ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Cybersecurity

Building resilience before, during and after a significant event

Institutions are best positioned to respond when relationships, plans, communication channels and reporting processes are established in advance.

August 27, 2026
Reading Time: 3 mins read
Building resilience before, during and after a significant event

By Heather Wyson

Financial institutions face an increasingly complex risk environment in which cyberattacks, technology outages, natural disasters, third-party disruptions and physical security events can quickly affect operations, customers, employees and communities. Resilience depends on preparation long before an incident occurs, disciplined coordination during the event and structured follow-up after operations resume.

Recommendations and Resources for Financial Institutions: Enhanced Resiliency and Recovery is a new resource developed by the American Bankers Association, the Financial Services Information Sharing and Analysis Center, and the U.S. Department of the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection. It emphasizes a simple but critical principle: Institutions are best positioned to respond when relationships, plans, communication channels and reporting processes are established in advance.

Significant events rarely fit neatly into one category. A cyber incident may trigger customer communications, law enforcement engagement, regulatory notification and third-party coordination at the same time. A natural disaster may require emergency communications, continuity planning, employee support and coordination with state and local officials. For that reason, financial institutions should plan around core functions and decision points rather than developing isolated plans for every possible scenario.

Before a significant event, institutions should build and maintain trusted relationships with public- and private-sector partners. Key partners include the Cybersecurity and Infrastructure Security Agency’s Cyber Security Advisors, Protective Security Advisors, Emergency Communications Coordinators, the FBI, U.S. Secret Service, Treasury OCCIP, fusion centers, FS-ISAC, regional financial-sector coalitions, state bankers associations and local emergency management agencies. These relationships can accelerate access to threat information, investigative support, technical assistance, priority communications resources and coordinated sector updates when time is limited.

Plans must be actionable. Institutions should identify critical functions, responsible staff and backups, vendor dependencies, regulatory contacts, law enforcement liaisons and employee, customer and external communications protocols. They should register for appropriate government services, including DHS’s Homeland Security Information Network, CISA cyber hygiene services, cybersecurity advisories and programs for telecommunications priority and restoration. Plans should be tested through tabletop and operational exercises offered by FS-ISAC, industry groups, federal agencies, state emergency management organizations and regional coalitions. Exercises help reveal gaps in decision-making, communications, escalation, and recovery procedures before an actual incident exposes them.

During a significant event, institutions should move quickly but deliberately. Legal counsel should be engaged early to support decision-making, preserve appropriate documentation, and advise on disclosure and compliance obligations.

Depending on the nature of the event, institutions may need to contact CISA, the FBI, the U.S. Secret Service, FS-ISAC, regulators, trade associations, emergency management officials, third-party service providers and local partners. Firms should also note that incidents may require firms to notify or coordinate with entities outside of US jurisdictions. Consistent communication is essential: Employees need clear direction, customers need accurate information and external stakeholders need updates that are timely, coordinated and fact-based.

After the event, institutions should meet applicable federal and state reporting obligations, including computer-security incident notification requirements, suspicious activity reporting requirements when appropriate and other sector-specific disclosure rules. Recovery should also include a structured lessons-learned review. Institutions should evaluate the effectiveness of their response, communications, vendor coordination, customer support, regulatory engagement and law enforcement follow-up. Findings should be incorporated into risk assessments, business continuity plans, incident response procedures, budgets, training and future exercises.

“Resilience is built before the crisis begins,” says John Carlson, SVP for cybersecurity regulation and resilience at ABA. “For financial institutions, that means establishing trusted relationships, testing response plans and ensuring decision-makers know whom to call and what programs and support they can leverage to strengthen their response.”

The most resilient institutions do not wait for a crisis to determine whom to call, what to say or how to recover. They build relationships in advance, test plans regularly, communicate clearly, document decisions and continuously improve. In a sector where trust, continuity and public confidence are essential, preparedness is not simply a compliance exercise. It is a core operational responsibility.

Heather Wyson is VP for cyber and physical security at ABA.

Tags: ComplianceCrisis communicationsCybersecurityPhysical securityRisk management
ShareTweetPin

Related Posts

Hitting home

Hitting home

ABA Banking Journal
September 9, 2026

When people talk about financial services, they often talk about systems, markets, platforms and performance. But on Sept. 11, all of that fell away.

FinCEN, banking agencies release FAQs on digital credentials, customer ID

FinCEN, banking agencies release FAQs on digital credentials, customer ID

Compliance and Risk
September 8, 2026

Financial institutions may use a mobile driver’s license or other government-issued virtual ID as a form of documentary verification for purposes of customer identification program compliance, so long as they maintain the appropriate technology or systems to extract...

FinCEN issues alert on Iran, commercial aviation parts procurement

FinCEN issues alert on Iran, commercial aviation parts procurement

Compliance and Risk
September 8, 2026

FinCEN issued an alert for financial institutions on identifying and reporting procurement networks supporting Iran’s aviation industry. The alert was issued in conjunction with the announcement that the Treasury Department was imposing sanctions on 36 entities tied to...

Old ways of life, new bank opportunities

Old ways of life, new bank opportunities

Community Banking
September 8, 2026

As the Amish and Plain population explodes across the country, their growth creates new opportunities for community banks with flexible policies.

FCC proposes ‘robocall scorecard’ to rate voice service providers

FCC proposes ‘robocall scorecard’ to rate voice service providers

Compliance and Risk
September 5, 2026

The FCC is seeking public comment on creating a “robocall scorecard” to measure how voice service providers are protecting consumers from illegal calls. In related news, the commission booted 14 providers from the U.S. telecommunications network.

ABA highlights banker comments seeking stronger ‘know your customer’ rules for originating providers

Consumers share experiences with AI-enabled scams

Compliance and Risk
September 4, 2026

More than two in five U.S. consumers said they have encountered a scam powered by artificial intelligence, either personally or through someone they know, according to a recent survey by Credit One Bank.

NEWSBYTES

FinCEN, banking agencies release FAQs on digital credentials, customer ID

September 8, 2026

New York Fed: Inflation expectations ticked down in August

September 8, 2026

ABA, associations urge FHA to provide clear language about eligibility for VA loan terms

September 8, 2026

SPONSORED CONTENT

Taming AI Agent Sprawl: A Playbook for Consumer Lending

Taming AI Agent Sprawl: A Playbook for Consumer Lending

September 1, 2026
Grow Public Deposits Without the Operational Burden End Fragment

Grow Public Deposits Without the Operational Burden End Fragment

September 1, 2026
Could Your Bank Absorb the Hidden Cost of Running Legacy Systems?

Could Your Bank Absorb the Hidden Cost of Running Legacy Systems?

August 20, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

The exam question a backup can’t answer

August 18, 2026

PODCASTS

Podcast: Banking the brave new world of college athletics

August 4, 2026

Podcast: Tactics for meaningful strategic planning

July 28, 2026

Podcast: Why it might be time to revisit a key FDIC ratio

July 23, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.