Regulated industry service

Financial Institution Cybersecurity Readiness Review

Know where you stand against NCUA, the FFIEC and GLBA before the examiner asks. An advisory readiness review delivered by executive-level security leadership, with reporting your board can act on and remediation you can track.

This is an assessment and readiness service. A Readiness Score is an advisory measure prepared by My CISO Partner; it is not a Regulatory Compliance Determination, which only your cognizant regulator or examiner makes.

What the service is

A structured readiness review against the regulations that govern your institution.

We take NCUA's information security programme rule, the FFIEC IT Examination Handbook's own booklets, and the GLBA Safeguards Rule, express them as an assessable control library with their citations preserved, and work through every applicable control with your team: what the requirement asks, what you have in place, what evidences it, where the gaps are, how serious they are, and what closes them.

  • One versioned framework mapped across your governing regulators, so a rule change becomes a new edition and your historical results stay exactly as they were assessed.
  • Every control keeps its regulatory reference. Requirement statements are plain-English summaries for audit planning; the regulations control.
  • A readiness score that distinguishes compliance status, risk severity, regulatory importance, evidence sufficiency and remediation status — with the calculation shown, never a bare percentage.
  • Regulatory changes from NCUA, the FDIC, the OCC, the Federal Reserve and the CFPB are tracked as they publish, so a new rule or guidance document shows up against your framework, not after your next exam.
Who it is for

Institutions that answer to a federal or state regulator — or their examiners.

Credit unions

Federally insured credit unions preparing for an NCUA examination or working through Part 748's Appendix A/B information security programme requirements.

Community & regional banks

Banks preparing for an FFIEC-aligned IT examination, working from the Information Security, Business Continuity, or Architecture, Infrastructure and Operations booklets.

Non-bank lenders & fintechs

Mortgage companies, finance companies and fintech partners whose GLBA Safeguards Rule obligations sit with the FTC rather than a banking regulator.

Leadership and counsel

CEOs, boards, general counsel and chief compliance officers who need the position stated in plain language, with the basis for every statement.

Problems it solves

The gaps that surface at the exam table are the expensive ones.

No single picture

NCUA, FFIEC and GLBA obligations live with different owners and different binders. Nobody can say, on one page, where the programme stands.

Evidence that cannot be produced

A control is "in place" until an examiner asks for the record. Every control here carries what an examiner examines, what was received, and when it expires.

Findings without owners

Gaps noted in a report and never closed. Every finding has a rating, an owner, a date, a remediation plan and a validation step, and closed findings cannot be quietly edited.

Regulatory change tracked nowhere

A proposed rule or new guidance from a prudential regulator publishes, and it takes a manual scan to notice — or nobody does. Changes are logged against your framework as they publish.

Boards asking the wrong question

"Are we compliant?" is the examiner's determination to make. "Where are we not ready, and what are we doing about it?" is answerable, and it is what the executive dashboard answers.

Vendor & third-party risk

Core processors, cloud providers and other service providers carry real GLBA and FFIEC obligations; the review scopes third-party oversight rather than treating it as someone else's control.

Review methodology

Ten stages, one traceable chain.

From the first conversation to the executive report, every stage leaves a record you can follow back: framework → domain → requirement → control → evidence → assessment → finding → remediation.

ClientAssessmentScopeControl reviewEvidenceAssessmentFindingsRisk ratingRemediationExecutive report
  • Scope is set from your charter type, primary regulator, asset size and third-party footprint — frameworks that do not apply are recorded as out of scope with the reason, not silently dropped.
  • Each control is recorded as Compliant, Partially Compliant, Non-Compliant, Not Applicable or Not Assessed — the assessor's vocabulary, not a verdict on the institution — with evidence requested, received and rated for sufficiency.
  • The readiness score weights each control by its regulatory significance, discounts it by evidence sufficiency, deducts for unresolved critical and high findings, and caps its band when coverage is low. The weighting is configuration, and every step is shown.
  • Issued results are frozen. A final assessment cannot be edited or reopened; a changed position is a new assessment, so history is never rewritten.
Areas assessed

Cross-mapped to the frameworks that actually govern you.

