NOTE: This article may contain outdated information. See the updated article for details: Updated Ransomware Self-Assessment Tool (R-SAT 2.0).
* * * * *
On Tuesday, October 13, 2020, a Ransomware Self-Assessment Tool (R-SAT) was released to state-chartered financial institutions by the CSBS, BECTF, and USSS. Read this article to find answers to frequently asked questions about the R-SAT. Click the question below to jump to the related section.
The R-SAT is a 16-question self-assessment, in the form of a PDF document, created to help financial institutions reduce the risks of ransomware. It was specifically designed for state-chartered banks and credit unions. As a self-assessment, the R-SAT is different from an audit, a risk assessment, or a best practices document, but asks banks to consider aspects of each, as it relates to ransomware. According to the CSBS Press Release, "using the ransomware tool, a bank can assess its efforts to control and mitigate risks associated with the threat of ransomware and identify gaps that require increased security."
Ransomware is the combination of malware and a ransom heist. The malware encrypts data on a computer or network making it irrecoverable by the owner. Then attackers offer to give a decryption key in exchange for ransom. Even if the ransom is paid, it is not guaranteed that attackers will provide a decryption key.
The Conference of State Bank Supervisors (CSBS) is the national organization of state financial regulators that come together to develop and publish guidance across the states. CSBS released the R-SAT to their state-charted financial institutions, citing that it was developed with the Bankers Electronic Crimes Task Force (BECTF), led by Texas Banking Commissioner, Charles Cooper, and the United States Secret Service (USSS). The BECTF is composed of U.S. community financial institution executives, state bank regulators (likely members of the CSBS), and other industry stakeholders. The United States Secret Service is a federal law enforcement agency that conducts criminal investigations and protects the nation's leaders.
Ransomware is a growing threat.
According to the cover letter distributed with the tool, the R-SAT was designed because, "Ransomware has become the most visible cyber threat to our nation's networks." According to the CSBS Press Release, "using the ransomware tool, a bank can assess its efforts to control and mitigate risks associated with the threat of ransomware and identify gaps that require increased security." In other words, the R-SAT was designed to help you look at your controls and risks from a new angle to see if there is anything you can do to improve your resilience to a ransomware attack. The way the assessment is written, the recommended controls are built-in to the questions.
Examiners want to talk to you about ransomware.
Based on what we see in the statements released by the various states, the R-SAT was also designed to create talking points between examiners and institutions for exams in 2021. There is no indication these talking points would necessarily be considered findings.
Regulators want to make sure you have strong backup practices and are using multi-factor authentication.
In the cover letter, a whole section is dedicated to the value of two controls that are "very important: strong backup practices and the use of Multi-Factor Authentication (MFA)." To be effective, ransomware needs to compromise administrative credentials. MFA makes this much more difficult to accomplish. In the event administrative credentials are compromised and ransomware does encrypt data, strong backup practices ensure you can restore data to a previously uncompromised point without having to pay the ransom.
A copy of the R-SAT, the associated cover letter, and the press release can be downloaded from the CSBS website at: https://www.csbs.org/ransomware-self-assessment-tool.
Each state has different expectations related to the R-SAT for state-regulated banks, credit unions, and other state-chartered financial institutions. Since the R-SAT was released by the CSBS, we expect all state-charted institutions will be contacted about completing it. See our article State Banking Departments Announce New Ransomware Assessment (R-SAT) for a list of states who have communicated expectations related to the R-SAT.
If you are a nationally-chartered bank or credit union, we do not expect you will be asked to complete the R-SAT. However, we do believe completing the R-SAT is a helpful exercise you should consider.
It is currently unclear how often state-chartered institutions will be expected to complete the R-SAT. We are waiting on responses from regulators regarding this expectation. However, it is clear many regulators expect an initial assessment to be completed by early 2021.
The only "right" way to answer the questions is to answer them accurately. If you are a Tandem customer, we recommend you use the mapping document to help you quickly find the accurate answer to the questions. Access the mapping in Tandem by going to the Resources page.
There is no final rating you are trying to achieve, or specific answer set that gives you a passing grade. You will see several of the questions appear to be designed as though you should answer it "yes," such as questions about if you use certain controls. However, control implementation depends on the environment and compensating controls. Remember, this tool is primarily designed to draw attention to ransomware attacks and the controls which can protect against them.
On November 17th, 2020, Tandem hosted a webinar over the R-SAT. In this webinar, Russ Horn reviewed each question to discuss the expected purpose of the question and other interesting things to consider.
Here are a few notes from the webinar about each question.
As the goal of the R-SAT is to find gaps in ransomware controls, it could be beneficial to report what you found from the assessment regarding controls. Summarize what you have in place for preventing, detecting, and responding to ransomware. Then, present the items which are not currently in place that you would either recommend implementing or determine justification for not having those controls at this time. While this information could be reported separately, it could also be included when discussing information security and cybersecurity in regularly scheduled meetings.
The R-SAT is designed to bring attention to ways you can prevent and respond to ransomware. You should look into the recommended controls and determine if the control is implemented or not. If a recommended control does not currently exist in your security environment, you may wish to consider implementing the control and updating the related documentation in your Risk Assessment, Policies, Business Continuity Plan, Vendor Management, or Incident Management program.
Here are a few specifics you may consider:
We reviewed the Tandem commentary and consultative text to see what content could be improved to align with the topics addressed by the R-SAT. As the R-SAT reinforces existing concepts, we found very little needed to be updated. We made changes to five policies to better address controls that prevent ransomware.
If you are a Tandem Policies subscriber, check the Software Updates page for the full details of these changes (October 28, 2020) and instructions on how to accept the suggestions. If you are not a Tandem Policies subscriber, you may consider making similar updates to your Information Security policies. Here are the updates we made:
If you use the Compliance Management product, we recommend creating an event for completing the R-SAT. When creating an event, you can document the details, assign responsibility and a due date, and upload a copy of the completed assessment.
If you use the Audit Management product and you find there are several improvements needed to your controls around ransomware, you could create an audit to list all the findings and use it to track how and when you are addressing each issue.
If you use the Policies product, you could attach a copy of the completed R-SAT to your Malicious Software Protection policy.
Yes! The Tandem Cybersecurity Assessment product allows users to complete cybersecurity control self-assessments based on the R-SAT framework. Learn more at Tandem.App/Cybersecurity.
Update log: