- First, none of this activity should come as a surprise to financial institutions. The cybercrime problem continues to worsen, as we all see played out in the media every day, and the need to ensure that our nation’s critical infrastructure is hardened can’t be delayed.
- Second, with approximately 13,000 banks and credit unions, the U.S. financial sector has a wide, varied, and potentially-exposed attack surface. These mentions of cybersecurity are simply the next step in the natural evolution of how regulators handle such threats and concerns when dealing with such an exposed segment of the US economy that finds itself under increasingly sophisticated attacks.
- Third, financial institutions would be wise to assume that cybersecurity will become increasingly regulated; in addition, they should begin to plan a strategy that includes “cyber” in their already full plate of compliance initiatives. And while this change perhaps won’t happen overnight, financial institutions should in the meantime ensure that they have a logical risk management framework in place that guides and comprehensively covers the requisite people, processes, and technology that are needed to mitigate cyber-threats.
OpRisk & Cyber Threats: As Interconnected as Ever
July 1st, 2014
Actimize FMC Product Team, Financial Markets Compliance

The Office of the Comptroller of the Currency (OCC), the Federal Financial Institutions Examination Council (FFIEC), and a number of other important bodies have recently highlighted the importance of increasing diligence against cyber threats.As the FFIEC launched its cybersecurity assessment pilot program, other organizations called for more knowledge-sharing. But it is the heightened focus on banking institutions’ operational risk that brought these protection strategies up to a whole new level. In fact, it was the OCC that was among the first to publicly describe the critical nature of cyber threats last year, as major factors threatening financial institutions’ operational risks. It is worth noting that hints of this appeared as early as May 2012 in remarks made by the OCC’s head, Comptroller Thomas J. Curry.What does all the dialogue coming out of the OCC and other regulatory bodies really mean?