Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

FFIEC Assessment Helps Financial Institutions Prevent Cyber Attacks

By Ashley B. Matthews on July 29, 2015
Email this postTweet this postLike this postShare this post on LinkedIn

Shredded PaperThe Federal Financial Institutions Examination Council (FFIEC) recently issued an assessment tool meant to assist financial institutions in the detection of cybersecurity vulnerabilities and the prevention of cyber attacks.

The FFIEC is an interagency body that develops the principles and standards used by agencies and organizations empowered to examine financial institutions, such as the Consumer Financial Protection Bureau, the Office of the Comptroller of the Currency (OCC), and the Federal Deposit Insurance Corporation. Earlier this year, the FFIEC released a list of its cybersecurity priorities for 2015.

According to the FFIEC, cyber attacks increasingly threaten financial institutions’ financial, operational, legal and reputational wellbeing. The FFIEC’s new tool is designed to assist financial institutions in avoiding these threats by:

  1. identifying factors contributing to, and determining the institution’s overall, cyber risk;
  2. assessing the institution’s cybersecurity preparedness;
  3. evaluating whether the institution’s cybersecurity preparedness is aligned with its risks;
  4. determining risk-management practices and controls that could be enhanced and actions that could be taken to achieve the institution’s desired state of cyber preparedness; and
  5. informing risk-management strategies.

Because cybersecurity risks constantly evolve, the FFIEC noted in its overview, the assessment is meant to serve as a “repeatable and measurable process for institutions to measure their cybersecurity preparedness over time.”

The assessment is broken into two parts. The “Inherent Risk Profile” assists a financial institution in determining the level of risk associated with its activities, services and products. The “Cybersecurity Maturity” assessment helps management to measure cybersecurity preparedness within five “domains”:

  1. Cyber-risk management and oversight
  2. Threat intelligence and collaboration
  3. Cybersecurity controls
  4. External-dependency management
  5. Cyber-incident management and resilience.

In November, the FFIEC released observations associated with its own cybersecurity assessment conducted in the summer of 2014 at 500 financial institutions. The resulting guidance recommended that financial institutions enhance management-level employees’ understanding and awareness of cybersecurity risks.

The November report further noted that sophisticated attackers develop dynamic tools and techniques targeted to specific products and services. Thus, it is important to understand the unique risks posed by the financial institution’s specific menu of offerings (for instance, risks associated with the institution’s own ACH, ATMs, mobile applications, and/or cloud computing). The FFIEC recommended that all financial institutions participate in the Financial Services Information Sharing and Analysis Center, a forum for the sharing of information related to cybersecurity threats and incidents.

According to the FFIEC’s press release, it will accept comments regarding the assessment pursuant to an upcoming notice in the Federal Register. In addition, the OCC will host a webinar about the Cybersecurity Assessment Tool at 2-3:30 p.m. (ET) on July 30.

Photo of Ashley B. Matthews Ashley B. Matthews

Ashley advises retailers and financial institutions with respect to consumer financial services, privacy and security, and governance matters.

Read more about Ashley B. MatthewsEmail
  • Posted in:
    Banking, Finance and Securities, Privacy and Cybersecurity
  • Blog:
    Subject to Inquiry
  • Organization:
    McGuireWoods LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo