ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Cybersecurity

You’ve Been Hacked: How Will You Respond?

June 25, 2015
Reading Time: 3 mins read

By Merrie Spaeth

Impersonating reporters on panels has become one of my favorite pastimes. After ABA’s Annual Convention last year, where I played a reporter on a panel examining how to handle a cyber attack, ABA invited me to return for its Risk Management Forum. The scenario was similar: Your bank has been hacked. In this mock scenario, the institution in the hot seat was a billion-dollar bank in the South named Lucky Bank, and the media outlet I represented was “UOMe” TV.

The first news of the hack came from credit card companies reporting that customers were complaining en masse about unauthorized charges and cancelled charges. A plaintiffs’ law firm—Dewey, Cheatham & Howe, borrowed from NPR’s “Car Talk”—trolled the Internet looking for bank customers for a class action suit, as did a well-connected, disgruntled blogger called Bankerbabe.

Lucky Bank also received word that the hackers were selling information allowing criminals to access ATMs, so bank personnel were physically reprogramming ATMs outside their branches. Internet-savvy customers noted the workmen and posted pictures of them on Instagram. Bankerbabe called them to my attention at the television station.

My role was to ask the questions the media would ask and to illustrate how social media platforms such as Facebook and Twitter complicate the communication challenge. Although bank executives may feel they have quite enough legal, technical and operational issues to contend with, communication—both internal and external—is needed across the entire enterprise. You will undoubtedly have to communicate with key audiences before you have all the facts. Typically, you will not have any of the key facts confirmed when you get word through third parties or social media.

Create a timeline beginning with taking the first phone call or reading the first tweet. Consider how you would handle the questions below after the first hour, day or week. On social media, you must have credible responses that convey confidence and inspire trust. And you’ll have to deal with these questions from reporters, customers and the general public. If you’re lucky, the reporter or customer will call customer service, but they may also be trading rumors on social media.

How and when you respond to these kinds of questions will undoubtedly depend on your own bank, the nature and scope of an attack and other considerations, but grappling with the questions will give you a snapshot of your preparedness.

Think about how you’ll handle questions like this:

  • 
I have heard that your bank has been hacked. Can you confirm or deny this?
  • 
How many customers have been affected?
  • 
What information did the hackers get? Social security numbers? What other kinds of customer data?
  • 
What have you told customers?
  • 
Who’s to blame?
  • 
Are you going to change your IT or security providers?
  • 
When did you detect the problem?
  • 
Did you have any warning signs?
  • 
How long were you exposed before discovering it?
  • 
Why did you wait to announce it?
  • 
What are you trying to cover up?
  • 
What kind of liability do you have?
  • 
Will you pay for credit counseling for customers?
  • 
Has this happened before?
  • 
Have you notified your regulators?
  • 
Are you confident you have identified and blocked all the intrusions?
  • 
Do you have insurance to cover this?
  • 
Are you going to apologize?
  • 
What if you do not find out who’s responsible?
  • 
Is this a criminal event, hackers displaying their abilities, terrorism or sabotage?
  • 
Can you guarantee this will never happen again?

Some reporters and bloggers better versed in information security may ask more in-depth questions:

  • 
Did you have Intrusions Detection Systems (IDS) implemented?
  • 
What about sandboxing as a preventive technique?
  • 
Does your IT department regularly send fake emails to employees to see if they open unauthorized emails, a primary way that hackers gain access? (The technique is controversial as an invasion of privacy, and because so many scam emails look so realistic, lots of employees inevitably get caught.)
  • 
Critics say that Security Event Management systems (SEMs) are ineffective architecture with a high false positive ratio. Are you using SEMs?
  • 
Experts say that hackers are increasingly gaining access to financial institutions through third party vendors or smaller financial institutions that may not have adequate security measures. What have you done to audit the security provisions of the enterprises you do business with? 
Can you guarantee they all have the proper security in place?

Merrie Spaeth is founder and president of Spaeth Communications.

Tags: CybersecurityData breachesSocial media
ShareTweetPin

Related Posts

Bank community engagement: Banking on care

Bank community engagement: Banking on care

Community Banking
November 13, 2025

Here are four ways banks can provide crucial support to the 63 million Americans who are caregivers.

ABA Foundation, AMBA partner to improve veterans’ financial health

Banking on service

Community Banking
November 11, 2025

Serving the military and veteran community with financial services.

Treasury Department seeks feedback on stablecoins, illicit activities

Survey: Most consumers would try stablecoins if offered by banks

Newsbytes
November 11, 2025

Nearly three in four consumers are open to trying stablecoins and other digital currency services if offered by their primary bank, compared to just 3.6% who would feel comfortable using unregulated providers, according to a new survey.

Survey: Most consumers uncomfortable talking about finances

Survey: Most consumers uncomfortable talking about finances

Financial Education
November 5, 2025

A new survey found that when talking to friends or family, most people find it easier to discuss politics or their love life than their bank accounts.

CFPB launches ‘tip line’ to report on bureau employees

Inspector general report finds CFPB cybersecurity lacking

Compliance and Risk
November 4, 2025

The CFPB's procedures for securing its information systems have deteriorated in recent months, and the issue has been made worse by the loss of contractor resources and bureau personnel, according to a recent audit by the Federal Reserve...

Face the music

Face the music

Retail and Marketing
November 4, 2025

Banks are finding powerful new ways to market via music, from hometown performers and festivals to the massive recent Eras tour.  

NEWSBYTES

FDIC considering tokenized deposit insurance guidance, stablecoin issuer rules

November 14, 2025

ABA DataBank: U.S. auto delinquencies approaching pre-Covid highs

November 14, 2025

Banking agencies release CRA data on small-business, small-farm lending in 2024

November 14, 2025

SPONSORED CONTENT

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

November 1, 2025
5 FedNow®  Service Developments You May Have Missed

5 FedNow® Service Developments You May Have Missed

October 31, 2025

Cash, Security, and Resilience in a Digital-First Economy

October 20, 2025
Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

October 1, 2025

PODCASTS

Podcast: The Erie Canal at 200

November 6, 2025

Podcast: Why branches are top priority for PNC

October 23, 2025

Podcast: From tractors to drones, how farming tech affects ag lending

October 16, 2025

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2025 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2025 American Bankers Association. All rights reserved.