The Bedel Security Blog

What Strong Cybersecurity Governance Looks Like At a Community Bank

Written by Brian Petzold | Sep 4, 2026

There is no such thing as a perfect cybersecurity program, as the threat landscape changes so quickly that new attack methods can appear overnight. But a strong cybersecurity governance program helps a bank identify emerging threats quickly and prevent, detect, or respond to them before they cause real damage. Examiners understand this, so they will often spend much of their time looking at the governance program rather than at individual controls. But what are they looking for? What can a bank do to more effectively govern cybersecurity risk?

It starts with the board and senior management. Regulators want to see that management and the board have adequate cyber literacy to ask real questions and that the annual GLBA report provides an accurate picture of the institution's cybersecurity strengths and weaknesses. They will look at minutes for real discussion of the program, at what ongoing training is provided, and at what decisions have been made to proactively correct deficiencies. They will also expect an accountable Information Security Officer with genuine independence from IT operations, so that the person building the controls is not the same one attesting that they work.

Policy alignment with the information security program is also important. Board policies must clearly define risk tolerances and assign responsibilities for cybersecurity risk discussion, monitoring, remediation, and risk acceptance. The information security program must align and clearly implement these policies across the organization.

The risk assessment and third-party management program get close scrutiny, both for whether they are current and for whether they are used to identify gaps and drive decision-making. Special attention goes to how new products, vendors, and systems are assessed prior to purchase. For third-party management specifically, banks should expect questions about how the program adheres to the 2023 interagency guidance from the OCC, Federal Reserve, and FDIC.

Testing of the incident response and business continuity plans will also be reviewed, with an emphasis on whether they are exercised realistically and whether they direct the required notifications internally and externally when an incident occurs.

Metrics are where a lot of otherwise capable programs quietly fail. Volume reporting - emails blocked, alerts triaged, patches pushed - tells a board almost nothing, and regulators have gotten good at recognizing it. What they want is anything that shows direction and residual risk: mean time to remediate critical findings, the trend in phishing failure rates, the percentage of endpoints out of compliance, and the number of risk acceptances sitting past their review date. Banks that can demonstrate in committee and board minutes that these are regularly reviewed and trigger actions will likely receive better ratings.

That last measure points directly to the risk register. Regulators want to see that the institution has one and that it is regularly reviewed and discussed. The register should include items identified in exams, audits, risk assessments, testing, and internal discussions, and should track decisions to accept, remediate, or eliminate risk.

For banks and credit unions that are still struggling with cybersecurity governance, one place to begin is with an assessment based on an accepted industry framework (NIST CSF 2.0, CISA Performance Goals, etc.). This has become more pressing since the FFIEC retired the Cybersecurity Assessment Tool at the end of August 2025, leaving institutions that relied on it without a framework. When performed properly and with honesty, these assessments will help to identify where an Information Security Program is weakest. If you need help with this, Bedel Security can work with you to perform a NIST CSF 2.0 assessment using our CySPOT® CSF+ Assessment. Contact us to learn more!