Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupport
Contact Us
Search
Close

Sound Practices for Operational Resilience Released by US Banking Regulators

By Rajesh De, Jeffrey P. Taft, David A. Simon, Megan Webster, J. Paul Forrester & Matthew Bisanz on November 5, 2020
Email this postTweet this postLike this postShare this post on LinkedIn

On October 30, 2020, the US federal banking regulators1 issued guidance on sound practices for the largest US banking organizations to strengthen their operational resilience, including with respect to cyber risk management (the “Guidance”).2 Operational resilience is an organization’s ability to prepare for, adapt to, withstand, and recover from disruptions and to continue operations. Disruptions may come from any type of internal or external operational risk and include technology-based failures, cyber incidents, pandemic outbreaks, and natural disasters.

The practices in the Guidance are characterized as being drawn from “existing regulations, guidance, statements, and common industry standards,” and the regulators maintain that the Guidance does not revise existing precedent or impose new requirements. However, the Guidance blurs the lines between rules, guidance, and supervisory expectations, and, therefore, regulators could expect the largest and most complex banking organizations to enhance operational resilience policies, procedures, and processes and associated control, monitoring, and testing to address the Guidance. Additionally, the Guidance blends concepts from different areas of banking law and, therefore, could be characterized as requiring organizations to reorganize compliance structures to coordinate activities that were previously conducted in silos.

Continue reading.

Rajesh De

Raj De serves on Mayer Brown’s global Management Committee. He was previously the Managing Partner of Mayer Brown’s Washington DC office, which is comprised of more than two hundred lawyers. He leads the firm’s global Cybersecurity & Data Privacy practice, as well as…

Raj De serves on Mayer Brown’s global Management Committee. He was previously the Managing Partner of Mayer Brown’s Washington DC office, which is comprised of more than two hundred lawyers. He leads the firm’s global Cybersecurity & Data Privacy practice, as well as the firm’s National Security practice, and serves as a member of the firm’s Congressional Investigations & Crisis Management team. After nearly two decades in private practice and public service across all three branches of the United States government, Raj is one of the most trusted voices in Washington. He has held senior appointments in the White House, the Department of Justice (DOJ) and the Department of Defense (DOD). Raj returned to Mayer Brown in 2015 after serving as General Counsel at the United States National Security Agency (NSA). Since returning to the firm, Raj has received numerous recognitions, including by American Lawyer (“Lateral All-Star”), Washingtonian magazine (“Top Lawyer”), The National Law Journal (“Cybersecurity and Data Privacy Trailblazer”), and Cybersecurity Docket (“Incident Response 30”).

Raj focuses his practice on cutting-edge legal and policy issues at the nexus of technology, national security, law enforcement and privacy. He advises clients, including management teams and boards of directors, in connection with crisis management, government and internal investigations, high-stakes litigation, regulatory enforcement matters, and congressional inquiries. Raj provides clients with strategic counseling and practical legal advice, drawing upon a wealth of experience in government service and private practice.

Read Raj’s full bio.

Read more about Rajesh DeEmail
Show more Show less
Photo of Jeffrey P. Taft Jeffrey P. Taft

Jeffrey Taft is a partner in the Firm’s Financial Services Regulatory & Enforcement group and the Cybersecurity and Data Privacy practice. His practice focuses primarily on bank regulation, bank receivership and insolvency issues, payment systems, consumer financial services and cybersecurity/privacy issues. He has…

Jeffrey Taft is a partner in the Firm’s Financial Services Regulatory & Enforcement group and the Cybersecurity and Data Privacy practice. His practice focuses primarily on bank regulation, bank receivership and insolvency issues, payment systems, consumer financial services and cybersecurity/privacy issues. He has extensive experience counseling financial institutions, merchants, technology companies and other entities on various federal and state banking and consumer credit issues, including compliance with the Bank Holding Company Act, National Bank Act, International Banking Act, Consumer Financial Protection Act, Truth-in-Lending Act, the Fair Credit Reporting Act, the Electronic Fund Transfer Act, the Equal Credit Opportunity Act, the Fair Debt Collection Practices Act, the Real Estate Settlement Procedures Act, state unfair or deceptive acts or practices statutes, CFPB’s UDAAP authority and the development and implementation of privacy, cybersecurity and information security programs under the Gramm-Leach Bliley Act, the NYDFS cybersecurity regulation and industry standards, such as PCI DSS and NIST.

Read Jeff’s full bio.

Read more about Jeffrey P. TaftEmail
Show more Show less
Photo of David A. Simon David A. Simon

David Simon is a partner in Mayer Brown’s Washington DC office and a leading member of the global Cybersecurity & Data Privacy practice. He is also a member of the firm’s National Security and Government Contracts practices. A former special counsel at the…

David Simon is a partner in Mayer Brown’s Washington DC office and a leading member of the global Cybersecurity & Data Privacy practice. He is also a member of the firm’s National Security and Government Contracts practices. A former special counsel at the US Department of Defense (DoD) and chief cyber counsel to the US Cyberspace Solarium Commission, David has deep experience advising victims of ransomware attacks and state-sponsored cyber activity. Named as a Cybersecurity Trailblazer by The National Law Journal, David has also been named to Cybersecurity Docket’s “Incident Response 40,” a collection of 40 of the “best and brightest” incident response attorneys in the country. David regularly supports clients as the lead investigator and crisis manager for cross-border cyber incidents, including data breaches involving personal data, nation-state threats targeting intellectual property, state-sponsored theft of sensitive U.S. government information, and destructive attacks. David has directed and advised on dozens of complex cyber incident and data breach investigations in the last few years alone. He has counseled companies on major cyber incidents and incident preparedness across virtually every sector of the economy. David represents financial institutions, automotive manufacturers and self-driving car companies, tech companies, telecommunications companies, healthcare companies, insurance companies, defense and aerospace companies, private equity firms and their portfolio companies.

Read David’s full bio.

Read more about David A. SimonEmailDavid's Linkedin Profile
Show more Show less
Photo of J. Paul Forrester J. Paul Forrester

Paul Forrester is a respected corporate finance and securities lawyer whose practice is especially focused on structured credit, including collateralized loan obligations, energy (including oil and gas, utilities, shipping, refinery and pipeline) financings and project development, and financing (especially concerning renewable energy, industrial…

Paul Forrester is a respected corporate finance and securities lawyer whose practice is especially focused on structured credit, including collateralized loan obligations, energy (including oil and gas, utilities, shipping, refinery and pipeline) financings and project development, and financing (especially concerning renewable energy, industrial, petrochemical, power and transportation projects and infrastructure).

View full profile on MayerBrown.com.

Read more about J. Paul ForresterEmail
Show more Show less
  • Posted in:
    Banking, Finance and Securities
  • Blog:
    Inside Cybersecurity & Privacy Law
  • Organization:
    Mayer Brown

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
  • About LexBlog
  • The Field We Built
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo