ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Cybersecurity

You’ve Been Hacked: How Will You Respond?

June 25, 2015
Reading Time: 3 mins read

By Merrie Spaeth

Impersonating reporters on panels has become one of my favorite pastimes. After ABA’s Annual Convention last year, where I played a reporter on a panel examining how to handle a cyber attack, ABA invited me to return for its Risk Management Forum. The scenario was similar: Your bank has been hacked. In this mock scenario, the institution in the hot seat was a billion-dollar bank in the South named Lucky Bank, and the media outlet I represented was “UOMe” TV.

The first news of the hack came from credit card companies reporting that customers were complaining en masse about unauthorized charges and cancelled charges. A plaintiffs’ law firm—Dewey, Cheatham & Howe, borrowed from NPR’s “Car Talk”—trolled the Internet looking for bank customers for a class action suit, as did a well-connected, disgruntled blogger called Bankerbabe.

Lucky Bank also received word that the hackers were selling information allowing criminals to access ATMs, so bank personnel were physically reprogramming ATMs outside their branches. Internet-savvy customers noted the workmen and posted pictures of them on Instagram. Bankerbabe called them to my attention at the television station.

My role was to ask the questions the media would ask and to illustrate how social media platforms such as Facebook and Twitter complicate the communication challenge. Although bank executives may feel they have quite enough legal, technical and operational issues to contend with, communication—both internal and external—is needed across the entire enterprise. You will undoubtedly have to communicate with key audiences before you have all the facts. Typically, you will not have any of the key facts confirmed when you get word through third parties or social media.

Create a timeline beginning with taking the first phone call or reading the first tweet. Consider how you would handle the questions below after the first hour, day or week. On social media, you must have credible responses that convey confidence and inspire trust. And you’ll have to deal with these questions from reporters, customers and the general public. If you’re lucky, the reporter or customer will call customer service, but they may also be trading rumors on social media.

How and when you respond to these kinds of questions will undoubtedly depend on your own bank, the nature and scope of an attack and other considerations, but grappling with the questions will give you a snapshot of your preparedness.

Think about how you’ll handle questions like this:

  • 
I have heard that your bank has been hacked. Can you confirm or deny this?
  • 
How many customers have been affected?
  • 
What information did the hackers get? Social security numbers? What other kinds of customer data?
  • 
What have you told customers?
  • 
Who’s to blame?
  • 
Are you going to change your IT or security providers?
  • 
When did you detect the problem?
  • 
Did you have any warning signs?
  • 
How long were you exposed before discovering it?
  • 
Why did you wait to announce it?
  • 
What are you trying to cover up?
  • 
What kind of liability do you have?
  • 
Will you pay for credit counseling for customers?
  • 
Has this happened before?
  • 
Have you notified your regulators?
  • 
Are you confident you have identified and blocked all the intrusions?
  • 
Do you have insurance to cover this?
  • 
Are you going to apologize?
  • 
What if you do not find out who’s responsible?
  • 
Is this a criminal event, hackers displaying their abilities, terrorism or sabotage?
  • 
Can you guarantee this will never happen again?

Some reporters and bloggers better versed in information security may ask more in-depth questions:

  • 
Did you have Intrusions Detection Systems (IDS) implemented?
  • 
What about sandboxing as a preventive technique?
  • 
Does your IT department regularly send fake emails to employees to see if they open unauthorized emails, a primary way that hackers gain access? (The technique is controversial as an invasion of privacy, and because so many scam emails look so realistic, lots of employees inevitably get caught.)
  • 
Critics say that Security Event Management systems (SEMs) are ineffective architecture with a high false positive ratio. Are you using SEMs?
  • 
Experts say that hackers are increasingly gaining access to financial institutions through third party vendors or smaller financial institutions that may not have adequate security measures. What have you done to audit the security provisions of the enterprises you do business with? 
Can you guarantee they all have the proper security in place?

Merrie Spaeth is founder and president of Spaeth Communications.

Tags: CybersecurityData breachesSocial media
ShareTweetPin

Related Posts

Treasury Department launches cybersecurity initiative for financial services

Bank survey finds widespread cybersecurity concerns among small business owners

Compliance and Risk
August 17, 2026

Eight-seven percent of small business owners believe a cyberattack could have severe financial consequences, with 84% believing it could damage their customer relationships.

Bill would strengthen criminal penalties for ATM robberies

State attorneys general express support for ATM crime bill

Compliance and Risk
August 14, 2026

Fifteen state attorneys general urged Congress to pass legislation ensuring that robberies of off-site ATMs carry the same legal consequences as bank robberies. ABA also supports the bill.

ABA urges ‘same risk, same regulation’ for digital assets

ABA urges federal regulation of AI, level playing field for financial services

Compliance and Risk
August 14, 2026

Congress should establish a nationally harmonized, risk-based framework for regulating artificial intelligence in the financial services sector, which would preempt state laws while assuring strong consumer protection and cybersecurity outcomes, ABA told House Financial Services Committee members.

Cost of funds shoots to top of community bankers’ concerns in 2024

Survey finds most consumers want to maintain bank branch access

Community Banking
August 14, 2026

U.S. consumers want digital banking convenience but also want to maintain access to bank branches and people for complex issues and personalized financial guidance, according to a new survey by Santander.

FBI and CISA release updated cybersecurity advisory on Scattered Spider

White House announces new push to combat cybercrime, fraud

Compliance and Risk
August 13, 2026

President Trump directed federal law enforcement to create a new program that partners with the private sector to target transnational criminal organizations responsible for ransomware attacks, phishing campaigns and other cybercrimes.

Banks, Sports Sponsorships and COVID: Three Ways to Win

The new playbook for banking athletes

Retail and Marketing
August 10, 2026

An ABA Banking Journal series explores how banks are adapting to the financial needs of student athletes, professionals and the sports industry around them.

NEWSBYTES

ABA voices support for updating derivatives, hedging accounting standards

August 18, 2026

Survey finds satisfaction gap among credit card holders

August 18, 2026

NAR: Pending home sales dipped in July

August 18, 2026

SPONSORED CONTENT

Why Your Systems Keep Slowing Down — and What to Do About It

The exam question a backup can’t answer

August 18, 2026
Beyond Surveillance: Rethinking Security for Modern Financial Institutions

Beyond Surveillance: Rethinking Security for Modern Financial Institutions

August 12, 2026
Relationship Banking at Scale: Why Banks Need The Digital Sales & Service Platform

Relationship Banking at Scale: Why Banks Need The Digital Sales & Service Platform

August 1, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

Examiners Are Now Looking at Your Non-Core Systems

June 11, 2026

PODCASTS

Podcast: Banking the brave new world of college athletics

August 4, 2026

Podcast: Tactics for meaningful strategic planning

July 28, 2026

Podcast: Why it might be time to revisit a key FDIC ratio

July 23, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.