People are creatures of habit. We notice when the coffee cup is on the wrong shelf, the chair has moved a foot, or the website menu has been reorganized… again.
Board reporting is no exception. When Board members have reviewed cybersecurity control self-assessment results in a familiar format for years, a new report can feel like starting from scratch. The framework has changed. The terminology has changed. The charts have changed.
However, Board members still need answers to the same important questions.
As financial institutions continue transitioning away from the FFIEC Cybersecurity Assessment Tool (CAT), the challenge is translating results from a new framework into answers the Board can understand and apply. In this article, we’ll look at how to find and communicate those answers, regardless of the framework you choose.
Board members play an important role in overseeing a financial institution’s safety and soundness, and cybersecurity is part of that responsibility.
While this article offers practical guidance for those managing and reporting cybersecurity assessments, we also created a resource specifically for Board members. Download our new resource, A Board Member’s Guide to Cybersecurity Assessments, to discover what’s changed since the FFIEC CAT sunset, what to expect from current cybersecurity assessment reporting, and what questions need to be asked to present management with a credible challenge and better understand the results.
| Download Now: A Board Member’s Guide to Cybersecurity Assessments |
One of the key reasons financial institutions perform cybersecurity control self-assessments is to demonstrate compliance with regulatory requirements.
Previously, many institutions relied on the FFIEC CAT for this purpose. Its “Baseline” declarative statements provided a regulator-developed reference point for the controls generally expected of financial institutions.
New frameworks approach the compliance question in different ways. Some incorporate regulatory sources through mappings. Others have a strong connection to regulatory supervision. For example, the OCC CSW is based on the NIST CSF.
No framework provides a perfect or permanent measure of compliance. Regulations, threats, technologies, and cybersecurity practices continue to evolve. Every framework, including the FFIEC CAT, may contain controls that exceed an institution’s needs, omit newer controls which might be necessary, or leave some expectations open to interpretation.
For most community financial institutions, the practical approach is to select a regulator-recognized framework appropriate for the institution’s size, complexity, and risk, and use the assessment results to inform and support the institution’s overall compliance management process.
Your Board Needs to Know
| If you aren’t sure how to explain which framework is a good fit for your institution, check out our quiz: Which Cybersecurity Framework is the Best Fit for You? Answer a few questions and get your results now at Tandem.App/Quiz. |
How to Show This
Use a chart showing the implementation status of the framework’s controls, such as:
Beyond compliance, cybersecurity assessments help institutions evaluate whether their control environment is comprehensive and working as intended.
The FFIEC CAT combined an “Inherent Risk Profile” and a cybersecurity control self-assessment into one tool. While some frameworks feature scoping or tiering features which serve a similar purpose, most modern frameworks do not include this “risk profile” component. Risk identification and mitigation are often handled through an institution’s Information Security Risk Assessment, while the cybersecurity assessment provides assurance of the controls used to manage these risks.
The FDIC Risk Management Manual of Examination Policies, Section 16.1 states:
“If the institution incorporates a cybersecurity tool or framework (e.g., NIST Cybersecurity Framework) into its risk management process, examiners should detail the results of management’s assessment. The details should be presented in conjunction with the examiner’s review of the institution’s overall information security risk assessment and can be included under the supporting comments for cybersecurity preparedness.”
Risk assessments and cybersecurity assessments serve different purposes, but their results should inform each other. Presenting them together helps the Board understand both sides of the coin: the risks facing the institution and the strength of the control environment designed to address them.
| Learn more in our article, Difference Between Risk Assessments and Cybersecurity Control Self-Assessments. |
Your Board Needs to Know
How to Show This
Share your Information Security Risk Assessment alongside your cybersecurity assessment results. Use the risk assessment to summarize the institution’s key risks and the cybersecurity assessment to show the overall strength of the control environment.
One feature many institutions appreciated about the FFIEC CAT was its familiar tiered structure (Baseline, Evolving, Intermediate, Advanced, and Innovative) and how the maturity levels aligned with the institution’s inherent risk levels.
At first glance, this alignment offered a straightforward roadmap: determine where you are today, then work toward the next level.
In practice, that roadmap had several limitations:
Newer frameworks often make gap analysis more straightforward. Instead of working toward the next label, your institution can identify where each control stands today, determine where it needs to be, and create a plan to close the gap.
