ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Cybersecurity

Building resilience before, during and after a significant event

Institutions are best positioned to respond when relationships, plans, communication channels and reporting processes are established in advance.

August 27, 2026
Reading Time: 3 mins read
Building resilience before, during and after a significant event

By Heather Wyson

Financial institutions face an increasingly complex risk environment in which cyberattacks, technology outages, natural disasters, third-party disruptions and physical security events can quickly affect operations, customers, employees and communities. Resilience depends on preparation long before an incident occurs, disciplined coordination during the event and structured follow-up after operations resume.

Recommendations and Resources for Financial Institutions: Enhanced Resiliency and Recovery is a new resource developed by the American Bankers Association, the Financial Services Information Sharing and Analysis Center, and the U.S. Department of the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection. It emphasizes a simple but critical principle: Institutions are best positioned to respond when relationships, plans, communication channels and reporting processes are established in advance.

Significant events rarely fit neatly into one category. A cyber incident may trigger customer communications, law enforcement engagement, regulatory notification and third-party coordination at the same time. A natural disaster may require emergency communications, continuity planning, employee support and coordination with state and local officials. For that reason, financial institutions should plan around core functions and decision points rather than developing isolated plans for every possible scenario.

Before a significant event, institutions should build and maintain trusted relationships with public- and private-sector partners. Key partners include the Cybersecurity and Infrastructure Security Agency’s Cyber Security Advisors, Protective Security Advisors, Emergency Communications Coordinators, the FBI, U.S. Secret Service, Treasury OCCIP, fusion centers, FS-ISAC, regional financial-sector coalitions, state bankers associations and local emergency management agencies. These relationships can accelerate access to threat information, investigative support, technical assistance, priority communications resources and coordinated sector updates when time is limited.

Plans must be actionable. Institutions should identify critical functions, responsible staff and backups, vendor dependencies, regulatory contacts, law enforcement liaisons and employee, customer and external communications protocols. They should register for appropriate government services, including DHS’s Homeland Security Information Network, CISA cyber hygiene services, cybersecurity advisories and programs for telecommunications priority and restoration. Plans should be tested through tabletop and operational exercises offered by FS-ISAC, industry groups, federal agencies, state emergency management organizations and regional coalitions. Exercises help reveal gaps in decision-making, communications, escalation, and recovery procedures before an actual incident exposes them.

During a significant event, institutions should move quickly but deliberately. Legal counsel should be engaged early to support decision-making, preserve appropriate documentation, and advise on disclosure and compliance obligations.

Depending on the nature of the event, institutions may need to contact CISA, the FBI, the U.S. Secret Service, FS-ISAC, regulators, trade associations, emergency management officials, third-party service providers and local partners. Firms should also note that incidents may require firms to notify or coordinate with entities outside of US jurisdictions. Consistent communication is essential: Employees need clear direction, customers need accurate information and external stakeholders need updates that are timely, coordinated and fact-based.

After the event, institutions should meet applicable federal and state reporting obligations, including computer-security incident notification requirements, suspicious activity reporting requirements when appropriate and other sector-specific disclosure rules. Recovery should also include a structured lessons-learned review. Institutions should evaluate the effectiveness of their response, communications, vendor coordination, customer support, regulatory engagement and law enforcement follow-up. Findings should be incorporated into risk assessments, business continuity plans, incident response procedures, budgets, training and future exercises.

“Resilience is built before the crisis begins,” says John Carlson, SVP for cybersecurity regulation and resilience at ABA. “For financial institutions, that means establishing trusted relationships, testing response plans and ensuring decision-makers know whom to call and what programs and support they can leverage to strengthen their response.”

The most resilient institutions do not wait for a crisis to determine whom to call, what to say or how to recover. They build relationships in advance, test plans regularly, communicate clearly, document decisions and continuously improve. In a sector where trust, continuity and public confidence are essential, preparedness is not simply a compliance exercise. It is a core operational responsibility.

Heather Wyson is VP for cyber and physical security at ABA.

Tags: ComplianceCrisis communicationsCybersecurityPhysical securityRisk management
ShareTweetPin

Related Posts

Podcast: Making the jump from a high performer to a high-performing leader

Podcast: Making the jump from a high performer to a high-performing leader

ABA Banking Journal Podcast
September 16, 2026

"Leadership is a skill you have to develop and maintain over time," says Velera Wilson.

Digital Banking Reshapes Cybersecurity

How will banks reinvest the time AI saves?

Technology
September 15, 2026

The bank may become more efficient, but not necessarily more strategic. The capacity dividend becomes valuable only when it is intentionally reinvested.

ABA urges FCC to modernize calling rules, strengthen fraud protections

State AGs urge FCC to impose stronger ‘know your upstream provider’ requirements

Compliance and Risk
September 14, 2026

Forty-nine state attorneys general last week urged the Federal Communications Commission to impose stronger “know your upstream provider” requirements to keep calls off the U.S. calling network.

Banks’ wealth units pursue AI — carefully

Banks’ wealth units pursue AI — carefully

Wealth Management
September 14, 2026

'Some of the best ideas have come from junior employees doing the analytical work who often understand the technology better.'

Banking agencies pledge more scrutiny of core provider business practices

Banking agencies pledge more scrutiny of core provider business practices

Compliance and Risk
September 11, 2026

The federal banking agencies pledged to step up oversight of third-party core providers whose business practices “unreasonably limit” community banks from conducting due diligence or from negotiating contract terms that address the banks’ business needs.

CISA releases updated guide on insider threats

CISA releases updated guide on insider threats

Compliance and Risk
September 11, 2026

The guide gives organizations a current look at insider threats and practical steps to develop or enhance an insider threat program, according to CISA.

NEWSBYTES

CFPB releases updated home loan buyer’s guide

September 16, 2026

House committee advances ABA-backed bills on state lending rate caps, CFPB reform

September 16, 2026

Senate Ag Committee advances Farm Bill

September 16, 2026

SPONSORED CONTENT

Beyond the Portfolio: The Wealth Manager’s New Role in a Multigenerational World

Beyond the Portfolio: The Wealth Manager’s New Role in a Multigenerational World

September 17, 2026
Banking Technology at a Strategic Crossroads

Banking Technology at a Strategic Crossroads

September 8, 2026
Taming AI Agent Sprawl: A Playbook for Consumer Lending

Taming AI Agent Sprawl: A Playbook for Consumer Lending

September 1, 2026
Grow Public Deposits Without the Operational Burden End Fragment

Grow Public Deposits Without the Operational Burden End Fragment

September 1, 2026

PODCASTS

Podcast: Making the jump from a high performer to a high-performing leader

September 16, 2026

Podcast: Remembering 9/11, a quarter century later

September 10, 2026

Podcast: Banking the brave new world of college athletics

August 4, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.