Banking supervisionUnited States

FFIEC and FDIC Cybersecurity Expectations

Turn banking-sector cybersecurity expectations into continuous managed security and examiner-ready evidence.

View the control mapping

Where we contribute

A managed security layer within a broader compliance program.

FFIEC and FDIC expectations come from laws, regulations, examination handbooks, supervisory procedures, and interagency guidance, rather than one universal control checklist or certification. Network Box can operate and document substantial technical safeguards, while the financial institution remains accountable for its complete, risk-based information-security program.

Incident notification

Reviewed September 2, 2026

The 36-hour notification decision belongs to the bank.

An FDIC-supervised banking organization must notify the FDIC as soon as possible and no later than 36 hours after it determines that a computer-security incident has risen to the level of a notification incident.

Read the FDIC incident-notification rule summary ↗
  • The clock begins with the bank's determination that a qualifying notification incident occurred, not necessarily with the first malicious activity.
  • Network Box can supply rapid detection, escalation, timelines, affected-system information, investigation notes, and containment records.
  • The bank retains the legal determination, notification decision, regulator communication, and related documentation.
  • A covered bank service provider has a separate duty to notify affected bank customers after determining that covered services were materially disrupted or degraded for four or more hours.
  • Customer-information response and notice duties are separate and may also apply to an incident.

Regulatory foundation

Use the sources examiners use, not a retired scorecard.

The applicable agency, charter, activities, technologies, and risk profile determine which requirements and examination procedures apply. These four anchors frame this service mapping.

Legal baseline

12 CFR Part 364, Appendix B

For FDIC-supervised institutions, the interagency guidelines require a written program with suitable administrative, technical, and physical safeguards for customer information.

Examination sources

FFIEC Handbook and FDIC InTREx

The handbook and risk-focused examination procedures help examiners evaluate governance, security, operations, audit, resilience, development, and provider oversight.

Access guidance

Risk-based authentication

FFIEC guidance emphasizes risk assessment, layered security, monitoring, and MFA or controls of equivalent strength when warranted by risk.

Retired tool

No FFIEC CAT mapping

The FFIEC Cybersecurity Assessment Tool was sunset on August 31, 2025. This page intentionally maps to current handbook, regulatory, and supervisory expectations instead.

Legal baseline

Support the Appendix B information-security program.

Appendix B to 12 CFR Part 364 requires an institution's program to include safeguards appropriate to its size, complexity, activities, and customer-information risks. Network Box primarily strengthens the technical and operational portions.

Select a framework area to explore its detailed control mapping.
Framework areaNetwork Box contributionRelevant servicesCoverage
Management reporting, trends, incidents, findings, and service reviews give leadership evidence for oversight.
Security reportingService reviewsIncident summariesVulnerability reports
Supporting
Technical findings and observed activity provide inputs to the institution's enterprise risk assessment.
Vulnerability ManagementThreat intelligenceSIEMNBX: MDR, EDR, XDR24/7 SOC
Partial
Managed preventive, detective, and responsive controls turn selected safeguards into repeatable operations.
UTM+Secure SD-WANSecure Web GatewayWAFManaged Cloud Email SecuritySIEMNBX: MDR, EDR, XDR24/7 SOC
Strong
Service descriptions, responsibilities, performance records, incident provisions, and assurance information support oversight.
Service documentationContractual commitmentsSecurity reportingService reviewsAssurance documentation
Supporting
Threat, vulnerability, incident, service, and architecture changes provide concrete triggers for program improvement.
Threat intelligenceVulnerability reportingIncident lessonsService reviewsChange records
Supporting
Operational metrics and security evidence can be incorporated into institution-led board reporting.
Security reportingRisk trendsIncident summariesOpen findingsService performance
Supporting

These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.

Control mapping

Banking expectations and Network Box support.

This detailed matrix connects managed security operations to current FFIEC handbook and FDIC supervisory themes. Each row separates the Network Box contribution from the institution's continuing responsibility.

Authoritative sourceFFIEC IT Examination Handbook InfoBase ↗
Select a framework area to explore its detailed control mapping.
Framework areaNetwork Box contributionRelevant servicesCoverage
Operational reporting, trends, incident summaries, and open findings support informed oversight.
Security reportingService reviewsIncident summariesVulnerability reportsSIEM dashboards
Supporting
Documented managed services turn selected technical safeguards into repeatable, evidenced operations.
Managed security servicesService documentationManaged configurationsMonitoringSecurity reporting
Partial
Vulnerability, threat, event, architecture, and incident data provide current technical risk inputs.
Vulnerability ManagementSIEMNBX: MDR, EDR, XDRThreat intelligence24/7 SOCSecurity reviews
Partial
Managed inventories and discovery document assets, services, log sources, interfaces, and protected segments in scope.
Managed-device inventoryLog-source inventoryNetwork documentationVulnerability discovery
Partial
Managed enforcement points reduce attack paths and control traffic across locations and trust zones.
UTM+Secure SD-WANFirewallsVPNNetwork segmentationIDS/IPSSecure remote access
Strong
Controlled configurations, restricted administration, managed updates, and change records protect subscribed security services.
UTM+Secure SD-WANSecure Web GatewayWAFManaged Cloud Email SecurityChange records
Partial
Recurring assessment and prioritized findings drive a continuous remediation cycle when subscribed.
Vulnerability ManagementManaged security updatesThreat intelligenceRemediation guidanceSecurity reporting
Partial
Secure remote access, policy enforcement, supported MFA, and access telemetry protect managed entry points.
VPNMFA/TOTP supportDirectory integrationManaged administrative accessFirewall policySIEM
Partial
Centralized telemetry, correlation, alerting, analyst review, and reporting provide continuous visibility.
SIEMNBX: MDR, EDR, XDRManaged-device logging24/7 SOCCorrelationSecurity reporting
Strong
Layered inspection blocks malicious traffic, exploitation, phishing, harmful content, malware, and command-and-control activity.
UTM+FirewallIDS/IPSAnti-malwareSecure Web GatewayManaged Cloud Email SecurityNBX: MDR, EDR, XDR
Strong
WAF, intrusion prevention, monitoring, and vulnerability assessment protect public applications when subscribed.
WAFIDS/IPSVulnerability ManagementSIEMNBX: MDR, EDR, XDR24/7 SOC
Strong
The 24/7 SOC converts subscribed tools and telemetry into an operating detection-and-response capability.
24/7 SOCNBX: MDR, EDR, XDRSIEMThreat intelligenceIncident triageInvestigation
Strong
Investigation, escalation, containment assistance, documentation, and continuing updates support institution-led response.
24/7 SOCSIEMNBX: MDR, EDR, XDRIncident investigationContainment assistanceIncident reporting
Strong
Fast technical facts help the bank evaluate material disruption and meet decision-driven notification timelines.
SOC escalationIncident recordsEvent timelinesImpact informationResponse coordination
Supporting
Continuous monitoring, incident support, configuration records, and restoration of managed controls support resilience.
Managed-service monitoringResilient service optionsConfiguration managementIncident responseService restoration support
Partial
Protected configuration and recovery procedures support restoration of Network Box-managed security functions.
Managed configuration protectionSecurity-service recoveryOperational support
Supporting
Service, security, performance, incident, continuity, and assurance information supports due diligence and monitoring.
Contractual documentationService descriptionsSLAsSecurity reportingService reviewsAssurance documentation
Partial
Education, simulations, administration, and metrics improve workforce recognition of social engineering when subscribed.
Security Awareness TrainingPhishing simulationsCampaign reportsUser metrics
Strong
Operational records provide evidence for audit and examinations but do not replace independent challenge.
SIEM reportsConfiguration recordsChange recordsVulnerability reportsIncident recordsService reviews
Supporting
Segmentation, traffic controls, secure connectivity, inspection, and monitoring protect sensitive data flows.
UTM+VPNNetwork segmentationSecure Web GatewayWAFManaged Cloud Email SecuritySIEMNBX: MDR, EDR, XDR
Partial
Security assessment, WAF, architecture input, controlled service changes, and monitoring support the technology lifecycle.
Vulnerability ManagementWAFManaged change controlSIEMNBX: MDR, EDR, XDRSecurity review input
Partial

These mappings are illustrative and depend on deployment, configuration, service scope, the client environment, and evidence requirements. Strong, Partial, and Supporting describe Network Box's potential contribution, not a compliance conclusion.

Third-party risk

Make the MSP operating model explicit.

The institution, MSP, Network Box, and other material providers should document systems and data in scope; control ownership; administrative access; telemetry handling; service levels; incident contacts and timing; log ownership and retention; vulnerability remediation; continuity testing; subcontractors; assurance information; regulatory cooperation; and termination or transition duties.

Incident readiness

Make the 36-hour decision defensible before an incident.

