While others were waiting for spring to arrive, community bank officers and directors were waiting for the Federal Financial Institutions Examination Council (FFIEC) to provide additional guidance on its cybersecurity assessment program. On March 17, 2015, FFIEC provided an overview of its cybersecurity priorities for the remainder of 2015. FFIEC’s priorities include seven workstreams based
Financial Information
Do Your Due Diligence – Security Concerns May Lurk in Unexpected Places
In 2014, Lenovo began selling its laptops bundled with a piece of software known as SuperFish, which enabled Lenovo to display more targeted advertising content to its users to “enhance [the] user experience” of its customers. While adware has become a commonly used tool in the marketing field, this particular program became a problem for…
White House Proposes Expansive Data Breach Notification Bill
Last week, President Obama proposed wide-reaching legislation to establish a uniform, nationwide standard for data breach notifications that envisions a significant enforcement role for the Consumer Financial Protection Bureau (CFPB). The proposal, titled the Personal Data Notification and Protection Act, can be found here. In terms of the types of covered data, the White…
Sharing is Caring: The OCC Testifies before the Senate Banking Committee
On December 10, 2014, Valerie Abend, Senior Critical Infrastructure Officer for the Office of the Comptroller of the Currency (OCC) testified before the U.S. Senate Committee on Banking, Housing, and Urban Affairs on the OCC’s cyber-risk framework and recent OCC and Federal Financial Institutions Examination Council (FFIEC) cybersecurity initiatives. The OCC’s testimony serves as a reminder to community banks and other financial institutions that information sharing should be a component of a bank’s risk governance framework and that improved information sharing activities with the Financial Services Information Sharing and Analysis Center (FS-ISAC) and other industry groups are among the most effective processes to identify, respond to, and mitigate cybersecurity threats and vulnerabilities.
Continue Reading Sharing is Caring: The OCC Testifies before the Senate Banking Committee
Treasury: Ten Questions for Bank Executives and Boards of Directors
On December 3, 2014, Sarah Raskin, Deputy Secretary of the U.S. Department of Treasury (Treasury), gave a speech before the Texas Banker’s Association Executive Leadership Cybersecurity Conference. Deputy Secretary Raskin’s remarks provide effective guidance for community bank chief executive officers, chief risk executives and boards of directors to consider when assessing their cybersecurity preparedness. According to Deputy Secretary Raskin, Treasury categorizes their thinking around cybersecurity and financial industry preparedness against cyber-attacks into three activities: (1) baseline protections, (2) information sharing and (3) response and recovery. When analyzing each activity, banks should enhance their cybersecurity risk assessment processes by asking the following questions:
Continue Reading Treasury: Ten Questions for Bank Executives and Boards of Directors
‘Tis The Season We Fear The Data Breach Thieves
During the holidays, consumers are pulling out debit and credit cards again, again and again. It is with a degree of blind faith those same consumers trust their personal data is going where intended and not into the hands of some nefarious character. But with recent well-publicized data breaches at major retailer stores, consumers have…
OCC Comptroller Curry Provides Game Plan for Cybersecurity at Community Banks
In light of the recent data privacy breaches at major retailers and that the burden of such breaches hit community banks particularly hard, Office of the Comptroller of the Currency (OCC) Comptroller Curry’s recent speech at the Community Bankers Symposium in Chicago should provide a game plan for community banks and other financial institutions implementing…
FFIEC Releases Cybersecurity Assessment Observations and Statement
On November 3, 2014, the Federal Financial Institutions Examination Council (FFIEC) released general observations (the FFIEC Observations) based on its 2014 cybersecurity examination work program assessment (the Cybersecurity Assessment) of more than 500 community banks. The Cybersecurity Assessment supplemented regularly scheduled bank examinations, built upon key supervisory expectations contained in existing FFIEC information technology handbooks…
SIFMA Sets Forth Principles for Effective Cybersecurity Regulatory Guidance
On October 20, 2014, the Securities Industry and Financial Markets Association (SIFMA) issued guidance intended to protect the financial sector’s data security and infrastructure. SIFMA noted that the SEC, CFTC and other regulatory agencies are conducting a review of their cybersecurity policies, regulations, and guidance with the goal of strengthening the financial sector’s defense and response to cyber attacks, and harmonizing regulations and guidance for greater effectiveness. To facilitate the effort between SIFMA’s members and the regulatory agencies, SIFMA proposed ten cybersecurity principles for effective cybersecurity:
Continue Reading SIFMA Sets Forth Principles for Effective Cybersecurity Regulatory Guidance
Obama Signs Order to Improve Security of Consumer Financial Transactions
On October 17, 2014, before an audience at the Consumer Financial Protection Bureau (“CFPB”), President Obama announced the launching of the Buy Secure initiative. This initiative is designed to provide consumers with more tools to secure their financial information in the wake of massive data breaches among national retailers by assisting victims of identity theft, improving the Government’s payment security as a customer and a provider, and accelerating the transition to stronger security technologies and the development of next-generation payment security tools.
As the first part of this initiative, the President signed an Executive Order – “Improving the Security of Consumer Financial Transactions” – that takes critical steps to protect consumer’s financial security and confidence in the marketplace.
Continue Reading Obama Signs Order to Improve Security of Consumer Financial Transactions