By Heather Wyson
Financial institutions face an increasingly complex risk environment in which cyberattacks, technology outages, natural disasters, third-party disruptions and physical security events can quickly affect operations, customers, employees and communities. Resilience depends on preparation long before an incident occurs, disciplined coordination during the event and structured follow-up after operations resume.
Recommendations and Resources for Financial Institutions: Enhanced Resiliency and Recovery is a new resource developed by the American Bankers Association, the Financial Services Information Sharing and Analysis Center, and the U.S. Department of the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection. It emphasizes a simple but critical principle: Institutions are best positioned to respond when relationships, plans, communication channels and reporting processes are established in advance.
Significant events rarely fit neatly into one category. A cyber incident may trigger customer communications, law enforcement engagement, regulatory notification and third-party coordination at the same time. A natural disaster may require emergency communications, continuity planning, employee support and coordination with state and local officials. For that reason, financial institutions should plan around core functions and decision points rather than developing isolated plans for every possible scenario.
Before a significant event, institutions should build and maintain trusted relationships with public- and private-sector partners. Key partners include the Cybersecurity and Infrastructure Security Agency’s Cyber Security Advisors, Protective Security Advisors, Emergency Communications Coordinators, the FBI, U.S. Secret Service, Treasury OCCIP, fusion centers, FS-ISAC, regional financial-sector coalitions, state bankers associations and local emergency management agencies. These relationships can accelerate access to threat information, investigative support, technical assistance, priority communications resources and coordinated sector updates when time is limited.
Plans must be actionable. Institutions should identify critical functions, responsible staff and backups, vendor dependencies, regulatory contacts, law enforcement liaisons and employee, customer and external communications protocols. They should register for appropriate government services, including DHS’s Homeland Security Information Network, CISA cyber hygiene services, cybersecurity advisories and programs for telecommunications priority and restoration. Plans should be tested through tabletop and operational exercises offered by FS-ISAC, industry groups, federal agencies, state emergency management organizations and regional coalitions. Exercises help reveal gaps in decision-making, communications, escalation, and recovery procedures before an actual incident exposes them.
During a significant event, institutions should move quickly but deliberately. Legal counsel should be engaged early to support decision-making, preserve appropriate documentation, and advise on disclosure and compliance obligations.
Depending on the nature of the event, institutions may need to contact CISA, the FBI, the U.S. Secret Service, FS-ISAC, regulators, trade associations, emergency management officials, third-party service providers and local partners. Firms should also note that incidents may require firms to notify or coordinate with entities outside of US jurisdictions. Consistent communication is essential: Employees need clear direction, customers need accurate information and external stakeholders need updates that are timely, coordinated and fact-based.
After the event, institutions should meet applicable federal and state reporting obligations, including computer-security incident notification requirements, suspicious activity reporting requirements when appropriate and other sector-specific disclosure rules. Recovery should also include a structured lessons-learned review. Institutions should evaluate the effectiveness of their response, communications, vendor coordination, customer support, regulatory engagement and law enforcement follow-up. Findings should be incorporated into risk assessments, business continuity plans, incident response procedures, budgets, training and future exercises.
“Resilience is built before the crisis begins,” says John Carlson, SVP for cybersecurity regulation and resilience at ABA. “For financial institutions, that means establishing trusted relationships, testing response plans and ensuring decision-makers know whom to call and what programs and support they can leverage to strengthen their response.”
The most resilient institutions do not wait for a crisis to determine whom to call, what to say or how to recover. They build relationships in advance, test plans regularly, communicate clearly, document decisions and continuously improve. In a sector where trust, continuity and public confidence are essential, preparedness is not simply a compliance exercise. It is a core operational responsibility.
Heather Wyson is VP for cyber and physical security at ABA.









