<img src="https://ws.zoominfo.com/pixel/pIUYSip8PKsGpxhxzC1V" width="1" height="1" style="display: none;">
Are You Making This Common Vendor Management Mistake Observed by the FDIC?

Are You Making This Common Vendor Management Mistake Observed by the FDIC?

FIs aren’t doing enough to ensure their contracts with third-party vendors sufficiently address business continuity and incident response.

Apr 10, 2019 2 min read
3 Tips for Avoiding an Equifax-Style Breach

3 Tips for Avoiding an Equifax-Style Breach

When one of the nation’s largest credit reporting companies reports a breach involving the private financial data of over 145 million Americans, people

Mar 27, 2019 4 min read
Why Vendor Cyber Monitoring Matters

Why Vendor Cyber Monitoring Matters

No matter how strong a financial institution’s own cyber defenses are, it’s really only as strong as its weakest vendor.

Mar 21, 2019 2 min read
Risk Management: Knowing When It’s Time to Start Again

Risk Management: Knowing When It’s Time to Start Again

How can you tell if a risk management program needs to be totally reinvented? The benefits of a complete overhaul can often outweigh the inconvenience.

Mar 12, 2019 2 min read
How to Discover Vendor Cybersecurity Flaws Before Data Thieves Exploit Them

How to Discover Vendor Cybersecurity Flaws Before Data Thieves Exploit Them

How do you know if a cybersecurity rating is covering all the bases? Make sure it monitors these key areas...

Mar 8, 2019 2 min read
GAO & OCC Disagree Over Risk Management

GAO & OCC Disagree Over Risk Management

Have you felt like an examiner, auditor, or other reviewer just didn’t get you, your bank, or a program/business line? The OCC can relate.

Mar 1, 2019 4 min read
3 Tips for Avoiding UDAAP Violations

3 Tips for Avoiding UDAAP Violations

If you've ever wondered how to avoid unfair, deceptive, or abusive acts or practices, this post is for you! You'll see three great tips to help you...

Feb 25, 2019 3 min read
Is the Absence of Risk Stunting the Next Generation of Risk Managers?

Is the Absence of Risk Stunting the Next Generation of Risk Managers?

If we don’t give children the opportunity to encounter reasonable, relatively low-stakes risk, how will they be prepared for risk at the enterprise level?

Feb 22, 2019 3 min read
UDAAP Compliance: Defining Unfair, Deceptive, & Abusive Acts and Practices

UDAAP Compliance: Defining Unfair, Deceptive, & Abusive Acts and Practices

Get clear definitions for each of the key terms involved in UDAAP compliance, including how to define unfair, deceptive, and abusive acts and practices!

Feb 20, 2019 5 min read
Celebrating Abraham Lincoln's Banking Legacy: A Podcast

Celebrating Abraham Lincoln's Banking Legacy: A Podcast

In honor of Abraham Lincoln's birthday and President's Day, enjoy this podcast from ABA Banking Journal celebrating Lincoln's banking impact...

Feb 15, 2019 1 min read
Training Risk Management Heroes, Part 1: Banking on the Frontline

Training Risk Management Heroes, Part 1: Banking on the Frontline

Frontline staff at FIs are trained to protect both the institution and its customers by identifying fishy transactions, but staff are capable of going

Feb 14, 2019 3 min read
The Bad Guys Keep Getting Smarter. Let’s Hope Financial Institutions and Vendors Can Keep Pace.

The Bad Guys Keep Getting Smarter. Let’s Hope Financial Institutions and Vendors Can Keep Pace.

Cyber criminals are growing increasingly clever.Just consider what happened to Tampa Bay Credit Union recently...

Feb 8, 2019 1 min read
Fintech Update: Agencies Encourage Increased Regulator Oversight of Third Parties, but Will Anything Happen?

Fintech Update: Agencies Encourage Increased Regulator Oversight of Third Parties, but Will Anything Happen?

Increased risk exposure from third-party providers poses threats to the entire financial system, and banking regulatory agencies should have the ability

Feb 5, 2019 4 min read
Third-Party Management of Cloud Computing

Third-Party Management of Cloud Computing

While 'the cloud' may seem mysterious to the layperson, there shouldn’t be anything secretive about your third-party vendors’ cloud use. If your vendor

Jan 30, 2019 3 min read
2019 Risk Outlook: Concentration Risk

2019 Risk Outlook: Concentration Risk

Concentration risk is most commonly associated with lending. Looking ahead, the New York Fed is warning of a different kind of concentration risk

Jan 28, 2019 2 min read
Is Apple Pay a Vendor?

