2025-02-28
The South Dakota Division of Banking issued this memo to state-chartered banks and trust companies urging immediate implementation of fundamental cyber hygiene controls to mitigate escalating ransomware and state-sponsored threats. The regulator requires institutions to maintain comprehensive asset inventories, robust vulnerability and patch management programs, phishing-resistant multi-factor authentication, and effective third-party risk management frameworks. Additionally, the memo mandates the maintenance of secure backups, centralized logging, incident response plans, and the utilization of free CISA cyber hygiene services to enhance detection and resilience.