American Financial Services Association - Cybersecurity Assessment Tool provides response readiness reaches
Member login
American Financial Services Association

Cybersecurity Assessment Tool provides response readiness reaches

Blog Posts

If your company responds to market forces and security incidents with cat-like reflexes, chances are you may already have performed a self-assessment using something like the Federal Financial Institutions Examination Council’s Cybersecurity Assessment Tool (“CAT”).

The average cyber breach costs a company about $4 million with the cost per record estimated at $150 each, says Chris Couch, a cybersecurity expert with McGlinchey Stafford.

Couch, speaking at AFSA’s Law and Compliance Symposium last week, continued AFSA’s series of presentations on the CAT, which offers a framework that “non IT pros” can follow to assess a company’s current risk and identify opportunities to improve cybersecurity preparedness.

This session focused on the inherent risk assessment portion of the CAT. Couch explained the importance of measuring risk and outlined the CAT’s methodology including assessing the profile of the company, its policies and procedures, and its current exposure to technology risks.

Couch discussed elements of the CAT like knowing the number of internet providers your company has; whether or not your IT system is hosted internally or by third parties; if your company allows access from wireless devices; if it uses cloud services for data storage; if it allows access from personal devices like Apple and or Android; and if it requires dual factor authorization.

“Know your company’s delivery channels,” he said. “For example: are they online or mobile or both; what is the number of daily transactions; does it provide payment services; debit card access; or allow ACH payments?”

He says if companies perform an internal risk assessment, they would fall into one of the following five categories of risk.

· Least inherent: no technology and a small geographic footprint

· Minimal inherent: limited technology and systems outsources

· Moderate inherent: some complex technology and outsourced critical systems

· Significant inherent: complex use of technology and high-risk products such as accepting mobile payments and offering services directly

· High level inherent risk: cross-border transactions; in-house developed technology; lots of third-party access to company systems.

“To do this effectively, you must bring together all of the relevant stakeholders,” Couch said. “Identify the networks, the device details and the status of third parties and how they access the institutional systems.”

The final presentation in this series, which will cover the CAT’s measurement of Cybersecurity Maturity, is planned for a meeting later in 2019. In addition to the deep dive into the CAT, AFSA has presented several other sessions on cybersecurity issues in an ongoing effort to share information on this critical issue.

Cybersecurity Assessment Tool provides response readiness reaches
Mar 12, 2019

If your company responds to market forces and security incidents with cat-like reflexes, chances are you may already have performed a self-assessment using something like the Federal Financial Institutions Examination Council’s… Read the rest

Companies need to assess the risk of using social media to reach customers
Mar 07, 2019

With 73 percent of adults using more than one social media platform, banks and financial services companies are looking at social media as an efficient way to reach consumers. Navigating the compliance risks of social media was one of many … Read the rest

AFSA Comments on CFPB Debt Collection Survey
Mar 06, 2019

On March 6, AFSA commented on a proposed CFPB survey. The survey asks for consumers’ experience with debt collection and feedback on proposed disclosure forms. The CFPB first issued its request for approval in June 2017, then again … Read the rest

MoneySKILL® article published in Rebound Magazine
Mar 05, 2019

Just in time for March Madness, the AFSA Education Foundation was able to secure a full-page article in Rebound Magazine – a publication about basketball players for basketball players and their fans. This opportunity came through… Read the rest

Stay Relevant with Digital Technology
Mar 04, 2019

Join us on March 14, 2019, at 2 p.m. ET for Instant Funding through Push Payment Technology, presented by REPAY.

In today’s fast-paced and highly digital world, it’s important for lenders to stay relevant by offering flexible… Read the rest

Vehicle Finance Industry meeting Demand for credit by U.S. consumers
Feb 28, 2019

Notwithstanding press reports to the contrary, thoughtful review of data about the state of vehicle finance demonstrates that the market has grown in recent years with continued participation across the credit spectrum. The vehicle finance… Read the rest

Registration Opportunities Available for AFSAEF’s Management Development Programs
Feb 26, 2019

Each year since the mid-1980s, the AFSA Education Foundation offers two important enrichment programs for employees of member companies. The first program is THE EDGE, an acronym for Education, Development, Growth, and Enrichment. Designed… Read the rest

Stay Relevant with Digital Technology
Feb 25, 2019

Join us on March 14, 2019 at 2 p.m. ET for Instant Funding through Push Payment Technology, presented by REPAY.

In today’s fast-paced and highly digital world, it’s important for lenders to stay relevant by offering flexible … Read the rest

Welcome New Members
Feb 21, 2019

AFSA would like to welcome the following new members to the association:

CU Direct connects more than 16,000 car dealerships to 1100 credit unions for auto loan application, transmission and funding. CU Direct provides full circle lending… Read the rest

AFSA Meets with FCC to discuss status of TCPA
Feb 21, 2019

AFSA staff and other trade associations met with the Federal Communications Commission (FCC) this week and last week to discuss the Telephone Consumer Protection Act (TCPA).

The group of trades met with staff from the FCC’s Consumer… Read the rest

1 130 131 132 133 134 135 136 137 138 139 140 150