Cyberattacks are on the rise in the wake of widespread digital adoption during the pandemic; now the U.S. financial system faces an elevated threat of cyberattack if Russia delivers on promised retaliations against U.S. sanctions imposed this week after the country’s invasion of Ukraine, experts say.
Here are 33 questions every banker should ask themselves now — ahead of potential cyberattacks:
-

Image by CanStock When was the last time we ran a cybersecurity event practice drill and rehearsed what to do?
- Have we checked the dark web to see if our data stores are for sale there?
- What will we do if we have data stores for sale on the dark web?
- What are our regulatory obligations to report and respond to data on the dark web?
- What is our overall plan for responding to a ransomware attack?
- Would we pay if hit with a ransomware attack?
- How can we protect against a potential ransomware attack now?
- Do we have the talent to respond to a cybersecurity attack on our data? On our network?
- If we do not have security talent on staff, where will we find it when an attack happens?
- Do we have a cyber forensic team we can call to investigate if we’re attacked or breached?
- If we outsource security, will that be enough of a response for regulators investigating an attack? Will it be enough of a response for customers?
- When was our last penetration test?
- When was the last time our website underwent a security audit? What about our mobile app?
- What exactly is our cloud provider’s security posture on our data?
- If an attack occurred today, could we answer questions from our customers and the press about what steps we took to secure our systems?
- If an attack occurred today, who would be responsible for kicking off disaster recovery and response protocol?
- Do we have a disaster recovery plan for cyberattacks?
- Have we tested our disaster recovery plan?
- Do we have a backup for our critical systems offline in cold storage?
- Have we tested our cold storage backup within the past six months to ensure it will work?
- Have we instilled sound security measures at the development team level or is security only a network-level conversation?
- How will we communicate with customers immediately if there is a cyber shutdown of our systems?
- What if our chatbot is compromised?
- Do we have a backup and recovery plan if critical infrastructure in our headquarters is brought down due to a citywide cyberattack?
- Is security a board-level discussion for us?
- What executive-level leader is ultimately responsible for our cyber security posture?
- If we outsource security, how sure are we that mission-critical systems are protected and can’t be brought offline?
- Multifactor authentication is table stakes for security — do we use it?
- Are we exploring how biometrics could be leveraged in our online apps?
- Are our APIs secure or could they be leveraged in an attack?
- What is my cloud provider doing to ensure the safety of my data?
- How long could a “live off the land” attacker last in our system without detection?
- Are we automating security where we can — for example, blocking executables automatically?