This gives management a clearer picture of progress and a practical way to decide which improvements matter most, which should come first, and what they may cost.
Your Board Needs to Know
How to Show This
Share a prioritized list of significant gaps showing planned actions, cost, priority, responsibility, target dates, and current status.
You can also use a control status chart by framework category to show where controls are implemented or not implemented. Grouping the results by category can reveal broader trends, such as whether gaps are concentrated in a specific area.
Another benefit of the FFIEC CAT was standardization. When institutions used the same assessment and answered the same declarative statements, their results could be compared with peers.
The good news is that peer comparison is still possible with newer frameworks. With enough institutions using the same framework and reporting tools like Tandem, management can compare results at the framework, category, and control level.
These peer comparisons add useful context to assessment results. A result shared by most peers may reflect a broader industry challenge, while a result that is uncommon among peers may deserve closer attention.
Your Board Needs to Know
How to Show This
Use a peer comparison chart by framework, category, or control. Focus the Board’s attention on the most meaningful differences, especially areas where the institution falls behind peers or where peer performance may influence the priority of remediating a gap.
| Institutions using Tandem Cybersecurity Assessment can choose to participate in anonymous Peer Analysis to compare their assessment results with other participating institutions. Sign up for free at Tandem.App/Cybersecurity. |
One benefit (and challenge) of the FFIEC CAT was that it rarely changed. When it sunset, institutions were still evaluating the same 494 declarative statements first introduced in 2015.
This consistency made ongoing analysis relatively simple. Institutions could compare one assessment with the next, identify controls that improved, and see whether their overall cybersecurity posture was moving in the right direction.
Newer frameworks may change more frequently to keep pace with the evolving cybersecurity and regulatory environment. While this can complicate direct comparisons, it does not have to mean starting over. Software solutions may use mappings to carry applicable responses into the updated framework, allowing management to focus on reviewing new or changed controls while preserving relevant assessment history.
Your Board Needs to Know
How to Show This
Use a gap status chart to show remediation efforts that are closed, in progress, or not started.
Pair it with a year-over-year assessment comparison showing where control implementation improved, declined, or remained unchanged.
Turn your cybersecurity assessment results into reporting your Board can understand and use. Tandem Cybersecurity Assessment is free and includes the frameworks identified in the FFIEC CAT Sunset Statement, along with ready-to-use Board report templates featuring the charts and insights discussed in this article.
Want something more tailored? Use the custom document option to choose the information your Board needs and create a report that fits your institution.
Sign up for free at Tandem.App/Cybersecurity.
Which framework replaced the FFIEC Cybersecurity Assessment Tool (CAT)?
No single framework replaced the FFIEC CAT. In the CAT Sunset Statement, the FFIEC pointed institutions toward resources like the NIST Cybersecurity Framework, the CISA Cybersecurity Performance Goals, the CRI Profile, and the CIS Controls, leaving the choice to each institution.
Which cybersecurity framework should we report to our Board?
Whichever framework best fits your size, complexity, and risk. Your Board should know which framework you chose and why it is a good fit, not just the results. Take our quiz to find out which framework may be a good fit for you at Tandem.App/Quiz, or read our blog on “What Framework Do I Replace the FFIEC CAT With?”
How often should my Board review cybersecurity assessment results?
At least annually. The Interagency Guidelines Establishing Information Security Standards require the Board of Directors to be updated on the status of the Information Security Program at least annually. Most institutions include cybersecurity assessment results in that report, updating the Board more often based on preference and notable cybersecurity changes.
What should my cybersecurity assessment report to the Board include?
At a minimum, answer the five questions the Board of Directors cares about: whether you are compliant, whether controls are mitigating risks, what needs to improve, how you compare with peers, and whether you are improving over time. Pair each with a chart or a prioritized gap list so the information is easy to understand and act on.
Can we still compare our results to peers now that the CAT is gone?
Yes. When enough institutions use the same framework and reporting tools like Tandem Cybersecurity Assessment supports it, you can still compare results at the framework, category, and control level.
What questions should Board members ask about a cybersecurity assessment?
Boards should ask questions about which framework was selected and why, whether results indicate compliance, which gaps matter most, and how the institution compares with peers. Our resource, A Board Member’s Guide to Cybersecurity Assessments, provides a suggested list and walks through these concepts in more detail.