ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Cybersecurity

The Treasury Department’s Cybersecurity Checklist

April 29, 2015
Reading Time: 3 mins read

Boiling down what really matters concerning cybersecurity is a tough but worthy exercise. During recent remarks, Deputy Treasury Secretary Sarah Bloom Raskin offered a checklist of what the Treasury Department thinks are the essential elements of cybersecurity. Here we examine how your bank can answer her challenge.

MAKE CYBER RISK PART OF YOUR BANK’S CURRENT RISK MANAGEMENT FRAMEWORK

  • Tailor your framework to the size and business operations of your bank
  • Identify the cyber threats presented by your particular activities and operations and match those threats to the appropriate technology solutions.
  • Adopt policies, procedures and other controls to address identified cyber threats that their technology solutions cannot control and to reasonably anticipate possible breakdowns and overrides of that technology.
  • Employ highly qualified people to monitor and continually reassess the effectiveness of the deployed technology and controls, including those technologies or controls that are not directly operated by the institution.

USE THE NIST CYBERSECURITY FRAMEWORK

  • Identify your bank’s cyber posture and determine its risk profile and tolerance.
  • Develop organizational communication plans for responding to attacks.
  • Establish a common language and set of practices, standards and guidelines.
  • Apply your established risk-management approaches when the risks and associated controls are cyber-related.
  • Evaluate vendors and other third parties with access to your networks, systems and data.

UNDERSTAND THE SECURITY SAFEGUARDS THAT YOUR THIRD PARTIES HAVE IN PLACE

  • Know all vendors and third parties with access to your systems and data.
  • Ensure that those third parties have appropriate protections to safeguard your systems and data.
  • Conduct ongoing monitoring to ensure adherence to protections.
  • Document protections and related obligations in your contracts.

EVALUATE YOUR NEED FOR CYBER RISK INSURANCE

  • Know what it covers and excludes.
  • Know if it is adequate based on your risk exposure.
  • Leverage the qualification process to help assess your bank’s risk level.

ENGAGE IN BASIC CYBER HYGIENE

  • Know all the devices connected to your networks.
  • Reduce that number to only those who need those privileges.
  • Know who has administrative permissions to change, bypass and override system configurations.
  • Patch software on a timely basis.
  • Conduct continuous, automated vulnerability assessments.

SHARE INCIDENT DATA WITH INDUSTRY GROUPS

  • Join the Financial Services Information Sharing and Analysis Center.

HAVE AN INCIDENT PLAYBOOK AND A POINT PERSON FOR RESPONSE AND RECOVERY

  • Have a detailed, documented plan that designates who is responsible for leading the response-and-recovery efforts.
  • Chose a lead with exceptional organizational and communication skills because he or she will quarterback internal and external interactions.

DESIGNATE SENIOR LEADER AND THE BOARD ROLES DURING A CYBER INCIDENT RESPONSE

  • Designate when and which matters get escalated to the CEO.
  • Designate whether the full board or a committee—like risk or audit—is initially tasked to oversee the response from a governance perspective.
  • Participate in cyber exercises that simulate
    a cyber intrusion. Include the CEO, directors and other key players.

KNOW WHEN AND HOW TO ENGAGE WITH LAW ENFORCEMENT AFTER A BREACH

  • Have in your playbook when you should reach out to law enforcement.
  • Cultivate relationships with local U.S. Secret Service and FBI field offices.

KNOW WHEN AND HOW YOU WILL INFORM EVERYONE OF AN EVENT

  • Be transparent.
  • Avoid technical jargon and legalese and provide clear and consistent information.
  • Draft messages for various scenarios.

Tags: CybersecurityInformation sharingRisk management
ShareTweetPin

Related Posts

Is deepfake technology shifting the gold standard of authentication?

Overseeing the AI wave: How banks and boards can move fast — without breaking trust

Technology
October 13, 2025

The future of banking will be defined not by whether banks use AI, but by how wisely they do so.

Survey: Net interest margins, cybersecurity top risks facing community banks

Survey: Net interest margins, cybersecurity top risks facing community banks

Community Banking
October 7, 2025

Net interest margins are the most important external risk facing community banks, according to the Conference of State Bank Supervisors’ 2025 community bank survey. Cybersecurity was the top internal risk.

FinCEN proposes applying BSA requirements to investment advisers

FS-ISAC urges financial sector to adopt timeline for implementing quantum computing defenses

Compliance and Risk
September 25, 2025

The Financial Services Information Sharing and Analysis Center called for the creation of a timeline for the financial sector to bolster its cybersecurity defenses against threats posed by quantum computing.

Survey: Banks boosting cybersecurity due to AI while also investing in technology

G7 group issues document on AI benefits, risks to financial system

Compliance and Risk
September 25, 2025

A G7 working group has released a statement outlining what policymakers and financial institutions should consider when weighing the potential cybersecurity benefits of artificial intelligence against misuse of the technology by malicious actors.

New task force to tackle financial fraud, scams

FBI alert: Scammers impersonating agency’s cyber-crimes website

Compliance and Risk
September 23, 2025

The FBI is warning that scammers are spoofing the website of the agency’s Internet Crime Complaint Center, or IC3, to trick consumers into turning over financial information.

BAFT releases report on best practices, guidance for ISO 20022 migration

ABA op-ed: Don’t fall for fintech, retailer spin on consumer financial information sharing

Compliance and Risk
September 12, 2025

Financial technology firms and mega-retailers are trying to trick the public about access to their own consumer financial information so the companies can profit from charging for access to that same data, ABA’s Ryan Miller wrote in a...

NEWSBYTES

ABA: Same BSA regulations should apply to banks, digital assets

October 17, 2025

ABA asks Fed, administration to maintain full penny deposit services

October 17, 2025

Nacha adopts new rules to enhance international ACH transactions

October 17, 2025

SPONSORED CONTENT

Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

October 1, 2025
What good looks like in Small Business Lending – and how to get there

What good looks like in Small Business Lending – and how to get there

October 1, 2025
The Connectivity Dividend

The Connectivity Dividend

September 1, 2025
Building Trust with Every Transaction

Building Trust with Every Transaction

September 1, 2025

PODCASTS

Podcast: From tractors to drones, how farming tech affects ag lending

October 16, 2025

Podcast: Bigger data boosts financial inclusion at Synchrony

October 9, 2025

Podcast: AI and the future of BSA risk management

October 2, 2025

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2025 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2025 American Bankers Association. All rights reserved.