ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Cybersecurity

The Treasury Department’s Cybersecurity Checklist

April 29, 2015
Reading Time: 3 mins read

Boiling down what really matters concerning cybersecurity is a tough but worthy exercise. During recent remarks, Deputy Treasury Secretary Sarah Bloom Raskin offered a checklist of what the Treasury Department thinks are the essential elements of cybersecurity. Here we examine how your bank can answer her challenge.

MAKE CYBER RISK PART OF YOUR BANK’S CURRENT RISK MANAGEMENT FRAMEWORK

  • Tailor your framework to the size and business operations of your bank
  • Identify the cyber threats presented by your particular activities and operations and match those threats to the appropriate technology solutions.
  • Adopt policies, procedures and other controls to address identified cyber threats that their technology solutions cannot control and to reasonably anticipate possible breakdowns and overrides of that technology.
  • Employ highly qualified people to monitor and continually reassess the effectiveness of the deployed technology and controls, including those technologies or controls that are not directly operated by the institution.

USE THE NIST CYBERSECURITY FRAMEWORK

  • Identify your bank’s cyber posture and determine its risk profile and tolerance.
  • Develop organizational communication plans for responding to attacks.
  • Establish a common language and set of practices, standards and guidelines.
  • Apply your established risk-management approaches when the risks and associated controls are cyber-related.
  • Evaluate vendors and other third parties with access to your networks, systems and data.

UNDERSTAND THE SECURITY SAFEGUARDS THAT YOUR THIRD PARTIES HAVE IN PLACE

  • Know all vendors and third parties with access to your systems and data.
  • Ensure that those third parties have appropriate protections to safeguard your systems and data.
  • Conduct ongoing monitoring to ensure adherence to protections.
  • Document protections and related obligations in your contracts.

EVALUATE YOUR NEED FOR CYBER RISK INSURANCE

  • Know what it covers and excludes.
  • Know if it is adequate based on your risk exposure.
  • Leverage the qualification process to help assess your bank’s risk level.

ENGAGE IN BASIC CYBER HYGIENE

  • Know all the devices connected to your networks.
  • Reduce that number to only those who need those privileges.
  • Know who has administrative permissions to change, bypass and override system configurations.
  • Patch software on a timely basis.
  • Conduct continuous, automated vulnerability assessments.

SHARE INCIDENT DATA WITH INDUSTRY GROUPS

  • Join the Financial Services Information Sharing and Analysis Center.

HAVE AN INCIDENT PLAYBOOK AND A POINT PERSON FOR RESPONSE AND RECOVERY

  • Have a detailed, documented plan that designates who is responsible for leading the response-and-recovery efforts.
  • Chose a lead with exceptional organizational and communication skills because he or she will quarterback internal and external interactions.

DESIGNATE SENIOR LEADER AND THE BOARD ROLES DURING A CYBER INCIDENT RESPONSE

  • Designate when and which matters get escalated to the CEO.
  • Designate whether the full board or a committee—like risk or audit—is initially tasked to oversee the response from a governance perspective.
  • Participate in cyber exercises that simulate
    a cyber intrusion. Include the CEO, directors and other key players.

KNOW WHEN AND HOW TO ENGAGE WITH LAW ENFORCEMENT AFTER A BREACH

  • Have in your playbook when you should reach out to law enforcement.
  • Cultivate relationships with local U.S. Secret Service and FBI field offices.

KNOW WHEN AND HOW YOU WILL INFORM EVERYONE OF AN EVENT

  • Be transparent.
  • Avoid technical jargon and legalese and provide clear and consistent information.
  • Draft messages for various scenarios.

Tags: CybersecurityInformation sharingRisk management
ShareTweetPin

Related Posts

Reports explore information exposure, costs of data breaches

Report: Software vulnerabilities become top vector for data breaches

Compliance and Risk
June 12, 2026

Exploitation of software vulnerabilities has become the most common initial access vector for data breaches, according to the most recent Data Breach Investigations Report by Verizon.

With AI threats, CISA offers agencies guidelines for patching software vulnerabilities

With AI threats, CISA offers agencies guidelines for patching software vulnerabilities

Compliance and Risk
June 11, 2026

CISA released a new framework for federal civilian agencies in determining how quickly to patch software vulnerabilities, noting that artificial intelligence is “vastly increasing” the pace at which such vulnerabilities are discovered.

Survey: Banks boosting cybersecurity due to AI while also investing in technology

Financial Stability Board releases ‘sound practices’ for AI adoption

Compliance and Risk
June 10, 2026

The Financial Stability Board has released a draft list of 12 sound practices to guide the adoption of artificial intelligence by banks and other financial institutions.

House lawmakers propose federal studies on AI in financial services, housing

Proposed bill seeks to establish federal regulation of AI

Compliance and Risk
June 5, 2026

Two lawmakers have released a draft bipartisan bill to establish a national regulatory framework for artificial intelligence, including increased penalties for AI-enabled fraud and temporary preemption of state laws regulating AI models.

ABA urges ‘same risk, same regulation’ for digital assets

ABA: Data privacy bill leaves banks in existing federal privacy regulation framework

Compliance and Risk
June 3, 2026

ABA said that legislation to establish national data privacy standards contains many of the policy priorities that it has advocated for over the years, including ensuring that banks continue to be subject to the Gramm-Leach-Bliley Act framework.

Trump orders creation of AI ‘action plan’

Trump signs order to strengthen cybersecurity from AI-enabled threats

Community Banking
June 2, 2026

President Trump signed an executive order directing federal agencies to take steps to counter the potential cybersecurity threats posed by artificial intelligence, including by giving community banks the tools they need to protect themselves.

NEWSBYTES

ABA, associations: Basel proposal step in right direction

June 18, 2026

ABA DataBank: Probability of Fed hikes in 2026 on the rise

June 18, 2026

Mortgage rates drop

June 18, 2026

SPONSORED CONTENT

Why Your Systems Keep Slowing Down — and What to Do About It

Examiners Are Now Looking at Your Non-Core Systems

June 11, 2026
Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

June 1, 2026
A Modern Blueprint for Serving High-Net-Worth Families

A Modern Blueprint for Serving High-Net-Worth Families

May 28, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

AI Is in Your Bank. Is Your Cloud Contract Governing It?

May 20, 2026

PODCASTS

Podcast: Talent and innovation in community banking

June 18, 2026

Podcast: Understanding bank regulators’ guidance on illegal immigration

June 11, 2026

Podcast: Creating a feeling of welcome, for customers and new bankers

May 28, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.