SlideShare a Scribd company logo
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
1
JOIN. ENGAGE. LEAD.
CYBER SECURITY TIPS AND
RESOURCES FOR FINANCIAL
INSTITUTIONS
Managing Risk
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
2
JOIN. ENGAGE. LEAD.
CYBER SECURITY RISK
• Both preparing for and
responding to cyber attacks
increase the cost of doing
business.
• Attacks are increasingly
more sophisticated.
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
3
JOIN. ENGAGE. LEAD.
CYBER SECURITY RISK (CONT.)
Risks come directly through
banking operations and
through third-party providers.
Impacts individual bank and
entire payments system.
Attacks come from
criminals, politically hostile
sources, and insiders.
Data risks are difficult to
control (legacy systems and
manual points in any
process compound the
difficulty of threats).
Cyber Threats
Smaller institutions at most risk.
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
4
JOIN. ENGAGE. LEAD.
MANAGING CYBER SECURITY RISKS
Governance
Vendor management
Threat intelligence
Incident response
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
5
JOIN. ENGAGE. LEAD.
MANAGING CYBER
SECURITY RISK:
GOVERNANCE
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
6
JOIN. ENGAGE. LEAD.
GOVERNANCE
Policies,
Procedures,
& Controls
Assess
risks
Identify
gaps
Update
Test
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
7
JOIN. ENGAGE. LEAD.
MANAGING CYBER
SECURITY RISK:
VENDOR MANAGEMENT
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
8
JOIN. ENGAGE. LEAD.
COMPLIANCE RESPONSIBILITY
Even if your vendor is
responsible for day-to-day
management of certain products
or services, the responsibility
for all compliance
requirements resides with
your institution.
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
9
JOIN. ENGAGE. LEAD.
MONITOR YOUR VENDORS
Monitor your vendors’ performances to
help ensure that your company meets
its long-term strategic goals.
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
10
JOIN. ENGAGE. LEAD.
MULTIPLE FACETS
Be aware that vendor risk management is part of
many operational risk activities, including:
Scenario analysis.
Risk control self-assessments (RCSAs).
Key risk indicators (KRIs).
Information security.
Business continuity planning.
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
11
JOIN. ENGAGE. LEAD.
Regulators have consistently
advised banks to oversee vendors
just as they would any division of
the bank and will hold the bank
accountable for any vendor-
related risk management lapses.
ACCOUNTABILITY
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
12
JOIN. ENGAGE. LEAD.
MANAGING CYBER
SECURITY RISK:
THREAT INTELLIGENCE
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
13
JOIN. ENGAGE. LEAD.
SOURCES OF INTELLIGENCE
Audit reports.
Fraud detection
analysis tools.
BSA/AML
monitoring tools.
Cyber security
services.
U.S. Treasury,
Office of Foreign
Assets Control.
Financial Services
Information and
Sharing Analysis
Center (FS-ISAC).
InfraGard
(a partnership
between the FBI
and the private
sector).
United States
Secret Service:
Electronic Crimes
Task Forces.
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
14
JOIN. ENGAGE. LEAD.
MANAGING CYBER
SECURITY RISK:
INCIDENT RESPONSE
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
15
JOIN. ENGAGE. LEAD.
INCIDENT RESPONSE:
PLAN, PREPARE, AND TEST
Plan & Prepare
• Response policy and plan
prior to incident.
• Quick response guides for
likely incidents.
• Response team leader:
– Designate executive as plan
and response point person
and ensure redundancy.
• Response team:
– Escalates internally
– Notifies externally.
Test
• Train.
• Run simulations routinely.
• Include key stakeholders.
• Fine-tune response
capabilities.
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
16
JOIN. ENGAGE. LEAD.
MANAGING CYBER
SECURITY RISK:
IT RESOURCES
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
17
JOIN. ENGAGE. LEAD.
IT RESOURCES
 FFIEC IT Examination HandBook InfoBase
 Introduction to the FFIEC’s Cybersecurity
Assessment
 Framework for Improving Critical Infrastructure
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
18
JOIN. ENGAGE. LEAD.
Learn more about cyber security through RMA’s
premier publication, The RMA Journal:
http://ebiz.rmahq.org/eBusPPRO/CustomerProfile/
RMAJournalArticleSearch/tabid/393/Default.aspx
Subscribe to The RMA Journal today!
LEARN MORE
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
19
JOIN. ENGAGE. LEAD.
SHARE THIS PRESENTATION
Visit http://www.rmahq.org for information on risk management.
Visit our blog at http://rmablog.rmahq.org/
RMA is a member-driven professional association whose sole
purpose is to advance sound risk principles in the financial services
industry.
RMA helps its members use sound risk principles to improve
institutional performance and financial stability, and enhance the
risk competency of individuals through information, education, peer
sharing, and networking.
Become a member today.