Is Apple Pay a Vendor?

Apple Pay is not a direct vendor. This raises an interesting question. Should financial institutions (FI) using Apple Pay have to review Apple as a vendor?

Jan 25, 2019 2 min read
NCUA Eyes Economic Environment, Change Management & Third-Party Risk With 2019 Supervisory Priorities

NCUA Eyes Economic Environment, Change Management & Third-Party Risk With 2019 Supervisory Priorities

The NCUA has made adjustments to its Supervisory Priorities for 2019 - emphasizing controlling risks, including a new focus on third-party risk management.

Jan 23, 2019 2 min read
The Top 8 Internal Cybersecurity Vulnerabilities Challenging Financial Institutions

The Top 8 Internal Cybersecurity Vulnerabilities Challenging Financial Institutions

Internal vulnerabilities are the aspects of cybersecurity that your institution has direct control over. The eight most significant internal vulnerabilitie

Jan 16, 2019 2 min read
How the Government Shutdown is Affecting Regulatory Agencies

How the Government Shutdown is Affecting Regulatory Agencies

The partial government shutdown has furloughed workers at the national parks, the Smithsonian museums, the IRS, courts, and other federal institutions, but

Jan 10, 2019 2 min read
Your Vendor Talks Risk Management Talk, but Does It Walk the Walk?

Your Vendor Talks Risk Management Talk, but Does It Walk the Walk?

The words “manage, mitigate, and reduce risk” from a third-party vendor are music to the ears of a risk manager. Unfortunately, talk is cheap—and legal

Jan 9, 2019 2 min read
Inside the Life of an Information Security Officer

Inside the Life of an Information Security Officer

What’s it like to be the information security officer at a $1.5 billion-asset community bank? We chatted with one to learn more about the challenges ISO

Jan 2, 2019 4 min read
Turf Battles and Low Morale Can Increase Risk. Just ask FinCEN.

Turf Battles and Low Morale Can Increase Risk. Just ask FinCEN.

FinCEN’s issues are just a small part of the fascinating story about how Russia tried to use backdoor channels to infiltrate Treasury. It’s also a story

Dec 26, 2018 3 min read
Holiday Gift to Bankers: Regulators Slap Down Fintech Bank Wannabe

Holiday Gift to Bankers: Regulators Slap Down Fintech Bank Wannabe

The Robin Hood of legend is known for being above the law. Fintech firm Robinhood is learning that it is not.

Dec 20, 2018 2 min read
Yule Shoot Your Eye Out: Classic Holiday Movie Characters That Underestimated Risk

Yule Shoot Your Eye Out: Classic Holiday Movie Characters That Underestimated Risk

These classic films let us enjoy a bit of nostalgia and give us a break from the holiday rush, but do they have anything to teach us about risk? I’d say ye

Dec 19, 2018 4 min read
Business Continuity

Business Continuity

Business continuity means planning for major disruptions in a company so that the company can continue operations.

Dec 19, 2018 1 min read
What Asset-Based Risk Assessments Get Wrong

What Asset-Based Risk Assessments Get Wrong

Wouldn’t it be nice to reduce risk management to a simple checklist? That’s the thinking behind asset-based risk management - but this idea has more flash

Dec 13, 2018 4 min read
RPO - Recovery Point Objective

RPO - Recovery Point Objective

RPO is otherwise known as Recovery Point Objective and refers to the age of files that must be recovered from backup storage for normal operations to

Dec 13, 2018 1 min read
Findings on Findings on Findings: Guess Whose Audit Uncovered Over 2,000 Findings?

Findings on Findings on Findings: Guess Whose Audit Uncovered Over 2,000 Findings?

If you think tracking findings is challenging, try being the Pentagon. The Department of Defense underwent its first-ever full financial audit - the resuls

Dec 11, 2018 2 min read
Examiners Will Be Focusing on Your Institution’s Riskiest Areas. Do You Know What They Are?

Examiners Will Be Focusing on Your Institution’s Riskiest Areas. Do You Know What They Are?

In the FFIEC Press Release, dated 11/27/2018, the FFIEC provided a more formal idea of what a “risk-based exam” looks like and the factors that will help

Dec 7, 2018 2 min read
You Got SOC Questions? We Got SOC Answers!

You Got SOC Questions? We Got SOC Answers!

Did you ask a question during our live broadcast of How to Leverage SOC and SSAE 18 Reports Throughout Every Department of Your Financial Institution?

Dec 3, 2018 3 min read