2026-03-09

Added · Updated

Cyber Alert: The Fundamentals of Cyber Hygiene for Financial Institutions

The Texas Department of Banking shares the Conference of State Bank Supervisors' Cyber Hygiene Fundamentals for Financial Institutions Guide, which consolidates ten previously distributed fact sheets and board question documents into a single resource. This publication does not introduce new regulatory requirements but amplifies key controls from existing guidance to encourage increased oversight by senior management and Boards of Directors. It highlights six critical threats—ransomware, denial-of-service attacks, third-party risks, geopolitical and hacktivist activities, social engineering and phishing, and corporate account takeover—and recommends that CEOs share this information with CISOs and IT security personnel.

Texas Department of Banking logo

Texas

Texas Department of Banking

Click to view thumbnail

Media Contact: media@dob.texas.gov INDUSTRY NOTICE 2026-02 Date: March 9, 2026 The Fundamentals of Cyber Hygiene for Financial Institutions Today’s cyber threats evolve rapidly, requiring constant attention to protect your institution and its customers from potentially devastating consequences. Recent geopolitical events continue to elevate the risk of cybersecurity threats, and the expanding use of artificial intelligence (AI) also increases the risk of new cybersecurity attacks, including AI-enhanced malware attacks. Despite these changing threats, we find that fundamental cyber hygiene practices are the single most important measure for protecting institutions. Focusing on the fundamentals, to get them implemented as correctly as possible, is critical. The Department of Banking (Department) is sharing the following guide prepared by the Conference of State Bank Supervisors (CSBS) that provides a single, all-in-one resource on cybersecurity fundamentals. The Cyber Hygiene Fundamentals for Financial Institutions Guide contains ten cyber hygiene fact sheets and board questions documents previously distributed by CSBS. The guide provides a fundamental overview of how each of these controls and practices are critical to protecting institutions against existing and emerging cyber threats. This resource supplements the two notices the Department released in 2025, provided along with other Information Technology Resources available on the Department's website. The guide highlights six critical threats to be aware of, including cyber threats such as: • Ransomware • Denial-of-service attacks (Dos/DDoS) • Third-party risks • Geopolitical and hacktivist activities • Social engineering and phishing • Corporate account takeover The guide is not intended to introduce new guidance but rather to spotlight and amplify key controls from existing regulatory guidance and other authoritative sources, as well as encourage increased oversight by senior management and the Board on these controls. CEOs and senior management staff should also share the information with CISOs and IT security personnel.

IN 2026-02 March 9, 2026 2 2601 N. Lamar Blvd., Austin, Texas 78705 www.dob.texas.gov Board of Director Resources The Department recognizes the value of providing resources to Board members as well. CSBS has developed the following Cyber Hygiene Fundamentals for Financial Institutions – Fact Sheets and Board Questions, which contains additional documents for Cybersecurity Awareness Training, Data Backup Programs, Incident Response Programs, IT Asset Management, Threat Intelligence Programs, and Third-Party Risk Management. The document can be utilized to help keep a focus on each practice being appropriately implemented. We strongly encourage these documents to be shared with the appropriate staff and the Board of Directors.

More like this from TXDOB

We email you every new TXDOB publication the day it's published.

Topics
Share