Wow, how much technology has changed in the past 15 years? I remember when “vendor” reviews were uncommon, technology was hosted in-house in 95% of businesses, and arguments were made that a bad...
CrowdStrike and Supply Chain Risk Management—What Can we Learn From this Experience?
by Stephanie Goetz | Aug 2, 2024
The Superpower of Consistency in Cybersecurity
by Tony Bushong | Jul 26, 2024
In the ever-evolving world of financial services, where cyber threats are a constant and compliance mandates tighten, the importance of a robust Information Security Program (ISP) cannot be...
Control Assessments Vs. Risk Assessments
by Brian Petzold | Jul 19, 2024
When we first start working with new institutions, it is not unusual for us to see them struggling because they have focused their efforts on remediating controls that were found to be missing...
Preparing for the Unexpected: Crafting an Effective Incident Response Program
by Errica Padgett | Jul 12, 2024
In the rapidly evolving and dynamic business landscape, it is crucial for financial institutions to have and maintain an effective Incident Response Program. No longer is the Incident Response Plan...
The Parallels of Little League Coaching and Managing Cybersecurity Risk in Financial Institutions
by Vance Monical | Jun 28, 2024
In the seemingly disparate worlds of coaching little league baseball and managing cybersecurity risk within financial institutions, striking similarities emerge. Both roles require strategic...
Don't Forget the Bank Service Company Act
by Trisha Durkin | Jun 21, 2024
Let’s discuss an old regulation that seems to be picking up new life in recent regulatory examinations, the Bank Service Company Act (BSCA). This Act is essential for ensuring that financial...
Handling Change in Your Organization
by Chris Bedel | Jun 14, 2024
“Change is the only constant.”–Greek philosopher Heraclitus I’ve been involved in lots of conversations about change in the past week. “This AI stuff is going to change everything.” “I’m...
Artificial Intelligence–How will it be regulated
by Stephanie Goetz | Jun 7, 2024
Institutions are looking at services using Artificial Intelligence (AI), such as loan decisioning, resume review, and process automation. Using these services can be risky not only because of the...
Enhancing Productivity in Information Security: Small Wins, Big Gains
by Tony Bushong | May 24, 2024
In a previous post, we explored the transition from a reactive to a proactive approach in managing an information security program. Building on that, let’s delve into how you can boost your...
Is Ransomware Dying?
by Brian Petzold | May 17, 2024
In December 2023 the US Justice Department announced that they had disrupted operations of ALPHV/Blackcat, a ransomware group that was responsible for many of the most prolific attacks in 2023....