Â
Learning Objectives:
-
Explain the key cybersecurity frameworks relevant to banking.
-
Understand the transition from the FFIEC CAT to new frameworks.
-
Compare different frameworks and their suitability for different institutions.
2.1 The Importance of Cybersecurity Frameworks
Cybersecurity frameworks provide a structured approach to assessing and managing cyber risk. They offer standardised controls, best practices, and maturity models that help financial institutions align their security posture with regulatory expectations and industry standards. Frameworks serve as a common language for communicating cyber risk to boards, regulators, and stakeholders.
2.2 Key Cybersecurity Frameworks
The FFIEC Cybersecurity Assessment Tool (CAT) provided a standardised approach to assessing cybersecurity maturity across the financial sector for nearly a decade. With its retirement in August 2025, institutions must now choose among several frameworks . Key frameworks include:
National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF):Â Widely adopted, flexible, and the foundation for other frameworks. It provides a common language for managing cybersecurity risk.
Cyber Risk Institute (CRI) Profile:Â Aligns NIST with banking regulations. It offers a cloud profile extension and is the most detailed option, directly mapping to FFIEC handbooks .
Center for Internet Security (CIS) Critical Security Controls:Â Provides prioritisation and specific control descriptions. It offers a clear path from foundational to advanced controls.
Cybersecurity and Infrastructure Security Agency (CISA) Cross-Sector Cybersecurity Performance Goals (CPG):Â A short listing designed to prioritise cost, impact, and complexity ratings.
2.3 Selecting the Right Framework
Framework selection should be guided by the institution’s size, complexity, and risk appetite . The key isn’t to chase the perfect framework but to select one that aligns with the institution’s risk profile, resources, and strategic goals. Some frameworks are highly prescriptive while others are more flexible. The right choice depends on the institution’s risk culture and management style. Regulators expect annual self-assessments of the cybersecurity control environment, and management should be able to explain which framework was chosen, why it was chosen, and how it aligns with the bank’s risks and strategic vision .
.