More Related Content

What's hot

Cybersecurity - Webinar Session
Cybersecurity - Webinar SessionCybersecurity - Webinar Session
Cybersecurity - Webinar Session
Kalilur Rahman
 
Cybersecurity Roadmap Development for Executives
Cybersecurity Roadmap Development for ExecutivesCybersecurity Roadmap Development for Executives
Cybersecurity Roadmap Development for Executives
Krist Davood - Principal - CIO
 
Cyber Security PPT - 2023.pptx
Cyber Security PPT - 2023.pptxCyber Security PPT - 2023.pptx
Cyber Security PPT - 2023.pptx
ChandanChandu928137
 
Cyber Security for Financial Institutions
Cyber Security for Financial InstitutionsCyber Security for Financial Institutions
Cyber Security for Financial Institutions
Khawar Nehal khawar.nehal@atrc.net.pk
 
Introduction to Cybersecurity
Introduction to CybersecurityIntroduction to Cybersecurity
Introduction to Cybersecurity
Krutarth Vasavada
 
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
Edureka!
 
Cyber attacks and IT security management in 2025
Cyber attacks and IT security management in 2025Cyber attacks and IT security management in 2025
Cyber attacks and IT security management in 2025
Radar Cyber Security
 
Cybersecurity
CybersecurityCybersecurity
Cybersecurity
Edwin A. Opare
 
Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...
Stephen Cobb
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
PECB
 
What is Social Engineering? An illustrated presentation.
What is Social Engineering?    An illustrated presentation.What is Social Engineering?    An illustrated presentation.
What is Social Engineering? An illustrated presentation.
Pratum
 
Phishing awareness
Phishing awarenessPhishing awareness
Phishing awareness
PhishingBox
 
Threat landscape 4.0
Threat landscape 4.0Threat landscape 4.0
Threat landscape 4.0
Dr. C.V. Suresh Babu
 
Cyber Security Incident Response
Cyber Security Incident ResponseCyber Security Incident Response
Cyber Security Incident Response
PECB
 
Phishing ppt
Phishing pptPhishing ppt
Phishing ppt
shindept123
 
The Importance of Cybersecurity in 2017
The Importance of Cybersecurity in 2017The Importance of Cybersecurity in 2017
The Importance of Cybersecurity in 2017
R-Style Lab
 
CRI Cyber Board Briefing
CRI Cyber Board Briefing CRI Cyber Board Briefing
CRI Cyber Board Briefing
OCTF Industry Engagement
 
Email_Security Gateway.pptx
Email_Security Gateway.pptxEmail_Security Gateway.pptx
Email_Security Gateway.pptx
ssuser651fd4
 
Information security management
Information security managementInformation security management
Information security managementUMaine
 
Phishing Attack Awareness and Prevention
Phishing Attack Awareness and PreventionPhishing Attack Awareness and Prevention
Phishing Attack Awareness and Prevention
sonalikharade3
 

What's hot (20)

Cybersecurity - Webinar Session
Cybersecurity - Webinar SessionCybersecurity - Webinar Session
Cybersecurity - Webinar Session
 
Cybersecurity Roadmap Development for Executives
Cybersecurity Roadmap Development for ExecutivesCybersecurity Roadmap Development for Executives
Cybersecurity Roadmap Development for Executives
 
Cyber Security PPT - 2023.pptx
Cyber Security PPT - 2023.pptxCyber Security PPT - 2023.pptx
Cyber Security PPT - 2023.pptx
 
Cyber Security for Financial Institutions
Cyber Security for Financial InstitutionsCyber Security for Financial Institutions
Cyber Security for Financial Institutions
 
Introduction to Cybersecurity
Introduction to CybersecurityIntroduction to Cybersecurity
Introduction to Cybersecurity
 
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
Cybersecurity Frameworks | NIST Cybersecurity Framework | Cybersecurity Certi...
 
Cyber attacks and IT security management in 2025
Cyber attacks and IT security management in 2025Cyber attacks and IT security management in 2025
Cyber attacks and IT security management in 2025
 
Cybersecurity
CybersecurityCybersecurity
Cybersecurity
 
Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...Cyber Security 101: Training, awareness, strategies for small to medium sized...
Cyber Security 101: Training, awareness, strategies for small to medium sized...
 
Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023Cybersecurity trends - What to expect in 2023
Cybersecurity trends - What to expect in 2023
 
What is Social Engineering? An illustrated presentation.
What is Social Engineering?    An illustrated presentation.What is Social Engineering?    An illustrated presentation.
What is Social Engineering? An illustrated presentation.
 
Phishing awareness
Phishing awarenessPhishing awareness
Phishing awareness
 
Threat landscape 4.0
Threat landscape 4.0Threat landscape 4.0
Threat landscape 4.0
 
Cyber Security Incident Response
Cyber Security Incident ResponseCyber Security Incident Response
Cyber Security Incident Response
 
Phishing ppt
Phishing pptPhishing ppt
Phishing ppt
 
The Importance of Cybersecurity in 2017
The Importance of Cybersecurity in 2017The Importance of Cybersecurity in 2017
The Importance of Cybersecurity in 2017
 
CRI Cyber Board Briefing
CRI Cyber Board Briefing CRI Cyber Board Briefing
CRI Cyber Board Briefing
 
Email_Security Gateway.pptx
Email_Security Gateway.pptxEmail_Security Gateway.pptx
Email_Security Gateway.pptx
 
Information security management
Information security managementInformation security management
Information security management
 
Phishing Attack Awareness and Prevention
Phishing Attack Awareness and PreventionPhishing Attack Awareness and Prevention
Phishing Attack Awareness and Prevention
 

