications, firewalls, network devices, remote-access tools, firmware, and specialized industry software.

Effective patch management starts with knowing what technology exists. You cannot consistently patch software or equipment that nobody is tracking.

Limited Exemption Does Not Mean No Cybersecurity Requirements

Under today’s Part 500 rules, smaller covered entities may qualify for a limited exemption based on employee count, revenue, or assets. But limited is the important word.

Even exempt organizations can still have significant obligations, including a cybersecurity program, written policies, risk assessments, access controls, third-party service provider policies, MFA, asset inventory, data retention, cybersecurity awareness training, and required DFS notices.

Being smaller may reduce the number of requirements that apply. It does not turn Part 500 into a paperwork exercise.

A Practical Part 500 Reality Check

Smaller regulated organizations should be able to demonstrate that their cybersecurity documentation matches what is actually happening in their environment.

A practical review should include:

  • A current risk assessment based on actual systems, data, users, vendors, and threats.
  • An accurate inventory of computers, servers, network devices, software, and cloud services.
  • Written security policies that reflect the controls actually in use.
  • A patching process covering operating systems, third-party applications, network equipment, and firmware.
  • MFA and access controls that are implemented and periodically reviewed.
  • Documentation showing that required training, reviews, and compliance activities are actually being performed.

How CDML Can Help

For smaller NYDFS-regulated organizations, the challenge is translating regulatory requirements into practical controls, documentation, monitoring, and repeatable processes.

CDML Computer Services can help by:

  • Reviewing risk assessments and identifying gaps between documented controls and the actual IT environment.
  • Creating or updating asset inventories.
  • Evaluating patch management across endpoints, applications, firewalls, network devices, and firmware.
  • Reviewing MFA, permissions, administrative access, and identity controls.
  • Assessing cybersecurity policies, incident response procedures, disaster recovery plans, and business continuity documentation.
  • Providing security monitoring, endpoint protection, email security, employee cybersecurity training, vulnerability management, and compliance reporting.
  • Developing a remediation roadmap that prioritizes the most important security and compliance gaps.

A compliance program should not exist only in a binder or PDF. Policies, risk assessments, technical controls, and daily practices should support one another and accurately represent how the organization operates.


Final Thoughts

The Order Express settlement is another reminder that NYDFS is looking beyond whether cybersecurity documents exist. Regulators want to see whether risk assessments are meaningful, cybersecurity programs respond to those risks, and written policies match the organization’s actual technology and practices.

If your organization is regulated by NYDFS and you are not sure whether your cybersecurity documentation reflects your real environment, contact CDML Computer Services to schedule a compliance review.

Stay safe. Stay informed. Stay compliant.

Empowering business growth through innovation using secure, sustainable solutions.

📞 Contact us here: https://cdml.com/contact/
📚 Read more on our blog: https://cdml.com/blog-2
📺 Listen to our blogcasts: https://www.youtube.com/@CDMLComputerServices

Icon

Elevating Customer Experience.