When I first entered the banking world, user access reviews were much more straightforward. Spreadsheets were used to capture the basics of who had network and core application access. There was a page in each employee’s file listing the keys and codes they had, and...
Finosec Tools and Resources to Empower You and Your Team
Finosec BlogTopics
Get notified on new insights from Finosec now!
Be the first to know about new Finosec blogs to grow your knowledge of the cybersecurity governance industry today!Resources for:
Financial Institutions
The Hidden Risks of Shadow IT: Why Community Banks Need a Detailed System Inventory
In the world of community banking, the landscape of information security and cyber risk management has dramatically evolved. Gone are the days when all servers were in-house, and every application installation involved the IT department. Today, it’s easier than ever for a Compliance Officer to sign off on a new software tool to manage Reg DD challenges or for a Loan Officer to adopt a cloud solution to improve customer acceptance rates.
Embracing AI: A Quick Start Guide for Community Financial Institutions
Recently, I had the privilege of speaking to a group of bankers at the ICBA Live conference. When I asked who was using AI, only a few hands went up. Then I asked how many had policies forbidding AI usage, and several more hands were raised. This brought us to an interesting realization: those banks were inadvertently in violation of their own policies. AI isn’t new—it’s been enhancing our industry for years, especially in cybersecurity and fraud detection.
Integrating FFIEC Authentication Guidance: A Blueprint for Your Next Exam With Insights from Recent Regulatory Actions
The Federal Financial Institutions Examination Council (FFIEC) Authentication Guidance update in August 2021 has marked a significant step towards enhancing authentication and security access measures within financial institutions. This update expanded upon previous handbooks from 2005 and 2011, emphasizing a broader scope that now includes employees, third-party vendors, and system-to-system communications via APIs.
Understanding R-SAT v2.0 – A Practical Guide for Information Security Officers: Part 3 of a 3 Part Series
Fostering a Culture of Security Through Education and Oversight As we wrap up our informative series based on the R-SAT v2.0 insights, we highlight not only the tactical applications of cybersecurity but also the strategic importance of cultivating a robust security...
Understanding R-SAT v2.0 – A Practical Guide for Information Security Officers: Part 2 of a 3 Part Series
Introduction: Streamlining Data Management in Cybersecurity Continuing our initial discussion in the 3-part series from the R-SAT v2.0, we turn to the core of data protection: data management. As an Information Security Officer, your role is pivotal in safeguarding...
Understanding R-SAT v2.0 – A Practical Guide for Information Security Officers: Part 1 of a 3 Part Series
Welcome to the first installment of our in-depth three-part series, building upon our November 14th webinar on the new Ransomware Self-Assessment tool (R-SAT v2.0). The new R-SAT was released by the Conference of State Bank Supervisors in mid/late October.
Discovering Possibilities and Building Connections: A Recap of Jack Henry Connect 2023
Jack Henry Connect 2023 was a testament to the power of community, innovation, and the endless possibilities when technology meets banking. Read our blog to learn more about our experience at the event last month.
Navigating the Ransomware Minefield: Key Takeaways from the CSBS Report on Financial Institutions & R-SAT 2.0
A new version of the Ransomware Self-Assessment Tool (R-SAT v2.0) was published for banks to help mitigate new risks associated with ransomware attacks and identify security gaps. Learn more about these changes in our blog and how Finosec’s Governance 360 platform can help.