Similar to Cyber Security Tips and Resources for Financial Institutions

How to Measure and Mitigate Conduct Risk
How to Measure and Mitigate Conduct RiskHow to Measure and Mitigate Conduct Risk
How to Measure and Mitigate Conduct Risk
Colleen Beck-Domanico
 
What to Do Before a Cyber Incident Occurs
What to Do Before a Cyber Incident OccursWhat to Do Before a Cyber Incident Occurs
What to Do Before a Cyber Incident Occurs
Colleen Beck-Domanico
 
How to Manage Increasing Data Compliance Issues in Community Banks
How to Manage Increasing Data Compliance Issues in Community BanksHow to Manage Increasing Data Compliance Issues in Community Banks
How to Manage Increasing Data Compliance Issues in Community Banks
Colleen Beck-Domanico
 
10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk Management10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk Management
Colleen Beck-Domanico
 
Key Challenges Facing Vendor Risk Management Programs
Key Challenges Facing Vendor Risk Management ProgramsKey Challenges Facing Vendor Risk Management Programs
Key Challenges Facing Vendor Risk Management Programs
Colleen Beck-Domanico
 
How to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkHow to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management Framework
Colleen Beck-Domanico
 
The Rise and Risks of Lending to Non-Depository Financial Institutions
The Rise and Risks of Lending to Non-Depository Financial InstitutionsThe Rise and Risks of Lending to Non-Depository Financial Institutions
The Rise and Risks of Lending to Non-Depository Financial Institutions
Colleen Beck-Domanico
 
Winning Tactics for Data Governance
Winning Tactics for Data GovernanceWinning Tactics for Data Governance
Winning Tactics for Data Governance
Colleen Beck-Domanico
 
Small Business Lending Outlook
Small Business Lending OutlookSmall Business Lending Outlook
Small Business Lending Outlook
Colleen Beck-Domanico
 
Operational Risk Governance: 5 Core Regulatory Expectations
Operational Risk Governance: 5 Core Regulatory ExpectationsOperational Risk Governance: 5 Core Regulatory Expectations
Operational Risk Governance: 5 Core Regulatory Expectations
Colleen Beck-Domanico
 
How to Instill Ethics in Commercial Lending: Understanding Due Diligence
How to Instill Ethics in Commercial Lending: Understanding Due DiligenceHow to Instill Ethics in Commercial Lending: Understanding Due Diligence
How to Instill Ethics in Commercial Lending: Understanding Due Diligence
Colleen Beck-Domanico
 
10 Components of a Robust Credit Culture
10 Components of a Robust Credit Culture10 Components of a Robust Credit Culture
10 Components of a Robust Credit Culture
Colleen Beck-Domanico
 
The 8 steps of Credit Risk Management
The 8 steps of Credit Risk ManagementThe 8 steps of Credit Risk Management
The 8 steps of Credit Risk Management
Hak Kim
 
The 8 Steps of Credit Risk Management
The 8 Steps of Credit Risk ManagementThe 8 Steps of Credit Risk Management
The 8 Steps of Credit Risk Management
Colleen Beck-Domanico
 
The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...
The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...
The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...
Colleen Beck-Domanico
 
The Top Risks Challenging the Financial Services Industry
The Top Risks Challenging the Financial Services IndustryThe Top Risks Challenging the Financial Services Industry
The Top Risks Challenging the Financial Services Industry
Colleen Beck-Domanico
 
What You Really Need to Know about Commercial Real Estate Underwriting
What You Really Need to Know about Commercial Real Estate UnderwritingWhat You Really Need to Know about Commercial Real Estate Underwriting
What You Really Need to Know about Commercial Real Estate Underwriting
Colleen Beck-Domanico
 
What Skills Will Risk Managers Need in 2028
What Skills Will Risk Managers Need in 2028What Skills Will Risk Managers Need in 2028
What Skills Will Risk Managers Need in 2028
Colleen Beck-Domanico
 
4 Core Capabilities for Building Strong Risk Governance
4 Core Capabilities for Building Strong Risk Governance4 Core Capabilities for Building Strong Risk Governance
4 Core Capabilities for Building Strong Risk Governance
Colleen Beck-Domanico
 
Being a Banker Today: The Changing Role of the Underwriter
Being a Banker Today: The Changing Role of the UnderwriterBeing a Banker Today: The Changing Role of the Underwriter
Being a Banker Today: The Changing Role of the Underwriter
Colleen Beck-Domanico
 

Similar to Cyber Security Tips and Resources for Financial Institutions (20)

How to Measure and Mitigate Conduct Risk
How to Measure and Mitigate Conduct RiskHow to Measure and Mitigate Conduct Risk
How to Measure and Mitigate Conduct Risk
 
What to Do Before a Cyber Incident Occurs
What to Do Before a Cyber Incident OccursWhat to Do Before a Cyber Incident Occurs
What to Do Before a Cyber Incident Occurs
 
How to Manage Increasing Data Compliance Issues in Community Banks
How to Manage Increasing Data Compliance Issues in Community BanksHow to Manage Increasing Data Compliance Issues in Community Banks
How to Manage Increasing Data Compliance Issues in Community Banks
 
10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk Management10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk Management
 
Key Challenges Facing Vendor Risk Management Programs
Key Challenges Facing Vendor Risk Management ProgramsKey Challenges Facing Vendor Risk Management Programs
Key Challenges Facing Vendor Risk Management Programs
 
How to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkHow to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management Framework
 
The Rise and Risks of Lending to Non-Depository Financial Institutions
The Rise and Risks of Lending to Non-Depository Financial InstitutionsThe Rise and Risks of Lending to Non-Depository Financial Institutions
The Rise and Risks of Lending to Non-Depository Financial Institutions
 
Winning Tactics for Data Governance
Winning Tactics for Data GovernanceWinning Tactics for Data Governance
Winning Tactics for Data Governance
 
Small Business Lending Outlook
Small Business Lending OutlookSmall Business Lending Outlook
Small Business Lending Outlook
 
Operational Risk Governance: 5 Core Regulatory Expectations
Operational Risk Governance: 5 Core Regulatory ExpectationsOperational Risk Governance: 5 Core Regulatory Expectations
Operational Risk Governance: 5 Core Regulatory Expectations
 
How to Instill Ethics in Commercial Lending: Understanding Due Diligence
How to Instill Ethics in Commercial Lending: Understanding Due DiligenceHow to Instill Ethics in Commercial Lending: Understanding Due Diligence
How to Instill Ethics in Commercial Lending: Understanding Due Diligence
 
10 Components of a Robust Credit Culture
10 Components of a Robust Credit Culture10 Components of a Robust Credit Culture
10 Components of a Robust Credit Culture
 
The 8 steps of Credit Risk Management
The 8 steps of Credit Risk ManagementThe 8 steps of Credit Risk Management
The 8 steps of Credit Risk Management
 
The 8 Steps of Credit Risk Management
The 8 Steps of Credit Risk ManagementThe 8 Steps of Credit Risk Management
The 8 Steps of Credit Risk Management
 
The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...
The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...
The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...
 
The Top Risks Challenging the Financial Services Industry
The Top Risks Challenging the Financial Services IndustryThe Top Risks Challenging the Financial Services Industry
The Top Risks Challenging the Financial Services Industry
 
What You Really Need to Know about Commercial Real Estate Underwriting
What You Really Need to Know about Commercial Real Estate UnderwritingWhat You Really Need to Know about Commercial Real Estate Underwriting
What You Really Need to Know about Commercial Real Estate Underwriting
 
What Skills Will Risk Managers Need in 2028
What Skills Will Risk Managers Need in 2028What Skills Will Risk Managers Need in 2028
What Skills Will Risk Managers Need in 2028
 
4 Core Capabilities for Building Strong Risk Governance
4 Core Capabilities for Building Strong Risk Governance4 Core Capabilities for Building Strong Risk Governance
4 Core Capabilities for Building Strong Risk Governance
 
Being a Banker Today: The Changing Role of the Underwriter
Being a Banker Today: The Changing Role of the UnderwriterBeing a Banker Today: The Changing Role of the Underwriter
Being a Banker Today: The Changing Role of the Underwriter
 

More from Colleen Beck-Domanico

The RMA COVID-19 Resource Center
The RMA COVID-19 Resource CenterThe RMA COVID-19 Resource Center
The RMA COVID-19 Resource Center
Colleen Beck-Domanico
 
How Modernized Training Is Influencing the Banking Industry
How Modernized Training Is Influencing the Banking IndustryHow Modernized Training Is Influencing the Banking Industry
How Modernized Training Is Influencing the Banking Industry
Colleen Beck-Domanico
 
Recruiting, Developing, and Retaining Risk Talent
Recruiting, Developing, and Retaining Risk TalentRecruiting, Developing, and Retaining Risk Talent
Recruiting, Developing, and Retaining Risk Talent
Colleen Beck-Domanico
 
How will climate change affect financial services?
How will climate change affect financial services?How will climate change affect financial services?
How will climate change affect financial services?
Colleen Beck-Domanico
 
Credit Risk Certification (CRC): 5 Reasons to Up Your Game
Credit Risk Certification (CRC): 5 Reasons to Up Your GameCredit Risk Certification (CRC): 5 Reasons to Up Your Game
Credit Risk Certification (CRC): 5 Reasons to Up Your Game
Colleen Beck-Domanico
 
5 Risks in Commercial Lending
5 Risks in Commercial Lending5 Risks in Commercial Lending
5 Risks in Commercial Lending
Colleen Beck-Domanico
 
Implementing the CECL Standard: 5 Actions to Take Now
Implementing the CECL Standard: 5 Actions to Take Now Implementing the CECL Standard: 5 Actions to Take Now
Implementing the CECL Standard: 5 Actions to Take Now
Colleen Beck-Domanico
 
What is Blockchain and How Can It Change the Game for Financial Institutions?
What is Blockchain and How Can It Change the Game for Financial Institutions?What is Blockchain and How Can It Change the Game for Financial Institutions?
What is Blockchain and How Can It Change the Game for Financial Institutions?
Colleen Beck-Domanico
 
Implementing the New BSA Customer Due Diligence Rule
Implementing the New BSA Customer Due Diligence RuleImplementing the New BSA Customer Due Diligence Rule
Implementing the New BSA Customer Due Diligence Rule
Colleen Beck-Domanico
 
