On Tuesday, October 24, 2023, the state bank regulators (CSBS), Bankers' Electronic Crimes Task Force, and United States Secret Service published an updated version of the Ransomware Self-Assessment Tool (R-SAT). In this blog, we'll discuss what the R-SAT is, what got updated, and what you need to do about it.
The first version of the R-SAT was published in October 2020. You can learn more about the tool's origins in our blog: Ransomware Self-Assessment Tool (R-SAT): What Banks and Credit Unions Need to Know.
The updated R-SAT 2.0 is a 20-question self-assessment. It was created to help financial institutions manage risks associated with the evolving threat of ransomware. The tool is designed to provide guidance and highlight any potential gaps in a business' cybersecurity program.
Along with the updated R-SAT 2.0, the Conference of State Bank Supervisors (CSBS) published a report on Ransomware Lessons learned by Banks that Suffered an Attack. The report provides a summary of findings gathered from multiple state banking departments across the United States. These departments conducted an extensive study on ransomware incidents that affected state-chartered banks and credit unions.
The report highlights the following key insights:
The agencies integrated lessons learned from these findings into the R-SAT 2.0 updates.
The new version of the R-SAT maintains the same overall appearance and format as Version 1.0. It also continues to adhere to the NIST Cybersecurity Framework (CSF). A lot of the content should look familiar, but it was expanded from 16 to 20 questions.
Here is a summary of some significant changes you can expect to see in R-SAT 2.0.
By considering and adopting these updates, financial institutions can take a significant step towards a safer, more secure future, benefiting not only individual institutions but also the greater financial industry.
A: Certain state regulatory authorities are already encouraging completion of R-SAT 2.0 before upcoming examinations (e.g., California, Texas, etc.). While it is up to your regulators to determine if the R-SAT is "required," it is a helpful tool, and we recommend completing it (as a best practice) to assess your preparedness for ransomware. If you have questions about if the R-SAT 2.0 is required, check with your state regulator.
A: If you have all the answers on-hand, you could probably fill out the R-SAT 2.0 document in a few hours. That said, it could take longer if you need to involve some of your third parties (e.g., managed service providers (MSPs), cloud service providers, insurance companies, consultants, etc.). It also depends on what you mean by "complete." You may find there are some controls listed on the R-SAT which your institution has not implemented. If this is the case, other stakeholders may need to be involved to determine how you plan to address those gaps. In short, the answer to this question ultimately comes down to your institution's size, risk, complexity, and current level of ransomware preparedness.
A: We recommend completing it at least annually, but review and make updates as changes occur at your institution. Think about reviewing and updating the R-SAT 2.0 if your control environment changes, if you start offering a new product or service, if you change relevant service providers, or if you have a ransomware incident.
The Tandem Cybersecurity Assessment product allows users to complete cybersecurity control self-assessments based on the R-SAT. Learn more and sign up for access to the free version of the product at Tandem.App/Cybersecurity.
For additional assistance with preventing, detecting, and responding to ransomware, check out the other Tandem products. Tandem is a cybersecurity governance, risk management, and compliance (GRC) suite of web-based applications, designed to help financial institutions manage the risk of cyber threats.
Some of the Tandem products include Incident Management, Policies, Risk Assessment, Vendor Management, and more. See how Tandem can help you at Tandem.App.