Strong Cybersecurity is a Moving Target
As cybersecurity budgets increase, I’ve been posed with the question of “When will it ever be enough?” In my opinion, we are either getting better or...
Last week, we saw the Federal Financial Institutions Council (FFIEC) announce an update to its Cybersecurity Resource Guide. It was originally released in 2018 and intended to be a resource to institutions in order to continue to strengthen their cybersecurity resilience. This update is intended to provide resources for the most prevalent risk today- ransomware.
Many of our customers asked if there is a new requirement or any updates required to the program as a result of this publication. As far as we can tell the short answer is no. This is assuming that you have completed the CSBS Ransomware Self-Assessment released in late 2020. We have not yet seen a requirement for the R-SAT to be performed annually if you have tracked or closed any gaps noted.
There are, however, a few tools listed in the guide which I think are worth reviewing and could be helpful in refreshing your program. These include:
Below is a link to the updated guide, happy hunting!
https://www.ffiec.gov/press/pdf/FFIECCybersecurityResourceGuide2022ApprovedRev.pdf
As cybersecurity budgets increase, I’ve been posed with the question of “When will it ever be enough?” In my opinion, we are either getting better or...
It is a good practice to identify a cybersecurity framework as part of an institution’s Information Security Program. A framework helps to identify...
Ever get that feeling that you don’t know what you don’t know about the effectiveness of your cybersecurity program?