Meeting the Challenge of HMDA Compliance
Meeting the Challenge of HMDA ComplianceMeeting the Challenge of HMDA Compliance
Meeting the Challenge of HMDA Compliance
Colleen Beck-Domanico
 
3 Things You Should Know about Appraisals
3 Things You Should Know about Appraisals3 Things You Should Know about Appraisals
3 Things You Should Know about Appraisals
Colleen Beck-Domanico
 
How to Keep Your Balance as a Risk Manager
How to Keep Your Balance as a Risk ManagerHow to Keep Your Balance as a Risk Manager
How to Keep Your Balance as a Risk Manager
Colleen Beck-Domanico
 
5 Commercial Real Estate (CRE) Challenges in 2017
5 Commercial Real Estate (CRE) Challenges in 20175 Commercial Real Estate (CRE) Challenges in 2017
5 Commercial Real Estate (CRE) Challenges in 2017
Colleen Beck-Domanico
 
8 Risk Management Tips You Need to Know Now
8 Risk Management Tips You Need to Know Now8 Risk Management Tips You Need to Know Now
8 Risk Management Tips You Need to Know Now
Colleen Beck-Domanico
 
A Quick Guide to Credit Considerations in Hospitality Lending
A Quick Guide to Credit Considerations in Hospitality LendingA Quick Guide to Credit Considerations in Hospitality Lending
A Quick Guide to Credit Considerations in Hospitality Lending
Colleen Beck-Domanico
 
How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...
How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...
How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...
Colleen Beck-Domanico
 
A Quick Guide to Credit Considerations in Real Estate Lending
A Quick Guide to Credit Considerations in Real Estate LendingA Quick Guide to Credit Considerations in Real Estate Lending
A Quick Guide to Credit Considerations in Real Estate Lending
Colleen Beck-Domanico
 
How to Lower the Risk Profile of Your Auto Loan Portfolio
How to Lower the Risk Profile of Your Auto Loan PortfolioHow to Lower the Risk Profile of Your Auto Loan Portfolio
How to Lower the Risk Profile of Your Auto Loan Portfolio
Colleen Beck-Domanico
 
8 Things You Need to Know about HELOCs
8 Things You Need to Know about HELOCs8 Things You Need to Know about HELOCs
8 Things You Need to Know about HELOCs
Colleen Beck-Domanico
 
7 Tips to Help You Prepare for CECL
7 Tips to Help You Prepare for CECL7 Tips to Help You Prepare for CECL
7 Tips to Help You Prepare for CECL
Colleen Beck-Domanico
 

More from Colleen Beck-Domanico (20)

The RMA COVID-19 Resource Center
The RMA COVID-19 Resource CenterThe RMA COVID-19 Resource Center
The RMA COVID-19 Resource Center
 
How Modernized Training Is Influencing the Banking Industry
How Modernized Training Is Influencing the Banking IndustryHow Modernized Training Is Influencing the Banking Industry
How Modernized Training Is Influencing the Banking Industry
 
Recruiting, Developing, and Retaining Risk Talent
Recruiting, Developing, and Retaining Risk TalentRecruiting, Developing, and Retaining Risk Talent
Recruiting, Developing, and Retaining Risk Talent
 
How will climate change affect financial services?
How will climate change affect financial services?How will climate change affect financial services?
How will climate change affect financial services?
 
Credit Risk Certification (CRC): 5 Reasons to Up Your Game
Credit Risk Certification (CRC): 5 Reasons to Up Your GameCredit Risk Certification (CRC): 5 Reasons to Up Your Game
Credit Risk Certification (CRC): 5 Reasons to Up Your Game
 
5 Risks in Commercial Lending
5 Risks in Commercial Lending5 Risks in Commercial Lending
5 Risks in Commercial Lending
 
Implementing the CECL Standard: 5 Actions to Take Now
Implementing the CECL Standard: 5 Actions to Take Now Implementing the CECL Standard: 5 Actions to Take Now
Implementing the CECL Standard: 5 Actions to Take Now
 
What is Blockchain and How Can It Change the Game for Financial Institutions?
What is Blockchain and How Can It Change the Game for Financial Institutions?What is Blockchain and How Can It Change the Game for Financial Institutions?
What is Blockchain and How Can It Change the Game for Financial Institutions?
 
Implementing the New BSA Customer Due Diligence Rule
Implementing the New BSA Customer Due Diligence RuleImplementing the New BSA Customer Due Diligence Rule
Implementing the New BSA Customer Due Diligence Rule
 
Meeting the Challenge of HMDA Compliance
Meeting the Challenge of HMDA ComplianceMeeting the Challenge of HMDA Compliance
Meeting the Challenge of HMDA Compliance
 
3 Things You Should Know about Appraisals
3 Things You Should Know about Appraisals3 Things You Should Know about Appraisals
3 Things You Should Know about Appraisals
 
How to Keep Your Balance as a Risk Manager
How to Keep Your Balance as a Risk ManagerHow to Keep Your Balance as a Risk Manager
How to Keep Your Balance as a Risk Manager
 
5 Commercial Real Estate (CRE) Challenges in 2017
5 Commercial Real Estate (CRE) Challenges in 20175 Commercial Real Estate (CRE) Challenges in 2017
5 Commercial Real Estate (CRE) Challenges in 2017
 
8 Risk Management Tips You Need to Know Now
8 Risk Management Tips You Need to Know Now8 Risk Management Tips You Need to Know Now
8 Risk Management Tips You Need to Know Now
 
A Quick Guide to Credit Considerations in Hospitality Lending
A Quick Guide to Credit Considerations in Hospitality LendingA Quick Guide to Credit Considerations in Hospitality Lending
A Quick Guide to Credit Considerations in Hospitality Lending
 
How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...
How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...
How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...
 
