New York, NY and Washington, DC — February 2, 2022 — Axio, a leading SaaS provider of cyber risk management and quantification solutions, today announced a new joint...
In a significant shift for the financial services sector, the Federal Financial Institutions Examination Council (FFIEC) recently announced that its Cybersecurity Assessment Tool (CAT) will be sunset in August 2025. Since 2015, the FFIEC CAT has been a standard tool for financial institutions to assess their cybersecurity risk management practices. This announcement may represent a major change for institutions that commonly use the CAT, but also presents an opportunity. Financial institutions could use this announcement as a catalyst for the adoption of a new framework that enables many benefits beyond self-assessment. Let’s dive into what this announcement means, why it’s happening, and how Axio, in partnership with the Cyber Risk Institute (CRI), can help you more efficiently manage cyber risk in your institution.
The FFIEC notes that the decision to sunset the CAT supports a “whole-of-government” approach aimed at improving security and resilience across critical infrastructure sectors, including financial services. This holistic strategy acknowledges that critical infrastructure operators face many of the same threats and foundational practices can help mitigate systemic risks.
Some factors the FFIEC noted as influencing the CAT’s retirement include the National Institute of Standards and Technology (NIST) releasing the considerably updated version 2.0 of the Cybersecurity Framework (CSF) earlier this year and the Cross-Sector Cybersecurity Performance Goals (CPGs) published by CISA. There is great alignment between the CSF and CPGs and these resources are representative of the whole-of-government approach to addressing the shared risks of critical infrastructure operators.
There are many cybersecurity frameworks and models, but if you’re considering a switch, which one is the right one for you? The FFIEC suggests that financial institutions consider resources “to better address and inform management of continuously evolving cyber security risk,” along with frameworks like:
While the CIS Controls provide a solid foundation for improving general cybersecurity practices, the CRI Profile v2.0 is the benchmark for cybersecurity and resiliency in the financial services industry. The CRI Profile offers several distinct advantages:
While transitioning to a new cybersecurity framework can be resource intensive, the Axio platform can help you make the most of your switch. Axio’s easy-to-use platform enables dynamic and collaborative decision-making. It enables your institution to gain a greater understanding of your cybersecurity posture through assessment, make more informed decisions through cyber risk quantification, and understand how your insurance coverage aligns with your risk exposure.
The Axio Assessment platform can help your institution realize the benefits of adopting the CRI Profile, while adding additional value, such as:
The FFIEC’s decision to sunset the CAT provides financial institutions with an opportunity to carefully evaluate the tools that they are using to manage cyber risks. The powerful combination of the CRI Profile and Axio can help institutions consistently evaluate their operational resilience and navigate an ever-changing threat environment.
Visit CRI’s website if you are a financial institution that is interested in becoming a CRI member. If you’re interested in learning more about how Axio can help you in your adoption of the CRI Profile, visit out FFIEC-CAT Transition Resource Page or fill out the form below speak to one of our cyber risk experts.
New York, NY and Washington, DC — February 2, 2022 — Axio, a leading SaaS provider of cyber risk management and quantification solutions, today announced a new joint...
The financial services sector is facing a major shift as the FFIEC Cybersecurity Assessment Tool (CAT) sunsets on August 31. Thousands of financial institutions...