NYDFS settles with money transmitter for $250K over alleged cybersecurity regulation violations
On August 5, NYDFS announced a $250,000 cybersecurity settlement with a licensed money transmitter for alleged violations of the state’s cybersecurity regulation, 23 NYCRR Part 500. NYDFS’s investigation, which the department noted commenced after the company experienced a September 2022 ransomware attack in which just over half of its servers were encrypted, found that the company: (i) failed to conduct a risk assessment sufficient to inform the design of its cybersecurity program in violation of § 500.9(a); (ii) failed to design a cybersecurity program based on an adequate risk assessment and sufficient to identify and assess risks to nonpublic information in violation of § 500.2(b); and (iii) failed to implement and maintain written cybersecurity policies addressing systems and network security, including policies for application and system updates and deployment of “patches,” in violation of § 500.3(g).
NYDFS noted that the company’s annual risk assessment considered operational and information technology risks but failed to consider cybersecurity risks and threats specific to the company or evaluate the adequacy of existing controls. NYDFS also noted that the company’s patching policies covered only a small number of the third-party applications and software products it used, leaving it exposed to known vulnerabilities. In assessing the penalty, NYDFS stated it considered the company’s cooperation with the investigation, its size and limited revenue, and that the company has remediated the identified deficiencies.