A Quick Guide to Credit Considerations in Real Estate Lending
A Quick Guide to Credit Considerations in Real Estate LendingA Quick Guide to Credit Considerations in Real Estate Lending
A Quick Guide to Credit Considerations in Real Estate Lending
 
How to Lower the Risk Profile of Your Auto Loan Portfolio
How to Lower the Risk Profile of Your Auto Loan PortfolioHow to Lower the Risk Profile of Your Auto Loan Portfolio
How to Lower the Risk Profile of Your Auto Loan Portfolio
 
8 Things You Need to Know about HELOCs
8 Things You Need to Know about HELOCs8 Things You Need to Know about HELOCs
8 Things You Need to Know about HELOCs
 
7 Tips to Help You Prepare for CECL
7 Tips to Help You Prepare for CECL7 Tips to Help You Prepare for CECL
7 Tips to Help You Prepare for CECL
 

Recently uploaded

how can I sell pi coins after successfully completing KYC
how can I sell pi coins after successfully completing KYChow can I sell pi coins after successfully completing KYC
how can I sell pi coins after successfully completing KYC
DOT TECH
 
Isios-2024-Professional-Independent-Trustee-Survey.pdf
Isios-2024-Professional-Independent-Trustee-Survey.pdfIsios-2024-Professional-Independent-Trustee-Survey.pdf
Isios-2024-Professional-Independent-Trustee-Survey.pdf
Henry Tapper
 
The secret way to sell pi coins effortlessly.
The secret way to sell pi coins effortlessly.The secret way to sell pi coins effortlessly.
The secret way to sell pi coins effortlessly.
DOT TECH
 
how to sell pi coins at high rate quickly.
how to sell pi coins at high rate quickly.how to sell pi coins at high rate quickly.
how to sell pi coins at high rate quickly.
DOT TECH
 
how can I sell/buy bulk pi coins securely
how can I sell/buy bulk pi coins securelyhow can I sell/buy bulk pi coins securely
how can I sell/buy bulk pi coins securely
DOT TECH
 
What website can I sell pi coins securely.
What website can I sell pi coins securely.What website can I sell pi coins securely.
What website can I sell pi coins securely.
DOT TECH
 
Chương 6. Ancol - phenol - ether (1).pdf
Chương 6. Ancol - phenol - ether (1).pdfChương 6. Ancol - phenol - ether (1).pdf
Chương 6. Ancol - phenol - ether (1).pdf
va2132004
 
一比一原版BCU毕业证伯明翰城市大学毕业证成绩单如何办理
一比一原版BCU毕业证伯明翰城市大学毕业证成绩单如何办理一比一原版BCU毕业证伯明翰城市大学毕业证成绩单如何办理
一比一原版BCU毕业证伯明翰城市大学毕业证成绩单如何办理
ydubwyt
 
BYD SWOT Analysis and In-Depth Insights 2024.pptx
BYD SWOT Analysis and In-Depth Insights 2024.pptxBYD SWOT Analysis and In-Depth Insights 2024.pptx
BYD SWOT Analysis and In-Depth Insights 2024.pptx
mikemetalprod
 
how to sell pi coins in South Korea profitably.
how to sell pi coins in South Korea profitably.how to sell pi coins in South Korea profitably.
how to sell pi coins in South Korea profitably.
DOT TECH
 
Exploring Abhay Bhutada’s Views After Poonawalla Fincorp’s Collaboration With...
Exploring Abhay Bhutada’s Views After Poonawalla Fincorp’s Collaboration With...Exploring Abhay Bhutada’s Views After Poonawalla Fincorp’s Collaboration With...
Exploring Abhay Bhutada’s Views After Poonawalla Fincorp’s Collaboration With...
beulahfernandes8
 
Scope Of Macroeconomics introduction and basic theories
Scope Of Macroeconomics introduction and basic theoriesScope Of Macroeconomics introduction and basic theories
Scope Of Macroeconomics introduction and basic theories
nomankalyar153
 
when will pi network coin be available on crypto exchange.
when will pi network coin be available on crypto exchange.when will pi network coin be available on crypto exchange.
when will pi network coin be available on crypto exchange.
DOT TECH
 
how can i use my minded pi coins I need some funds.
how can i use my minded pi coins I need some funds.how can i use my minded pi coins I need some funds.
how can i use my minded pi coins I need some funds.
DOT TECH
 