Information Security Programme

Board oversight, risk assessment, and programme governance — NCUA Part 748 Appendix A, and the FFIEC Information Security booklet.

Access & Identity Controls

Authentication, authorization and privileged access — FFIEC Information Security and Architecture, Infrastructure and Operations booklets.

Business Continuity & Resilience

Continuity planning, testing and recovery objectives — the FFIEC Business Continuity Management booklet.

Third-Party & Vendor Management

Oversight of core processors, cloud providers and other service providers — the FFIEC Outsourcing Technology Services booklet and the GLBA Safeguards Rule's service-provider requirement.

Audit & Independent Testing

Independent review of the information security programme — the FFIEC Audit booklet and NCUA Part 748's annual testing requirement.

Development, Acquisition & Change

Secure development, change management and system acquisition — the FFIEC Development, Acquisition and Maintenance booklet.

Management & Governance

IT governance, strategic alignment and resourcing — the FFIEC Management booklet.

GLBA Safeguards Rule

The FTC's written information security programme requirements — designated qualified individual, risk assessment, encryption, MFA, incident response and service-provider oversight — 16 CFR Part 314.

Deliverables

What you receive.

  • A scoped, control-by-control assessment record with regulatory references preserved.
  • An evidence register: every request, version, review decision, validity period and expiry, with an access ledger.
  • A findings register with rating, priority, owner, due date, root cause, business and regulatory impact, and a remediation plan per finding.
  • The Readiness Score with its domain breakdown and the full calculation.
  • An examiner-ready executive report — purpose and basis, scope, score, readiness by domain, priority findings, evidence position, remediation plan, limitations — and board briefing content.
  • A client portal that shows assessment status, the released findings and remediation plan, outstanding evidence, tracked regulatory changes and delivered reports.
Executive reporting

Written for the people who decide.

One dashboard for the CEO, the board, the CIO and CISO, general counsel and the compliance officer: overall readiness, critical and high findings, overdue remediation, evidence gaps, domains at risk and assessment completion — with drill-down from the headline to the control, the finding, the evidence and the action. Every number is a recorded fact; the summary says what it is built from.

Remediation support

Findings that get closed, not filed.

Each finding carries a remediation plan with actions, owners, dates, milestones and a validation step. Progress, overdue items and aging are visible to leadership; closure needs a reviewer and closure evidence; a closed finding can only be reopened with a stated, recorded reason.

Fractional CISO support

Ownership after the review.

Readiness is not a one-time exercise. Our Fractional CISO service carries the programme forward: owning the remediation plan, keeping evidence current, preparing leadership for examinations, and re-assessing as the rules and your institution change.

FAQ

Questions, answered directly.

No. It is an advisory readiness review. The readiness score describes the state of preparation as observed by the assessors; only your cognizant regulator or examiner determines compliance. Nothing in the reports states that an institution is, or is not, in compliance with any regulation, and the platform is built so that it cannot say so by accident.

NCUA Part 748's information security programme requirements for credit unions, the FFIEC IT Examination Handbook's booklets that banking examiners actually work from, and the GLBA Safeguards Rule for institutions whose Safeguards obligations sit with the FTC. Scope is set from your charter type and primary regulator, so only what applies to you is assessed.

We monitor the Federal Register and the relevant agencies — NCUA, the FDIC, the OCC, the Federal Reserve and the CFPB — for proposed rules, final rules, amendments and guidance, and log matching changes against your framework as they publish. Your executive dashboard and portal show what changed and what it affects; nothing is silently missed between reviews.

Named, senior consultants perform the review and make every judgement. An AI assistant can be enabled per engagement, by an administrator with a stated basis, to answer questions against your institution's own assessment, evidence, controls, risks and remediation plan — always citing the underlying record, and always labelled AI GENERATED — HUMAN REVIEW REQUIRED. It cannot change a status, close a finding or make any determination.

Start with the free assessment.

A short, scored assessment tells us where your programme stands today. A consultant follows up to scope the full readiness review.

Start the Free Readiness AssessmentSpeak with a Financial Institution Security Advisor