1 min read

Should Banks Expect New Cybersecurity Guidance?

That is a question that I see continually asked in various articles and websites.  This article by Tracy Kitten at bankinfosecurity.com tries to answer just that.

Below are my summary and reaction, along with a link to the original article:

  • The article also goes on to imply that banks should be using the NIST Cybersecurity Framework in lieu of, or alongside the FFIEC CAT.
    • My recommendation is this:  in a world of limited resources, banks should focus on the FFIEC CAT.  It ties back to the NIST framework and the FFIEC IT Examination Handbook and was created specifically for banks.  If you are using it to assess your risk and are working toward an appropriate maturity level, you are going to be in pretty good shape.

Read the Entire Article on the Author's Website...

Choosing a Cybersecurity Framework

Choosing a Cybersecurity Framework

It is a good practice to identify a cybersecurity framework as part of an institution’s Information Security Program. A framework helps to identify...

Read More

FDIC Article Provides Insights on Where to Focus Your Efforts on Cybersecurity

It’s no secret that Governance, Threat Intelligence, Security Awareness Training, and Patch Management are all part of a solid cybersecurity program,...

Read More
The Waning Days of the CAT Arrive

The Waning Days of the CAT Arrive

In late August, the FFIEC announced that they would sunset the Cybersecurity Assessment Tool (the “CAT”) on August 31, 2025. It had been apparent for...

Read More