Which Crypto to Buy Today for Short-Term in May-June 2024.pdf
Which Crypto to Buy Today for Short-Term in May-June 2024.pdfWhich Crypto to Buy Today for Short-Term in May-June 2024.pdf
Which Crypto to Buy Today for Short-Term in May-June 2024.pdf
Kezex (KZX)
 
how to sell pi coins effectively (from 50 - 100k pi)
how to sell pi coins effectively (from 50 - 100k  pi)how to sell pi coins effectively (from 50 - 100k  pi)
how to sell pi coins effectively (from 50 - 100k pi)
DOT TECH
 
innovative-invoice-discounting-platforms-in-india-empowering-retail-investors...
innovative-invoice-discounting-platforms-in-india-empowering-retail-investors...innovative-invoice-discounting-platforms-in-india-empowering-retail-investors...
innovative-invoice-discounting-platforms-in-india-empowering-retail-investors...
Falcon Invoice Discounting
 
Intro_Economics_ GPresentation Week 4.pptx
Intro_Economics_ GPresentation Week 4.pptxIntro_Economics_ GPresentation Week 4.pptx
Intro_Economics_ GPresentation Week 4.pptx
shetivia
 
USDA Loans in California: A Comprehensive Overview.pptx
USDA Loans in California: A Comprehensive Overview.pptxUSDA Loans in California: A Comprehensive Overview.pptx
USDA Loans in California: A Comprehensive Overview.pptx
marketing367770
 
Poonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit Card
Poonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit CardPoonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit Card
Poonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit Card
nickysharmasucks
 

Recently uploaded (20)

how can I sell pi coins after successfully completing KYC
how can I sell pi coins after successfully completing KYChow can I sell pi coins after successfully completing KYC
how can I sell pi coins after successfully completing KYC
 
Isios-2024-Professional-Independent-Trustee-Survey.pdf
Isios-2024-Professional-Independent-Trustee-Survey.pdfIsios-2024-Professional-Independent-Trustee-Survey.pdf
Isios-2024-Professional-Independent-Trustee-Survey.pdf
 
The secret way to sell pi coins effortlessly.
The secret way to sell pi coins effortlessly.The secret way to sell pi coins effortlessly.
The secret way to sell pi coins effortlessly.
 
how to sell pi coins at high rate quickly.
how to sell pi coins at high rate quickly.how to sell pi coins at high rate quickly.
how to sell pi coins at high rate quickly.
 
how can I sell/buy bulk pi coins securely
how can I sell/buy bulk pi coins securelyhow can I sell/buy bulk pi coins securely
how can I sell/buy bulk pi coins securely
 
What website can I sell pi coins securely.
What website can I sell pi coins securely.What website can I sell pi coins securely.
What website can I sell pi coins securely.
 
Chương 6. Ancol - phenol - ether (1).pdf
Chương 6. Ancol - phenol - ether (1).pdfChương 6. Ancol - phenol - ether (1).pdf
Chương 6. Ancol - phenol - ether (1).pdf
 
一比一原版BCU毕业证伯明翰城市大学毕业证成绩单如何办理
一比一原版BCU毕业证伯明翰城市大学毕业证成绩单如何办理一比一原版BCU毕业证伯明翰城市大学毕业证成绩单如何办理
一比一原版BCU毕业证伯明翰城市大学毕业证成绩单如何办理
 
BYD SWOT Analysis and In-Depth Insights 2024.pptx
BYD SWOT Analysis and In-Depth Insights 2024.pptxBYD SWOT Analysis and In-Depth Insights 2024.pptx
BYD SWOT Analysis and In-Depth Insights 2024.pptx
 
how to sell pi coins in South Korea profitably.
how to sell pi coins in South Korea profitably.how to sell pi coins in South Korea profitably.
how to sell pi coins in South Korea profitably.
 
Exploring Abhay Bhutada’s Views After Poonawalla Fincorp’s Collaboration With...
Exploring Abhay Bhutada’s Views After Poonawalla Fincorp’s Collaboration With...Exploring Abhay Bhutada’s Views After Poonawalla Fincorp’s Collaboration With...
Exploring Abhay Bhutada’s Views After Poonawalla Fincorp’s Collaboration With...
 
Scope Of Macroeconomics introduction and basic theories
Scope Of Macroeconomics introduction and basic theoriesScope Of Macroeconomics introduction and basic theories
Scope Of Macroeconomics introduction and basic theories
 
when will pi network coin be available on crypto exchange.
when will pi network coin be available on crypto exchange.when will pi network coin be available on crypto exchange.
when will pi network coin be available on crypto exchange.
 
how can i use my minded pi coins I need some funds.
how can i use my minded pi coins I need some funds.how can i use my minded pi coins I need some funds.
how can i use my minded pi coins I need some funds.
 
Which Crypto to Buy Today for Short-Term in May-June 2024.pdf
Which Crypto to Buy Today for Short-Term in May-June 2024.pdfWhich Crypto to Buy Today for Short-Term in May-June 2024.pdf
Which Crypto to Buy Today for Short-Term in May-June 2024.pdf
 
how to sell pi coins effectively (from 50 - 100k pi)
how to sell pi coins effectively (from 50 - 100k  pi)how to sell pi coins effectively (from 50 - 100k  pi)
how to sell pi coins effectively (from 50 - 100k pi)
 
innovative-invoice-discounting-platforms-in-india-empowering-retail-investors...
innovative-invoice-discounting-platforms-in-india-empowering-retail-investors...innovative-invoice-discounting-platforms-in-india-empowering-retail-investors...
innovative-invoice-discounting-platforms-in-india-empowering-retail-investors...
 
