• Home
  • Education
  • News and Resources
  • Advocacy
  • Associate Members
  • Contact
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
News
News, Resources

Is Your MSP Helping You Meet Evolving Regulatory Priorities? It Should Be.

By Jeff Olejnik 

The cybersecurity threat landscape is constantly evolving. And while the FFIEC Cybersecurity Assessment Tool (CAT) provides a reference for the controls required based on your inherent risk profile, the reality is that it hasn’t been updated since May 2017 — and a lot has changed since then.  

To protect your financial institution, it’s essential to stay informed about developments in the cyberthreat landscape and the latest regulatory priorities.  

The OCC identified regulatory priorities for cybersecurity and operations in its Fiscal Year 2024 Bank Supervision Operating Plan, highlighting key areas, including incident response, data recovery and operational resilience.   

Most financial institutions use a managed service provider (MSP) to help provide IT and security support. They can also help address the talent shortage gap by accessing specialized expertise at a lower cost.  

However, your choice of MSP is also critical for helping your organization meet regulatory priorities. The right MSP can help you respond to regulatory and cyberthreat updates, while inferior service can introduce operational risk and compliance concerns.   

Here are six areas where your MSP security services should be helping you meet regulatory priorities and mitigate risk: 

  1. Incident response

Establishing and regularly rehearsing your incident response plan is a crucial part of addressing cyberattacks.  

When a cybersecurity incident occurs, the immediate reaction is to take steps to fix the situation — often by rebuilding the workstation or server that was compromised. However, these actions can delete all evidence, making it nearly impossible to conduct a forensic investigation.   

Your MSP should be aware of its role in your incident response plan as an active partner in retaining evidence of an attack. Help ensure that your MSP is informed and willing to participate in helping you identify and act on opportunities to gather evidence or work with your digital forensic team during an incident.  

  1. Data recovery 

Testing is vital to maintaining an effective business continuity plan program. In addition to monitoring your backup system, your MSP should be helping you perform monthly file-level recovery tests and annual full recovery tests. 

Make sure to also provide your MSP with recovery time objectives and recovery point objectives (RTO and RPO) for the systems and applications they support and that the recovery strategy meets your requirements.   

And if you’re uncertain of what your RTO and RPO should be, consider working with an MSP or a business continuity planning specialist who can help you develop or improve your business impact analysis.  

  1. Operational resilience

Your MSP should be supporting your vulnerability management program, including periodic vulnerability scanning, patching and updating computers and network devices to help ensure known vulnerabilities are addressed — even for non-Microsoft applications (e.g. Adobe, Flash). Additionally, your MSP should be assisting you with IT asset management, including replacing deprecated, end-of-life equipment so that it doesn’t introduce security vulnerabilities. 

  1. Cybersecurity risks

Work with an MSP who can provide managed advanced endpoint detection and response (EDR). 

Traditional antivirus software checks files and programs to see if they’re “bad” based on a list it has. Advanced EDR watches everything happening on your device. It looks for how programs and files behave, allowing you to quickly detect and isolate ransomware and other malware before it infects other computers, minimizing the damage.   

Your MSP should be using both to keep your institution safe.  

  1. Unauthorized authentication and access

A quality MSP can assist you with authentication and access controls. Their support should include multifactor authentication implementation, regular removal of users who are no longer within your organization and monthly reports identifying dormant accounts.  

You also need to be aware of how your MSP accesses your network and systems.  

One of the baseline requirements in the FFIEC CAT includes encrypted connections and multifactor authentication for contractors and third parties. MSPs service many clients, and this baseline requirement is commonly not met. In fact, many MSPs share passwords among employees or even use the same administrator password to provide convenient access to multiple clients. This practice, however, introduces risk to your institution.   

  1. Third- and fourth-party risks 

As a third-party provider, your MSP should ensure that their own security practices are helping keep your institution safe. However, many providers commit to practices that may expose you to operational risk.  

