Federal banking regulators have taken a fresh step to modernize how financial institutions are evaluated for digital defense readiness. According to an official bulletin published by the Office of the Comptroller of the Currency (OCC), the agency has restructured and updated the references within its Cybersecurity Supervision Work Program (CSW). The regulator clarified that the recent update, released on Monday, September 21, focuses entirely on reorganization rather than introducing new mandates or altering existing supervisory procedures.
The updated framework is designed to help examiners evaluate modern technological risks more effectively. A primary adjustment involves realigning the CSW structure to match the updated National Institute of Standards and Technology (NIST) Cybersecurity Framework categories and subcategories. By adopting these updated categories, the regulatory program better addresses evolving digital threats while supporting risk-based information technology examinations across institutions of varying sizes.
The OCC noted that the updated bulletin maps directly to the Federal Financial Institutions Examination Council (FFIEC) Information Technology Examination Handbook as well as widely recognized cybersecurity frameworks. It is built to focus heavily on overall cybersecurity preparedness, serving as a supplement to existing guidelines found within the Comptroller’s Handbook booklets covering community bank supervision, large bank supervision, and federal branches and agencies supervision.
With the release of this updated program, the agency has officially rescinded OCC Bulletin 2023-22, which previously governed the Cybersecurity Supervision Work Program following its issuance in June 2023. Despite the updated structure, the agency emphasized that the revised work program does not establish any new regulatory expectations for financial institutions.
Furthermore, the regulator explicitly stated that banks are not required or expected to adopt this specific work program to evaluate their own internal cybersecurity preparedness. While the agency continues to encourage the adoption of a standardized approach to bolster digital defenses, individual banking institutions remain free to select from a broad variety of external tools, frameworks, and assessment methods currently available on the market.
This supervisory update follows a series of warnings and strategic shifts by federal regulators regarding the changing nature of technological threats within the financial sector. Earlier in May, the OCC highlighted that artificial intelligence is actively transforming the cyber threat landscape, designating it as a critical issue requiring proactive oversight. At that time, the agency recommended that financial institutions strengthen their defenses by implementing robust measures such as multifactor authentication and prompt patch management, while also utilizing artificial intelligence tools to defend against automated threats.
In addition to technological adaptation, previous reports indicate that the regulatory agency has increasingly aimed its oversight lens toward material financial vulnerabilities, including high-priority concerns like cyber and liquidity risks. By refining regulatory focus rather than expanding procedural demands, supervisory bodies aim to encourage institutional innovation, allowing financial organizations to allocate essential resources toward measurable risk mitigation and resilient transaction systems.
Source: PYMNTS