Regulatory notification is a governance and legal decision supported by technical facts. Detection, decision, escalation, and communication arrangements should be tested instead of improvised under pressure.

01

Named decision authority

Identify who determines whether an event meets the notification-incident definition and who is authorized to contact the regulator.

02

After-hours escalation

Maintain tested contacts and redundant escalation paths between the SOC, MSP, institution, counsel, leadership, and service providers.

03

Decision-time record

Document when facts became sufficient for the bank to determine that a qualifying notification incident occurred and preserve the basis for that decision.

04

Service-impact facts

Quickly establish affected services, duration, customer impact, business-line impact, continuing activity, and likely operational consequences.

05

Provider obligations

Contracts and playbooks should address the separate four-hour service-disruption threshold applicable to covered bank service providers.

06

Separate notice analysis

Evaluate customer-information response, customer notice, law-enforcement, insurer, contractual, and other reporting duties independently.

Assessment evidence

Show that safeguards are operating.

Available evidence depends on deployed services, configured log sources, agreed scope, format, and retention period.

  1. 01Service descriptions, responsibility assignments, and architecture information
  2. 02Managed security device, service, dependency, and log-source inventories
  3. 03Network diagrams and descriptions of protected boundaries and segments
  4. 04Firewall, VPN, SD-WAN, routing, segmentation, web, email, and WAF policies
  5. 05Administrative access and authentication records for managed services
  6. 06Security configuration, approval, maintenance, and change records
  7. 07Centralized logs, log-source health, SIEM searches, dashboards, and reports
  8. 08SOC alerts, analyst investigations, escalation histories, and incident reports
  9. 09Event timelines, affected-system information, indicators, and containment records
  10. 10Vulnerability findings, validation, severity, trends, and remediation recommendations
  11. 11IDS/IPS, malware, phishing, web, email, and application-security events
  12. 12Security-awareness participation and phishing-simulation results
  13. 13Service availability, performance, continuity, and operational-review reports
  14. 14Open findings, remediation status, exceptions, and management recommendations
  15. 15Available independent-assurance and managed-control documentation

Coverage key

What each label means.

Strong

Network Box can directly deliver and operate a substantial part of this technical outcome when the relevant services are in scope.

Partial

Network Box contributes meaningful controls, but the requirement also depends on the client's systems, configuration, people, or processes.

Supporting

Network Box provides useful security operations or evidence, but does not satisfy the requirement by itself.

Client responsibility

This area primarily remains with the MSP and client, their assessors, or other qualified parties.

Shared responsibility

Network Box helps operate the controls. The organization owns the compliance program.

The institution and its board own governance, the written information-security program, enterprise risk assessment, customer-information protection, identity and data governance, business continuity, independent testing, regulatory decisions and notifications, and oversight of every service provider. Outsourcing security operations does not outsource accountability.

FFIEC / FDIC FAQ

Questions about scope, evidence, and responsibility.

What is FFIEC / FDIC?

Turn banking-sector cybersecurity expectations into continuous managed security and examiner-ready evidence.

How can Network Box USA support FFIEC / FDIC?

Network Box USA can operate managed technical safeguards, monitor the subscribed environment, investigate and escalate security activity, maintain managed configurations, and produce service evidence that may support applicable FFIEC / FDIC requirements.

Does using Network Box USA make an organization FFIEC / FDIC compliant?

No. A managed security service can contribute controls, operations, and evidence, but it cannot guarantee compliance or replace the organization's governance, complete scope, legal interpretation, assessment, or formal certification and attestation work.

How should the FFIEC / FDIC control mapping be used?

Use the mapping as a scoping and evidence-planning aid. Each row explains the requirement, the potential Network Box contribution, available evidence, the coverage level, and the work that remains with the organization.

What evidence may be available for a FFIEC / FDIC assessment?

Depending on the deployed services and agreed retention, evidence may include managed configurations, logs, alerts, incident records, vulnerability findings, change records, service reports, and recurring operational reviews. The assessor determines whether evidence is sufficient.

What remains the organization's responsibility under FFIEC / FDIC?

The institution and its board own governance, the written information-security program, enterprise risk assessment, customer-information protection, identity and data governance, business continuity, independent testing, regulatory decisions and notifications, and oversight of every service provider. Outsourcing security operations does not outsource accountability.

Explore another frameworkReturn to the Compliance Center →

Security stack review

Map the technical foundation before the assessment starts.

Request a Security Stack Review