This website uses cookies

Read our Privacy policy and Terms of use for more information.

Today's Top Story

NYDFS fines a money transmitter $250,000 for weak patch and risk controls

New York's Department of Financial Services announced a $250,000 cybersecurity settlement with money transmitter Order Express, Inc. on 5 August, under its 23 NYCRR Part 500 rule (consent order dated 3 August). Investigators found the firm lacked adequate system-update policies and risk assessments — and penalised it even though its limited revenue qualifies it for a partial Part 500 exemption. The signal for every DFS-regulated bank, insurer, and licensee: limited-exemption status does not excuse missing patch-management and risk-assessment records, and penalties scale to revenue rather than disappearing.

On the Calendar This Week

Three hard gates land within 14 days — plus today's FedRAMP opening:

  • 10 Aug (today): FedRAMP's temporary Rev5 "Lost Sponsor" & "Ready Conversion" paths open (Class B/C, sponsorless).

  • 14 Aug, 12:00 pm ET: US CMMC Reform Task Force RFI closes.

  • 15 Aug: Netherlands' Cyberbeveiligingswet (NIS2) enters into force — no grace period.

  • 20 Aug: China's Network Data Security Risk Assessment Measures take effect.

Also Today

FedRAMP opens its only sponsorless Rev5 on-ramp — today. The temporary "Lost Sponsor" and "Ready Conversion" Program Certification pipelines let eligible Class B/C legacy cloud services certify without an agency sponsor, for providers that hit a qualifying milestone between January 2025 and March 2026. Both close 11 June 2027. Confirm eligibility and apply through the correct help-desk form — not the shared inbox. FedRAMP

Dutch NIS2 law is in force in 5 days. The Cyberbeveiligingswet applies in full from 15 August to 8,000+ organisations — NCSC-NL registration, duty of care, incident reporting, and board accountability — with fines up to €10M or 2% of turnover for essential entities. If you have a Dutch or pan-EU footprint, confirm scope and open registration now. Clyde & Co

China's data risk-assessment Measures take effect 20 August. CAC Order No. 24 (with MIIT and MPS) requires "important data" processors to run security risk assessments at least annually. Confirm whether your China processing is in scope. Hunton

Deadline Alert (≤14 days)

CMMC Reform RFI closes (14 Aug) · Dutch Cyberbeveiligingswet in force (15 Aug) · China data risk-assessment Measures effective (20 Aug). EU CRA Art. 14 reporting follows at 32 days (11 Sep).

One Thing to Do Today

Pull your patch-management and risk-assessment documentation and confirm it is current and evidenced — even under a limited exemption. NYDFS just priced that gap at $250,000.

Tomorrow's focus: Privacy — personal data protection developments and enforcement.