CrowdStrike and Supply Chain Risk Management—What Can we Learn From this Experience?

by Stephanie Goetz | Aug 2, 2024

Wow, how much technology has changed in the past 15 years? I remember when “vendor” reviews were uncommon, technology was hosted in-house in 95% of businesses, and arguments were made that a bad...

The Superpower of Consistency in Cybersecurity

by Tony Bushong | Jul 26, 2024

In the ever-evolving world of financial services, where cyber threats are a constant and compliance mandates tighten, the importance of a robust Information Security Program (ISP) cannot be...

Control Assessments Vs. Risk Assessments

by Brian Petzold | Jul 19, 2024

When we first start working with new institutions, it is not unusual for us to see them struggling because they have focused their efforts on remediating controls that were found to be missing...

Preparing for the Unexpected: Crafting an Effective Incident Response Program

by Errica Padgett | Jul 12, 2024

In the rapidly evolving and dynamic business landscape, it is crucial for financial institutions to have and maintain an effective Incident Response Program. No longer is the Incident Response Plan...

The Parallels of Little League Coaching and Managing Cybersecurity Risk in Financial Institutions

by Vance Monical | Jun 28, 2024

In the seemingly disparate worlds of coaching little league baseball and managing cybersecurity risk within financial institutions, striking similarities emerge. Both roles require strategic...

Don't Forget the Bank Service Company Act

by Trisha Durkin | Jun 21, 2024

Let’s discuss an old regulation that seems to be picking up new life in recent regulatory examinations, the Bank Service Company Act (BSCA). This Act is essential for ensuring that financial...

Handling Change in Your Organization

by Chris Bedel | Jun 14, 2024

“Change is the only constant.”–Greek philosopher Heraclitus I’ve been involved in lots of conversations about change in the past week. “This AI stuff is going to change everything.” “I’m...

Artificial Intelligence–How will it be regulated

by Stephanie Goetz | Jun 7, 2024

Institutions are looking at services using Artificial Intelligence (AI), such as loan decisioning, resume review, and process automation. Using these services can be risky not only because of the...

Enhancing Productivity in Information Security: Small Wins, Big Gains

by Tony Bushong | May 24, 2024

In a previous post, we explored the transition from a reactive to a proactive approach in managing an information security program. Building on that, let’s delve into how you can boost your...

Is Ransomware Dying?

by Brian Petzold | May 17, 2024

In December 2023 the US Justice Department announced that they had disrupted operations of ALPHV/Blackcat, a ransomware group that was responsible for many of the most prolific attacks in 2023....

Want these articles delivered weekly to your inbox? Subscribe to our Newsletter!

Recent Posts

Stay in the Loop!