Board Report: 2023-SR-B-010 June 26, 2023
We evaluated the Board and Reserve Banks' process for responding to cybersecurity incidents at supervised financial institutions.
We found that guidance documents do not clearly describe the mission or governance structure of the cybersecurity incident response process, leaving some staff unsure of roles and responsibilities. In addition, responses to cybersecurity incidents have not consistently followed the established process, highlighting the need for enhanced training.
Our report includes recommendations to enhance the effectiveness of the Board and Reserve Banks' process for responding to cybersecurity incidents at supervised institutions.