---
title: "Order Express Paid $250K Because Nobody Owned the Risk"
description: "If \"cyber risk\" is a myth, why did Order Express, Inc. just pay $250,000 to settle with the New York State Department of Financial Services (NYDFS) over cybersecurity violations On August 3, 2026, the..."
url: https://kaynemcgladrey.com/blog/order-express-paid-250k-because-nobody-owned-the-risk/
date: 2026-08-11
modified: 2026-08-11
author: "Kayne"
image: https://kaynemcgladrey.com/wp-content/uploads/2026/08/NYSDFS-Enforcement-Actions-August-3-2026-Consent-Order-Issues-to-Order-Express-Inc._1.webp
categories: ["Blog"]
type: post
lang: en
---

# Order Express Paid $250K Because Nobody Owned the Risk

If “cyber risk” is a myth, why did Order Express, Inc. just pay $250,000 to settle with the New York State Department of Financial Services (NYDFS) over cybersecurity violations

On August 3, 2026, the NYDFS issued a [Consent Order](https://www.dfs.ny.gov/system/files/documents/2026/08/ea20260803-order-express-inc.pdf) against Order Express, a Chicago-based money transmitter licensed to operate in New York. The company discovered a ransomware attack on September 7, 2022, that encrypted just over half its servers. NYDFS investigated and found three violations:

| Violation | Regulation | What Happened |
| --- | --- | --- |
| Inadequate risk assessment | 23 NYCRR § 500.9(a) | Assessment excluded cybersecurity threats |
| Flawed program design | 23 NYCRR § 500.2(b) | Program not based on adequate assessment |
| Incomplete patching policies | 23 NYCRR § 500.3(g) | Policies covered only a fraction of applications |

All three violations fall under Part 500, NYDFS’s cybersecurity rulebook for the financial firms it licenses. These are rules that make risk assessment and a program built on it mandatory, not optional.

Jorge Alberto Miranda, the Chief Operating Officer, signed the consent order. [NYDFS announced the settlement](https://www.dfs.ny.gov/reports_and_publications/press_releases/pr20260805) on August 5, 2026.

This case doesn’t prove cyber risk is real. It proves the opposite – that treating ‘cyber risk’ as its own category causes organizational confusion and increases business risks.

## The Myth in Practice

The myth isn’t that threats don’t exist. It’s that “cyber risk” belongs in a separate category from business risk, and Order Express demonstrates exactly what happens when organizations treat it that way.

The consent order reveals something subtle but damning. Order Express did conduct an annual risk assessment. Paragraph 13 states the assessment “considered operational and information technology risks” but “failed to consider cybersecurity risks and threats specific to the Company.” They didn’t skip the assessment; they scoped it incorrectly. Cybersecurity threats fell outside the frame of reference for whoever was running the process.

This is the separation described in Chapter 1 of [Cyber Risk is a Myth](https://www.routledge.com/Cyber-Risk-is-a-Myth-A-Business-Approach-to-Integrated-Risk-Management/McGladrey/p/book/9781041249054) (pre-order starts September 23rd), where the book traces how cybersecurity emerged as a specialized technical discipline with its own language, certifications, and professional identity. That specialization created valuable technical depth, but it also meant organizations without dedicated security expertise defaulted to what they understood. Operations risk made sense. IT infrastructure risk made sense. Cybersecurity risk sounded like work for specialists who didn’t exist at the company.

## The Capability Gap

And they didn’t exist. A search of LinkedIn and Apollo.io turns up no CISO at Order Express and no employees with “security” in their job title. Those sources aren’t exhaustive, but the absence is consistent with everything the consent order describes. The COO signed the consent order on the company’s behalf, but the organization had no one whose title or expertise made cybersecurity threats their job to assess alongside operational and financial risks.

Chapter 2 of the book discusses what it calls the “confidence problem”: when executives face technical decisions outside their domain expertise, uncertainty leads to decision paralysis or deferral. At Order Express, it’s worse. There was nobody confident enough to commission a proper assessment in the first place.

The patching failure maps to the same root cause. Paragraph 16 states that patching policies “covered only a small number of the third-party applications and software products Order Express uses.” The people writing those policies knew what they were responsible for, but they didn’t know what the business actually relied on.

Chapter 2’s translation framework argues that effective security communication connects vulnerabilities to revenue impact, cost implications, and strategic objectives. Without someone bridging that gap, the patching policy stayed narrow and incomplete. Systems the business depended on went unpatched, and the ransomware attackers in September 2022 found those gaps before anyone inside the company did.

## The Same Pattern, Different Scale

The Equifax case study in Chapter 1 shows the same pattern at massive scale. A patch existed. Someone ordered it. The communication broke down between technical teams and accountability owners. Order Express never reached that level of sophistication; they didn’t even have a complete inventory of what needed patching. But the failure mode is identical: technical tasks disconnected from business context produce blind spots that attackers exploit.

| What Order Express Lacked | What Happened as a Result |
| --- | --- |
| Dedicated security expertise | Risk assessment defaults to familiar territory |
| CISO or security staff | Nobody commissions cybersecurity-specific assessment |
| Business-technical translation | Patching policies reflect incomplete system knowledge |
| Executive security accountability | Enforcement lands at the C-suite with no owner beneath it |

## So Is Cyber Risk a Myth?

If cyber risk is a myth, why did Order Express settle? Because the threats were real, the consequences were real, and the $250,000 fine was real. But the category called “cyber risk” is what failed them. Had the company integrated cybersecurity into its existing annual risk assessment rather than treating it as a specialized domain, the violations probably wouldn’t have occurred. The assessment was already happening. It just didn’t include the right threats.

NYDFS didn’t fine Order Express because hackers were sophisticated. They fined them because the organizational structure left security unassessed and unprotected. The regulation requires a cybersecurity program “based on a risk assessment” designed to protect nonpublic information. The company had neither an adequate assessment nor an adequate program, because nobody understood that cybersecurity threats were business risks requiring assessment.

Order Express didn’t fall to a cyber attack. They fell to an integration failure. The ransomware was the symptom; the disease was a risk assessment that treated cybersecurity as someone else’s problem when nobody was actually that someone.

## What to Do About It

For organizations reading this, the takeaway isn’t abstract:

- **Audit who owns your cybersecurity risk assessment.** If the answer is “nobody” or “the IT person who also handles three other jobs,” you’re Order Express before September 2022.
- **Add cybersecurity threats to the assessment you’re already conducting.** The fix isn’t necessarily hiring a CISO tomorrow. It’s including the right threats in the process that already exists.
- **Translate technical risk into business language.** If your assessment can’t quantify the consequence in dollars, reputation, or downtime, it’s not complete.

The myth isn’t that threats don’t exist. It’s that labeling them “cyber” gives organizations permission to ignore them.
