October is National Cybersecurity Awareness Month

Since October is National Cybersecurity Awareness Month, FinCEN and OFAC have published advisories aiming to increase cybersecurity awareness and aid institutions in responding and reporting incidents. The FinCEN Advisory – Advisory on Ransomware and the Use of the Financial System to Facilitate Ransom Payments The advisory provides information on: (1) the role of financial intermediaries in the processing of ransomware … Read More

Update to Cybersecurity Assessment Tool

The FFIEC released an update the the Cybersecurity Assessment Tool.  This update to the Assessment addresses changes to the FFIEC IT Examination Handbook by providing a revised mapping in Appendix A to the updated Information Security and Management booklets. The updated Assessment will also provide additional response options, allowing financial institution management to include supplementary or complementary behaviors, practices and … Read More

NASCUS Cybersecurity Symposium

On March 24, the DCU published bulletin B-17-09 regarding the NASCUS Cybersecurity Symposium June 5-6 in San Diego, CA.  The bulletin is reprinted below. NASCUS Cybersecurity Symposium, June 5-6, 2017 Make plans to attend the NASCUS Cybersecurity Symposium San Diego, CA Division of Credit Unions (DCU) encourages credit unions to continue training on cybersecurity. While there are many resources available … Read More

FIN-2016-A005 Cyber-Events and Cyber-Related Crime Reporting

On October 25, 2016, FinCEN released FIN-2016-A005, Advisory to Financial Institutions on Cyber-Events and Cyber-Enabled Crime. It serves as a refresher of the credit union’s SAR filing obligations when encountering cyber-events. A financial institution is required to report a suspicious transaction conducted or attempted by, at, or through the institution that involves or aggregates to $5,000 or more in funds … Read More

FFIEC Cybersecurity Assessment Tool FAQs

The FFIEC released a Frequently Asked Questions Guide related to the Cybersecurity Assessment Tool (CAT). The FFIEC published the Cybersecurity Assessment Tool in June of 2015 as a voluntary tool to help financial institutions’ management identify risk and determine their cybersecurity preparedness. The CAT provides a repeatable and measurable process that financial institutions may use to measure their cybersecurity preparedness … Read More

FFIEC Revised Information Security Booklet

The Federal Financial Institutions Examination Council (FFIEC) has revised the “Information Security” booklet of the FFIEC Information Technology Examination Handbook (IT Handbook). The “Information Security” booklet is one of 11 that make up the IT Handbook. The revised “Information Security” booklet provides guidance to examiners and addresses factors necessary to assess the level of security risks to a financial institution’s information systems. … Read More

FFIEC Issues Statement on Safeguarding the Cybersecurity of Interbank Messaging and Payment Networks

The Federal Financial Institutions Examination Council (FFIEC) members today advised financial institutions, consistent with existing regulatory expectations, to actively manage the risks associated with interbank messaging and wholesale payment networks. In a statement, the FFIEC also stressed that financial institutions should review risk-management practices and controls related to information technology systems and wholesale payment networks, including risk assessment; authentication, authorization … Read More

Cybersecurity Information Sharing Act of 2015

On December 18, 2015, Congress passed and President Obama signed into law the Cybersecurity Information Sharing Act of 2015, which is designed to increase cybersecurity information sharing between the private sector and the Federal Government. The Act provides various protections to non-federal entities that share cyber threat indicators or defensive measures with the Federal Government. DHS’s Automated Indicator Sharing (AIS) … Read More

Cybersecurity Resources

The FDIC’s Winter 2015 Supervisory Insights includes an article on framework for cybersecurity.  With cybersecurity being a focus for both the NCUA and the DFI in 2016 exams, along with the risks associated with cyber threats, the article is a good read for credit unions (even if it is published by the competition). The article describes the evolving cyber threat … Read More