Five Steps to Comply with the NCUA’s Vital Records Preservation Rule
The NCUA published a final rule amending 12 CFR Part 749 on vital records preservation. Learn what the rule says and how it applies to your credit union.
The NCUA published a final rule amending 12 CFR Part 749 on vital records preservation. Learn what the rule says and how it applies to your credit union.
The CSBS released a practical cyber hygiene guide built for community financial institutions. Here's what it covers, how to use it, and what your Board and examiners will be asking about it.
Discover how vibe coding and AI citizen developers create compliance and security risks for community banks and credit unions, and what controls to put in place.
Federal banking regulators are increasingly approaching AI with cautious optimism. Here's what community banks and credit unions need to know in 2026.
AI notetaker apps take meeting minutes to the next level. But to deliver that convenience, the app owner may allow the tool to do things that matter from a GRC perspective. So, what can financial institutions do about it? Let’s take a closer look.
In February 2026, the Federal Financial Institutions Examination Council (FFIEC) updated their IT Examination Handbook to remove all references to reputation risk. What has changed and what do these updates mean for your financial institution? Let’s take a look.
How can we be prepared for deepfake attacks that look and sound real? In this article, we’ll explore how to train employees to recognize deepfakes quickly, verify unexpected requests, and report suspicious activity before it leads to serious damage.
What counts as an information asset? How do you evaluate risk at the information asset level? If you’ve asked any of those questions, this guide walks you through an asset-based risk assessment approach.
In our recent webinar, Level Up Your Tabletop Exercises, GRC Content Manager Alyssa Pugh walked through practical, experience-based guidance for making tabletops more effective and more valuable.
The Cybersecurity and Infrastructure Security Agency (CISA) published version 2.0 of their Cross-Sector Cybersecurity Performance Goals (CPGs). Let’s take a look at the CPGs and what changed in this latest version.
Smart glasses are being marketed as the next big leap in technology. They are powerful, but also risky when it comes to information security. So, how can you control the risk of wearables?