ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Cybersecurity

Building resilience before, during and after a significant event

Institutions are best positioned to respond when relationships, plans, communication channels and reporting processes are established in advance.

August 27, 2026
Reading Time: 3 mins read
Building resilience before, during and after a significant event

By Heather Wyson

Financial institutions face an increasingly complex risk environment in which cyberattacks, technology outages, natural disasters, third-party disruptions and physical security events can quickly affect operations, customers, employees and communities. Resilience depends on preparation long before an incident occurs, disciplined coordination during the event and structured follow-up after operations resume.

Recommendations and Resources for Financial Institutions: Enhanced Resiliency and Recovery is a new resource developed by the American Bankers Association, the Financial Services Information Sharing and Analysis Center, and the U.S. Department of the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection. It emphasizes a simple but critical principle: Institutions are best positioned to respond when relationships, plans, communication channels and reporting processes are established in advance.

Significant events rarely fit neatly into one category. A cyber incident may trigger customer communications, law enforcement engagement, regulatory notification and third-party coordination at the same time. A natural disaster may require emergency communications, continuity planning, employee support and coordination with state and local officials. For that reason, financial institutions should plan around core functions and decision points rather than developing isolated plans for every possible scenario.

Before a significant event, institutions should build and maintain trusted relationships with public- and private-sector partners. Key partners include the Cybersecurity and Infrastructure Security Agency’s Cyber Security Advisors, Protective Security Advisors, Emergency Communications Coordinators, the FBI, U.S. Secret Service, Treasury OCCIP, fusion centers, FS-ISAC, regional financial-sector coalitions, state bankers associations and local emergency management agencies. These relationships can accelerate access to threat information, investigative support, technical assistance, priority communications resources and coordinated sector updates when time is limited.

Plans must be actionable. Institutions should identify critical functions, responsible staff and backups, vendor dependencies, regulatory contacts, law enforcement liaisons and employee, customer and external communications protocols. They should register for appropriate government services, including DHS’s Homeland Security Information Network, CISA cyber hygiene services, cybersecurity advisories and programs for telecommunications priority and restoration. Plans should be tested through tabletop and operational exercises offered by FS-ISAC, industry groups, federal agencies, state emergency management organizations and regional coalitions. Exercises help reveal gaps in decision-making, communications, escalation, and recovery procedures before an actual incident exposes them.

During a significant event, institutions should move quickly but deliberately. Legal counsel should be engaged early to support decision-making, preserve appropriate documentation, and advise on disclosure and compliance obligations.

Depending on the nature of the event, institutions may need to contact CISA, the FBI, the U.S. Secret Service, FS-ISAC, regulators, trade associations, emergency management officials, third-party service providers and local partners. Firms should also note that incidents may require firms to notify or coordinate with entities outside of US jurisdictions. Consistent communication is essential: Employees need clear direction, customers need accurate information and external stakeholders need updates that are timely, coordinated and fact-based.

After the event, institutions should meet applicable federal and state reporting obligations, including computer-security incident notification requirements, suspicious activity reporting requirements when appropriate and other sector-specific disclosure rules. Recovery should also include a structured lessons-learned review. Institutions should evaluate the effectiveness of their response, communications, vendor coordination, customer support, regulatory engagement and law enforcement follow-up. Findings should be incorporated into risk assessments, business continuity plans, incident response procedures, budgets, training and future exercises.

“Resilience is built before the crisis begins,” says John Carlson, SVP for cybersecurity regulation and resilience at ABA. “For financial institutions, that means establishing trusted relationships, testing response plans and ensuring decision-makers know whom to call and what programs and support they can leverage to strengthen their response.”

The most resilient institutions do not wait for a crisis to determine whom to call, what to say or how to recover. They build relationships in advance, test plans regularly, communicate clearly, document decisions and continuously improve. In a sector where trust, continuity and public confidence are essential, preparedness is not simply a compliance exercise. It is a core operational responsibility.

Heather Wyson is VP for cyber and physical security at ABA.

Tags: ComplianceCrisis communicationsCybersecurityPhysical securityRisk management
ShareTweetPin

Related Posts

FDIC issues final special assessment to recover Deposit Insurance Fund losses

FDIC updates rules on reciprocal deposits

Compliance and Risk
August 27, 2026

The FDIC issued a final interim rule to update its regulations on reciprocal deposits to conform with housing legislation recently passed by Congress.

FDIC, OCC formally define unsafe and unsound practices

FDIC, OCC formally define unsafe and unsound practices

Compliance and Risk
August 27, 2026

The FDIC and OCC finalized a rule to formally define “unsafe and unsound practices,” which they said would bring more certainty to bank supervision.

What’s the banking connection in Dolly Parton’s “Jolene”?

What’s the banking connection in Dolly Parton’s “Jolene”?

Community Banking
August 27, 2026

Bank teller inspires hit song by legendary cultural figure.

FDIC proposes defining unsafe and unsound practices, removing reputational risk

FDIC pushes back comment deadline for disclosure rule

Compliance and Risk
August 27, 2026

The FDIC will extend the public comment deadline for its proposed bank information disclosure rule to align it with a deadline for a similar rule proposed by the OCC. ABA asked for the extension.

FTC seeks to enforce business disclosure of personalized pricing

FTC seeks to enforce business disclosure of personalized pricing

Compliance and Risk
August 26, 2026

Businesses that fail to disclose that they use consumer data to set personalized prices for goods or services are likely engaging in deception or unfairness and can expect the Federal Trade Commission to pursue enforcement actions, according to...

Investment account fraud: red flags and mitigation

Investment account fraud: red flags and mitigation

Compliance and Risk
August 25, 2026

The objective is not simply to stop a transaction. It is to help the customer recognize the deception and prevent additional losses.

NEWSBYTES

FDIC updates rules on reciprocal deposits

August 27, 2026

FDIC, OCC formally define unsafe and unsound practices

August 27, 2026

Mortgage rates inch up

August 27, 2026

SPONSORED CONTENT

Could Your Bank Absorb the Hidden Cost of Running Legacy Systems?

August 20, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

The exam question a backup can’t answer

August 18, 2026
Beyond Surveillance: Rethinking Security for Modern Financial Institutions

Beyond Surveillance: Rethinking Security for Modern Financial Institutions

August 12, 2026
Relationship Banking at Scale: Why Banks Need The Digital Sales & Service Platform

Relationship Banking at Scale: Why Banks Need The Digital Sales & Service Platform

August 1, 2026

PODCASTS

Could Your Bank Absorb the Hidden Cost of Running Legacy Systems?

August 20, 2026

Podcast: Banking the brave new world of college athletics

August 4, 2026

Podcast: Tactics for meaningful strategic planning

July 28, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.