Brian Petzold

Recent Posts

Helping Board Members Sleep at Night

by Brian Petzold | Jul 14, 2023

If you are a board member of a bank or credit union, how do you know that the cybersecurity program of the organization is being managed effectively? I often try to put myself into the shoes of a...

Reviewing the New Interagency Third-Party Risk Management Guidance

by Brian Petzold | Jun 9, 2023

On June 6th, the Federal Reserve, FDIC, and OCC released new interagency guidance on third-party risk management. The new guidance, based on existing OCC guidance from 2013 and 2020, calls for a...

Blocking Outbound Communications

by Brian Petzold | May 12, 2023

All organizations have (or should have) a firewall that blocks unexpected communications from the Internet to internal network hosts. But what about blocking unexpected communications from Internal...

The FDIC InTREX Gets Audited

by Brian Petzold | Feb 10, 2023

While the FFIEC has released three major guidance updates since July 2019, the FDIC has not updated its examination program to include the newer guidance. This is one of the findings of the January...

Discussions Triggered from the LastPass Breach

by Brian Petzold | Jan 6, 2023

Over the past month, many have written about the latest LastPass breach. If you have not kept up with the breach, you can see the disclosure from LastPass here. Since the breach was publicized,...

Regulators Becoming More Prescriptive

by Brian Petzold | Dec 9, 2022

Recently, the New York Department of Financial Services (“DFS”) released a proposed update to its 2017 “Cybersecurity Requirements for Financial Services Companies" law (also known as “23 NYCRR...

Self-Assessing Authentication & Access Risk

by Brian Petzold | Nov 4, 2022

A little over a year ago, banking regulators released the “Authentication and Access to Financial Institution Services and Systems” guidance. Since that time, Bedel Security has been taking the...

What Is A Strong Password in 2022?

by Brian Petzold | Sep 2, 2022

“How long should a password be?” “Should passwords even be used any longer?” These are questions that organizations have been grappling with as we enter the end of 2022. Each day, we are seeing...

Where Does Managing Aggregator Risk Belong?

by Brian Petzold | Aug 5, 2022

A little over a year ago, bank regulators published new proposed guidance on managing third-party risk. One of the more controversial topics in this guidance is whether a data aggregator needs to be...

Confessions of a Professional Worrier

by Brian Petzold | Jul 8, 2022

A few weeks ago, in my life outside of cybersecurity, a person said to me: “You are always thinking three steps ahead of the rest of us”. I am not sure if it was meant as a compliment or not. I...

Want these articles delivered weekly to your inbox? Subscribe to our Newsletter!

Recent Posts

Stay in the Loop!