logo
These tools can help financial institutions better manage their cybersecurity risks

These tools can help financial institutions better manage their cybersecurity risks

On Sept. 5, 2024, the Federal Financial Institutions Examination Council (FFIEC) announced it would sunset its Cybersecurity Assessment Tool (CAT) on Aug. 31, 2025. CAT was released in June 2015 as a voluntary assessment tool to help financial institutions identify their risks and determine their cybersecurity preparedness. Although the current controls addressed in the CAT are sound cybersecurity practices, the FFIEC notes that the decision to sunset arose from new and updated government and industry resources that financial institutions can use to better manage cybersecurity risks.
As a result, financial institutions will need to adopt a new framework to assess their cybersecurity environment. The FFIEC does not explicitly endorse the use of any tool and mentions the use of industry-developed resources, including — but not limited to — the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0, the Center for Internet Security (CIS) Critical Security Controls, and Cyber Risk Institute's (CRI) Cyber Profile (the Profile).
The NIST CSF 2.0 provides guidance to organizations of all sizes and sectors to manage cybersecurity risks. It is organized around six core functions — govern, identify, protect, detect, respond and recover — that result in 108 controls. These functions offer a comprehensive approach to understanding, assessing, prioritizing, and communicating cybersecurity efforts. The framework does not prescribe specific actions but links to resources that provide additional guidance on practices and controls to help achieve desired outcomes. This flexibility allows organizations to tailor the framework to their unique needs and maturity levels.
The CIS Critical Security Controls are a set of best practices designed to help organizations improve their cybersecurity posture. These controls are prescriptive, prioritized, and simplified, making them accessible and actionable for organizations of all sizes. The latest version, CIS Controls v8.1, includes 18 top-level controls, each with specific safeguards to address various aspects of cybersecurity.
The CRI Profile was created through public and private collaboration, pulling from global regulations and cybersecurity standards, such as the International Standards Organization and NIST CSF. The Profile's framework of 318 diagnostic statements for financial institutions to rely on is based on more than 2,500 regulatory, official guidance and other supervisory provisions worldwide. The number of diagnostic statements to comply with depends on your impact on the global, national, sector, or local market if a cybersecurity event substantially impacted you. The CRI provides nine questions to help you determine which of four tiers your organization is in.
In addition, the CRI Profile provides a mapping to the CAT, which can allow your institution to begin to transfer over your current framework into the CAT. However, the CRI Profile to the CAT is not a one-to-one transfer, and the items that are mapped up do not have the same language as the CAT and will require further assessment. Organizations utilizing this framework that want to transfer over the mapped items should be cognizant that the requirements of CAT can be insufficient for today's landscape. The items transferred over can be a great starting point, but it is important to review the new language and identify any additional gaps that need to be addressed to help ensure you are complying with the CRI Profile.
While the FFIEC does not endorse the use of one framework over another, of the recommended frameworks the FFIEC recommends as a replacement for CAT, only the CRI Profile was specifically curated for financial institutions, has a direct mapping to the CAT for an easier transition, and the scope of the framework is customized based on your impact score.
While the CAT is not set to retire until Aug. 31, 2025, it's important to begin planning your transition as soon as possible to decide which framework best suits your organization's needs; determine resources needed to complete the migration, including time and monetary; and identify potential control gaps that will need to be addressed.
If your organization needs assistance migrating to any of these new frameworks, please contact a professional at Forvis Mazars.
Forvis Mazars, LLP is an independent member of Forvis Mazars Global, a leading global professional services network. Ranked among the largest public accounting firms in the United States, the firm's 7,000 dedicated team members provide an Unmatched Client Experience® through the delivery of assurance, tax, and consulting services for clients in all 50 states and internationally through the global network.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

TSA Announces Big Change at Seattle-Tacoma International Airport
TSA Announces Big Change at Seattle-Tacoma International Airport

Yahoo

time21 hours ago

  • Yahoo

TSA Announces Big Change at Seattle-Tacoma International Airport

Over the past several months the Transportation Security Administration has been rolling out new technology to screen passengers before their travels. One of the busiest airports in the United States will be seeing that upgrade this month. On June 5 the TSA announced a new security checkpoint located at the south end of the terminal on the arrivals level at Seattle-Tacoma International Airport. The new checkpoint is designed to screen up to 750 passengers per hour. "It will be open daily 4 a.m. to 8 p.m. This is the first checkpoint on the baggage claim level as part of innovative designs in a space constrained terminal. This will provide a new option for travelers for convenience as well as additional queuing and re-composure space to improve the customer experience," the TSA said in a statement. The security administration revealed what passengers can expect when encountering the latest version of Credential Authentication Technology (CAT-2). "A TSA officer will scan the passenger's photo identification and a camera will capture a real-time photo of the passenger. CAT-2 uses facial matching technology to compare the features on the photo ID against the in-person, real-time photo," the TSA said. "Once the unit confirms a match, a TSA officer verifies it and the traveler can proceed to security screening. TSA officers can perform additional passenger verification if needed. Through a secure Internet connection, the units also verify that an individual is ticketed for air travel, negating the need to show a boarding pass." The TSA also revealed photos captured by the new equipment are "never stored or used for any other purpose than immediate identity verification." Travelers who don't want to participate in the facial matching process have the option to opt Announces Big Change at Seattle-Tacoma International Airport first appeared on Men's Journal on Jun 6, 2025

Hundreds Attend 2025 Drone Rodeo at Constellis Advisors & Training
Hundreds Attend 2025 Drone Rodeo at Constellis Advisors & Training

