Federal Financial Institutions Examination Council (FFIEC) members are taking various measures to raise awareness among financial institutions and their critical third-party service providers regarding cybersecurity risks and the need to identify, assess, and mitigate these risks considering the increasing volume and sophistication of cyber threats.
Increasingly, financial institutions rely on information technology and telecommunications to deliver services to consumers and business. Disruption, degradation, or unauthorized alteration of information and systems that support these services can affect operations, institutions, and their core processes, and undermine confidence in the nation's financial services sector.
Since June 2013, the FFIEC’s Cybersecurity and Critical Infrastructure Working Group has been working to enhance communication among its member agencies and build on existing efforts to strengthen other interagency and private sector group activities. The FFIEC also began assessing and enhancing the state of the industry preparedness and identifying gaps in the regulators' examination procedures and training that can be closed to strengthen the oversight of cybersecurity readiness.
The National Institute of Standards and Technology defines cybersecurity as "the process of protecting information by preventing, detecting, and responding to attacks." To that end, institutions should consider management of internal and external threats and vulnerabilities to protect information assets and the supporting infrastructure from technology-based attacks.
The following resources can help financial institution leaders understand supervisory expectations, increase awareness of cybersecurity risks, and assess and mitigate the risks facing their institutions.
FFIEC Resources
- CAT Sunset Statement, August 2024 (PDF)
- FFIEC Authentication and Access to Financial Institution Services and Systems Guidance, August 2021 (PDF)
- FFIEC Statement on Security in a Cloud Computing Environment, April 2020(PDF)
- FFIEC Joint Statement – Office of Foreign Assets Control Cyber-Related Sanctions Program Risk Management, 2019(PDF)
- Cybersecurity of Interbank Messaging and Wholesale Payment Networks, June 2016 (PDF)
- FFIEC Statement on Destructive Malware, March 2015 (PDF)
- FFIEC Statement on Compromising Credentials, March 2015 (PDF)
- FFIEC IT Examination Handbook InfoBase
May 7, 2014 - Webinar: Executive Leadership of Cybersecurity: What Today's CEOs Need to Know About the Threats They Don't See.
View Slides | View Video
Exercise Program Resources
- Federal Deposit Insurance Corporation’s Cyber Challenge
- FS-ISAC Global Events/Cyber-Attack Against Payment Systems (CAPS) Exercise
- CISA Exercises | CISA
Other Resources
- Center for Internet Security Controls
- Financial Services Information Sharing and Analysis Center
- FBI InfraGard
- National Credit Union Administration’s Cyber Security Resources Page
- CRI Profile at The Profile – Cyber Risk Institute
- NIST Cybersecurity Framework
- Cybersecurity and Infrastructure Security Agency
- USSS Cyber Investigations
- Stop Ransomware Campaign at Stop Ransomware | CISA