Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

NYDFS Secures $250,000 Cybersecurity Settlement with Money Transmitter

Дата публикации: 01-01-1970 00:00:00

On August 5, the NYDFS announced a $250,000 settlement with a licensed money transmitter over alleged violations of New York’s Cybersecurity Regulation, 23 NYCRR Part 500. NYDFS alleged that the money transmitter maintained inadequate cybersecurity risk assessments and policies governing system and software updates, deficiencies identified after a September 2022 ransomware event.
According to the consent order, the company discovered server-connectivity issues on September 7, 2022, shut down its network, and later determined that ransomware had encrypted just over half of its servers. The company timely reported the incident to NYDFS, which subsequently investigated its cybersecurity controls. Specifically, NYDFS alleged that the company:
Failed to conduct an adequate risk assessment. The company’s annual assessment addressed operational and information technology risks but allegedly did not sufficiently consider company-specific cybersecurity risks or evaluate the effectiveness of existing controls, in violation of Section 500.9(a).
Maintained an inadequate cybersecurity program. Because the company’s program was not based on an adequate risk assessment, NYDFS alleged that it was not sufficiently designed to identify and assess risks to nonpublic information, in violation of Section 500.2(b).
Maintained insufficient cybersecurity policies. The company’s policies governing application and system updates allegedly covered only a limited number of the third-party applications and software products it used, leaving other software exposed to known vulnerabilities and allegedly violating Section 500.3(g).
The company agreed to pay a $250,000 civil monetary penalty and has remediated the deficiencies identified by NYDFS. In assessing the penalty, NYDFS considered the company’s cooperation, size and revenue, and limited exemption from certain Part 500 requirements.
Putting It Into Practice: The settlement reflects NYDFS’s continued focus on cybersecurity governance and the adequacy of controls maintained by regulated financial institutions. The Department has increasingly emphasized risk assessments, patch management, and policies that are tailored to an institution’s actual systems and operations. Financial institutions subject to New York’s cybersecurity requirements should review their risk assessments and cybersecurity policies to ensure they address institution-specific threats, software vulnerabilities, and the effectiveness of existing controls.


Основное содержимое страницы с новостью.

NYDFS Secures $250,000 Cybersecurity Settlement with Money Transmitter

Thursday, August 13, 2026

On August 5, the NYDFS announced a $250,000 settlement with a licensed money transmitter over alleged violations of New York’s Cybersecurity Regulation, 23 NYCRR Part 500. NYDFS alleged that the money transmitter maintained inadequate cybersecurity risk assessments and policies governing system and software updates, deficiencies identified after a September 2022 ransomware event.

According to the consent order, the company discovered server-connectivity issues on September 7, 2022, shut down its network, and later determined that ransomware had encrypted just over half of its servers. The company timely reported the incident to NYDFS, which subsequently investigated its cybersecurity controls. Specifically, NYDFS alleged that the company:

  • Failed to conduct an adequate risk assessment. The company’s annual assessment addressed operational and information technology risks but allegedly did not sufficiently consider company-specific cybersecurity risks or evaluate the effectiveness of existing controls, in violation of Section 500.9(a).
  • Maintained an inadequate cybersecurity program. Because the company’s program was not based on an adequate risk assessment, NYDFS alleged that it was not sufficiently designed to identify and assess risks to nonpublic information, in violation of Section 500.2(b).
  • Maintained insufficient cybersecurity policies. The company’s policies governing application and system updates allegedly covered only a limited number of the third-party applications and software products it used, leaving other software exposed to known vulnerabilities and allegedly violating Section 500.3(g).

The company agreed to pay a $250,000 civil monetary penalty and has remediated the deficiencies identified by NYDFS. In assessing the penalty, NYDFS considered the company’s cooperation, size and revenue, and limited exemption from certain Part 500 requirements.

Putting It Into Practice: The settlement reflects NYDFS’s continued focus on cybersecurity governance and the adequacy of controls maintained by regulated financial institutions. The Department has increasingly emphasized risk assessments, patch management, and policies that are tailored to an institution’s actual systems and operations. Financial institutions subject to New York’s cybersecurity requirements should review their risk assessments and cybersecurity policies to ensure they address institution-specific threats, software vulnerabilities, and the effectiveness of existing controls.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1CFTC Exercises Emergency Authority Amid New York Prediction Market Dispute010.501-01-1970
2US Broker-Dealer Receives Heaviest-Ever Penalty as Regulators Fine UBS $125 Million for Anti-Money Laundering Shortfalls033.304-08-2026
3Who Owns the Compliance Failure? Bank-Fintech Liability Allocation in Banking-as-a-Service (BaaS) Programs08.5901-01-1970
4Pennsylvania Healthcare Provider Agrees to $3,000,000 Settlement Over Data Breach That Impacted 624,496 People031.524-07-2026
5FBI and US Banks Freeze $679 Million in Scam Transfers in 2025 After Rapid Victim Alerts032.8527-07-2026
6DOJ sues NY over CDPAP-2717-06-2026
7Why cyber risk quantification is essential for financial services09.1510-08-2026
8Keystone Pipeline system's operator agrees to pay a $26.9M penalty over a major Kansas oil spill0712-07-2026
9Philadelphia Casino Data Breach: Some Claims Win, Others Lose010.4201-01-1970
10Ransomware in 2026: More groups, more victims, no slowdown012.1424-07-2026

Классификация: Экономика. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 14.27. Источник: www.natlawreview.com.