Information &
Cyber Security Program.
The written spine of the program. We author it, keep it current with FFIEC expectations, and make sure what's on paper matches what actually happens in the bank.
- InfoSec Policy
- Acceptable Use
- Business Impact Analysis
- Business Continuity Plan
- Disaster Recovery Plan
- Internet Banking
- Incident Response Plan
- Vendor Management
- CATO
- Charters
A live picture of the risk surface, not a spreadsheet that gets dusted off before an exam. Risk is tracked, rated against appetite, and reported on a cycle.
- IT Risk Assessment
- Risk Tracking
- End of Life Assets
- Vendor Risk Assessment
- 3rd Party Audit Scope
- Risk Appetite & Tolerance
- CAT Tool
- Identity and Access Management
- Red Flag Risk Assessment
Where the year gets decided. Strategic plans, scope, and a controls project plan with hardware and software mapped to dates and dollars.
- Strategic Plans
- Information / Cyber Security Scope
- IT Controls Project Plan
- Hardware
- Software
- Implementation Docs
- Project Status Reports
The evidence an examiner asks for, ready before they ask. Topology, data flows, and system documentation kept current rather than reconstructed.
- Overview Docs
- Network Topology
- Data Flow Diagrams
- Pictures
- Software
- ISPD
Program training built for two different rooms — a board that needs to govern it, and staff who need to live it. Plus education you can pass to customers.
- Program training for the board
- Employee security training
- Customer education
The unglamorous monthly work that keeps everything else true: patches applied, renewals tracked, changes documented, servers hardened.
- Proactive Monthly Maintenance
- Change MGMT Docs
- Renewals
- Upgrades
- Troubleshooting
- Server Security
- Admin & Maintenance
Eyes on the network around the clock. SIEM, endpoint threat protection, firewall and patch posture, asset monitoring, and FS-ISAC intelligence.
- SIEM
- Endpoint Threat Protection
- Firewall
- Patch Management
- Change Management
- Asset Monitoring
- FS-ISAC
- Backup
The plans you hope never to run, pressure-tested before you need them. We test the recovery, the response, and the people.
- Disaster Recovery Plan
- Business Continuity Plan
- Incident Response Plan
- High Availability
- Social engineering testing
- Battery, phone, and HA server
A standing internal review of the whole program — our own audit of our own work, so nothing drifts between the third-party audit and the exam.
- Internal Information / Cyber Security Program Review
We prepare the file, sit in the room, and answer the questions. Third-party audit and the regulator exam, both managed end to end.
- InfoSec Program Audit — 3rd party
- Regulators Exam
Where it all lands. Steering committee cadence, minutes that hold up, and a board report written to be understood rather than filed.
- IT Steering Committee meetings
- Agendas and minutes
- Board report
- InfoSec program status