Intro_Economics_ GPresentation Week 4.pptx
Intro_Economics_ GPresentation Week 4.pptxIntro_Economics_ GPresentation Week 4.pptx
Intro_Economics_ GPresentation Week 4.pptx
 
USDA Loans in California: A Comprehensive Overview.pptx
USDA Loans in California: A Comprehensive Overview.pptxUSDA Loans in California: A Comprehensive Overview.pptx
USDA Loans in California: A Comprehensive Overview.pptx
 
Poonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit Card
Poonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit CardPoonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit Card
Poonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit Card
 

Cyber Security Tips and Resources for Financial Institutions

  • 1. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 1 JOIN. ENGAGE. LEAD. CYBER SECURITY TIPS AND RESOURCES FOR FINANCIAL INSTITUTIONS Managing Risk
  • 2. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 2 JOIN. ENGAGE. LEAD. CYBER SECURITY RISK • Both preparing for and responding to cyber attacks increase the cost of doing business. • Attacks are increasingly more sophisticated.
  • 3. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 3 JOIN. ENGAGE. LEAD. CYBER SECURITY RISK (CONT.) Risks come directly through banking operations and through third-party providers. Impacts individual bank and entire payments system. Attacks come from criminals, politically hostile sources, and insiders. Data risks are difficult to control (legacy systems and manual points in any process compound the difficulty of threats). Cyber Threats Smaller institutions at most risk.
  • 4. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 4 JOIN. ENGAGE. LEAD. MANAGING CYBER SECURITY RISKS Governance Vendor management Threat intelligence Incident response
  • 5. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 5 JOIN. ENGAGE. LEAD. MANAGING CYBER SECURITY RISK: GOVERNANCE
  • 6. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 6 JOIN. ENGAGE. LEAD. GOVERNANCE Policies, Procedures, & Controls Assess risks Identify gaps Update Test
  • 7. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 7 JOIN. ENGAGE. LEAD. MANAGING CYBER SECURITY RISK: VENDOR MANAGEMENT
  • 8. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 8 JOIN. ENGAGE. LEAD. COMPLIANCE RESPONSIBILITY Even if your vendor is responsible for day-to-day management of certain products or services, the responsibility for all compliance requirements resides with your institution.
  • 9. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 9 JOIN. ENGAGE. LEAD. MONITOR YOUR VENDORS Monitor your vendors’ performances to help ensure that your company meets its long-term strategic goals.
  • 10. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 10 JOIN. ENGAGE. LEAD. MULTIPLE FACETS Be aware that vendor risk management is part of many operational risk activities, including: Scenario analysis. Risk control self-assessments (RCSAs). Key risk indicators (KRIs). Information security. Business continuity planning.
  • 11. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 11 JOIN. ENGAGE. LEAD. Regulators have consistently advised banks to oversee vendors just as they would any division of the bank and will hold the bank accountable for any vendor- related risk management lapses. ACCOUNTABILITY
  • 12. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 12 JOIN. ENGAGE. LEAD. MANAGING CYBER SECURITY RISK: THREAT INTELLIGENCE
  • 13. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 13 JOIN. ENGAGE. LEAD. SOURCES OF INTELLIGENCE Audit reports. Fraud detection analysis tools. BSA/AML monitoring tools. Cyber security services. U.S. Treasury, Office of Foreign Assets Control. Financial Services Information and Sharing Analysis Center (FS-ISAC). InfraGard (a partnership between the FBI and the private sector). United States Secret Service: Electronic Crimes Task Forces.
  • 14. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 14 JOIN. ENGAGE. LEAD. MANAGING CYBER SECURITY RISK: INCIDENT RESPONSE
  • 15. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 15 JOIN. ENGAGE. LEAD. INCIDENT RESPONSE: PLAN, PREPARE, AND TEST Plan & Prepare • Response policy and plan prior to incident. • Quick response guides for likely incidents. • Response team leader: – Designate executive as plan and response point person and ensure redundancy. • Response team: – Escalates internally – Notifies externally. Test • Train. • Run simulations routinely. • Include key stakeholders. • Fine-tune response capabilities.
  • 16. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 16 JOIN. ENGAGE. LEAD. MANAGING CYBER SECURITY RISK: IT RESOURCES
  • 17. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 17 JOIN. ENGAGE. LEAD. IT RESOURCES  FFIEC IT Examination HandBook InfoBase  Introduction to the FFIEC’s Cybersecurity Assessment  Framework for Improving Critical Infrastructure
  • 18. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 18 JOIN. ENGAGE. LEAD. Learn more about cyber security through RMA’s premier publication, The RMA Journal: http://ebiz.rmahq.org/eBusPPRO/CustomerProfile/ RMAJournalArticleSearch/tabid/393/Default.aspx Subscribe to The RMA Journal today! LEARN MORE
  • 19. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 19 JOIN. ENGAGE. LEAD. SHARE THIS PRESENTATION Visit http://www.rmahq.org for information on risk management. Visit our blog at http://rmablog.rmahq.org/ RMA is a member-driven professional association whose sole purpose is to advance sound risk principles in the financial services industry. RMA helps its members use sound risk principles to improve institutional performance and financial stability, and enhance the risk competency of individuals through information, education, peer sharing, and networking. Become a member today.