Yahoo

timea day ago

  • Yahoo

Hundreds Attend 2025 Drone Rodeo at Constellis Advisors & Training

MOYOCK, N.C., June 6, 2025 /PRNewswire/ -- Constellis successfully hosted its 2025 Drone Rodeo at the Constellis Advisors & Training (CAT) facility in Moyock, NC, drawing more than 300 attendees and 30 participating vendors. The event featured live demonstrations including First Person View (FPV) systems, Dropper and Close Air Support, Demining, Toxic Suppression techniques, Drone Parachute deployments, and Integrated Tactical Response scenarios. Held on CAT's expansive 3,600-acre campus, the Drone Rodeo continues to serve as a premier forum for showcasing applied technology in real-world mission environments. Attendees from government and commercial sectors engaged directly with innovators in aerial systems, sensor integration, and mission support operations. "We're proud to see this event grow in scale and operational mission importance, and to utilize our unique CAT facility to foster partnerships and innovation," said Andrew Hartsog, Executive Vice President of Mission Support Services. "This year's Rodeo demonstrated not just technological evolution, but real collaboration between operators, engineers, and mission planners addressing today's toughest security challenges." Constellis will continue collaborating with the special operations, law enforcement, and national security communities at its upcoming Tactical Expo Day, scheduled for September 4, 2025, also at the CAT facility. For more information and to register, visit About Constellis Constellis provides end-to-end training, risk management, and comprehensive security solutions to safeguard people and infrastructure. Operating globally and based in Herndon, Virginia, our employees bring unparalleled dedication and passion for creating a safer world while upholding the highest standards of compliance, quality, and integrity. Constellis' solutions include logistics and life support, technical services, contingency operations, UAV and counter UAV services, advanced training, K-9, emergency response, fleet maintenance, construction, background investigations, and tailored unique capabilities to support a wide variety of mission requirements. At Constellis, our number one priority is securing customers' success. View original content to download multimedia: SOURCE Constellis Sign in to access your portfolio

Liongard Advances Proactive Cybersecurity with Acquisition of Darklight's AI-Powered Vulnerability Prioritization Platform
Liongard Advances Proactive Cybersecurity with Acquisition of Darklight's AI-Powered Vulnerability Prioritization Platform

Business Wire

timea day ago

  • Business Wire

Liongard Advances Proactive Cybersecurity with Acquisition of Darklight's AI-Powered Vulnerability Prioritization Platform

HOUSTON--(BUSINESS WIRE)-- Liongard, the global leader in Attack Surface Management (ASM), today announced the acquisition of the Darklight Cyio platform, an AI-powered cyber risk solution that applies real-time threat intelligence and business context to risk prioritization. 'This is a transformational step in our vision to help partners see more, understand what matters, and act faster. We're combining AI and context to protect every layer with precision,' said Michelle Accardi, CEO of Liongard. Darklight Cyio is a strong strategic fit, enhancing Liongard's platform capabilities and strengthening its value proposition for customers and partners. The transaction is accretive, aligns with the company's growth strategy, contributes positively to earnings, and supports Liongard's commitment to maintaining a strong financial foundation. 'We're confident this transaction positions us well for sustained success,' said Mayank Singhvi, Chief Financial Officer at Liongard. 'This acquisition supports our strategy to grow with purpose by expanding our platform intelligently, maintaining financial discipline, and delivering long-term value to our stakeholders.' With the acquisition of Darklight Cyio, Liongard significantly enhances its ability to provide partners with a unified, intelligence-driven approach to proactive cybersecurity. By integrating continuous risk analysis, contextual threat prioritization, and stakeholder-ready reporting into the Liongard platform, partners gain the ability to identify, assess, and act on cyber risks with greater precision and speed. 'Our vision has always been to help MSPs see everything, know what's changing, and act faster,' said Michelle Accardi, CEO of Liongard. 'With Darklight Cyio now part of Liongard, we're delivering on that vision in a transformational way by applying AI and business context so our partners can secure every layer of their environment with confidence.' Key Benefits for Liongard Partners Contextual Risk Prioritization Real-time threat intelligence aligned with business-critical systems to reduce noise and focus remediation efforts. Always-On Risk Scoring Continuous risk assessments that evolve as new threat intelligence is ingested, keeping your security posture current. Business-Aligned Vulnerability Insights Go beyond CVEs by evaluating vulnerabilities based on their impact to confidentiality, integrity, and availability. Custom Reporting for Every Audience Easily generate reports aligned to NIST, FedRAMP, and other standards for technicians, CISOs, and executive stakeholders. Deeper ASM Through Contextual Intelligence Amplify Liongard's core ASM capabilities with actionable insight into where vulnerabilities exist, what they mean, and how to respond. 'We're seeing a wave of consolidation across the cybersecurity and IT management landscape, especially in platforms serving MSPs and MSSPs,' said Jay McBain, Chief Analyst at Canalys. 'Liongard's acquisition of Darklight's Cyio platform represents the kind of strategic investment that not only strengthens its core offering but also positions the company as a frontrunner in delivering intelligent, risk-based automation and visibility to partners managing thousands of end customers.' This acquisition underscores Liongard's commitment to empowering IT and security professionals with automation, intelligence, and visibility that extend beyond the endpoint. It marks a bold step forward in enabling a proactive approach to cyber risk across today's complex digital ecosystems. Contact us to learn more: About Liongard: Liongard is redefining Attack Surface Management with an intelligent, AI-powered platform built for modern IT and security operations. Trusted by MSPs, MSSPs, and IT providers to protect over 70,000 end customers, Liongard delivers unified visibility across users, systems, networks, and cloud environments. With over 85 integrations, Liongard empowers teams to uncover hidden risks, enforce cybersecurity posture, and automate the actions that matter most. By combining deep asset intelligence with real-time insight and scalable remediation, Liongard fuels cyber resilience, operational efficiency, and sustainable growth. For more information, visit

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store