During your vendor due diligence process, make sure you not only understand your MSP’s controls, but also those of your MSP’s vendors, such as cloud service, data backup and remote monitoring and management providers. Kaseya and SolarWinds are examples of how fourth parties used by MSPs led to breaches of the MSP’s clients.  

A new and rising threat vector is your vendors’ use of AI. Your vendor due diligence needs to include questions about how AI is used, what data is shared and how your security and privacy are protected with the large language models used by your MSP. 

How Wipfli can help  

Wipfli’s MSP services bring industry-specific experience and cybersecurity know-how to help make your institution more efficient and secure. We understand the complex regulatory environment and unique business operations financial institutions face, making us capable of providing you with the targeted support you need.    

Our MSP services can do more to protect your financial institution. Contact us today to learn how. 

Print 🖨
June 11, 2024/by Katie Reiser
Tags: Associate Members, Cybersecurity
Share this entry
  • Share on Facebook
  • Share on X
  • Share on WhatsApp
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
https://www.wisbank.com/wp-content/uploads/2021/09/Triangle-Backgrounds_Lime-Green.jpg 972 1921 Katie Reiser https://www.wisbank.com/wp-content/uploads/2021/09/Wisconsin-Bankers-Association-logo.svg Katie Reiser2024-06-11 06:56:242024-06-11 06:56:24Is Your MSP Helping You Meet Evolving Regulatory Priorities? It Should Be.
You might also like
Silhouettes of Business People Working in Board Room Announcing the 2022 Bank Executives Conference
Guarding the Vault: Strategies for Banks to Combat Ransomware Threats
Row of digital locks with glowing lock in middle Time to Gear Up for First-Quarter Reporting Requirements
Network of lines and dots marked with numbers and locks Executive Letter: Protecting Your Bank from a Cyberattack
Hooded figure typing on laptop surrounded by strings of binary code See Into the Mind of a Cybercriminal
Cybersecurity Without the Checklist: Adapting to the CAT’s Sunset
5 Signs You’ve Outgrown Your MSP Services
Row of digital locks with glowing lock in middle Ensuring the Safety and Security of Wisconsin Communities
Search Search

Categories

  • Advocacy
  • Community
  • Compliance
  • Credit Unions
  • Education
  • Member News
  • News
  • Products
  • Resources
  • Uncategorized

Recent Posts

  • Asset Builders Holds Annual Finance and Investment Challenge Bowl State Championship
  • Steve Lonigro New Director of Retail Banking at Fox Valley Area Bank
  • Spring Bank Supports WBA Power of Community Week
  • Horicon Bank Expands With Hiring of Nicholas Hiltz as Mortgage Lender
  • Executive Letter: More Advocacy in Action

Archives

  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • December 2020
  • November 2020
  • October 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • May 2019
  • April 2019
  • March 2019
  • November 2018
  • September 2018
  • August 2018
  • June 2018
  • April 2018
  • March 2018
  • January 2018
  • November 2017
  • October 2017
  • September 2017
  • May 2017
  • April 2017
  • December 2016
  • November 2016
  • August 2016
Wisconsin Bankers Association logo
  • About
  • Community
  • Subsidiaries
  • Staff

questions@wisbank.com

608-441-1200

4721 S Biltmore Ln.
Madison, WI 53718

Get our Newsletter!
Subscribe

© 2025 Wisconsin Bankers Association. All rights reserved. | Website Design by Bizzy Bizzy
Link to: Cinnaire Closes $175 Million Equity Fund to Provide Affordable Housing in Midwest Link to: Cinnaire Closes $175 Million Equity Fund to Provide Affordable Housing in Midwest Cinnaire Closes $175 Million Equity Fund to Provide Affordable Housing in M... Link to: DeBauche Receives WBA Lifetime Service Award Link to: DeBauche Receives WBA Lifetime Service Award DeBauche Receives WBA Lifetime Service Award
Scroll to top Scroll to top Scroll to top

This site uses cookies. By continuing to browse the site, you are agreeing to our use of cookies.

OKLearn more×

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Terms of Use
Accept settingsHide notification only

Subscribe

* indicates required








Membership