FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

CFPB lags on information security updates

Bureau to hire 75 enforcement staffers

Marcie BellesbyMarcie Belles
November 6, 2023
in Risk & Security
Reading Time: 4 mins read
0
Share on Facebook

While the Consumer Financial Protection Bureau plans to step up enforcement action in the lending sector, the federal watchdog has yet to implement measures laid out in its own information security audits dating back to 2014.

At a consumer rights conference Oct. 26, CFPB Enforcement Director Eric Halperin unveiled a three-pronged approach aimed at protecting consumers amid rising debt burdens and high interest rates that are impeding access to capital. Halperin noted that the agency intends to hire 75 additional enforcement staffers to achieve its agenda.

Specifically, the CFPB plans to probe how companies use consumer data and whether they appropriately investigate disputes about data accuracy. Further, the agency expects to bolster its scrutiny of predatory lending and monitor the risk to consumers created by financial institutions’ reliance on “opaque algorithms” and other types of automation that replace human judgment in dispute resolution, Halperin said.

In a nutshell, Halperin noted that “the consumer economy continues to get more complex and less transparent every day.”

Yet, the CFPB appears to be lagging in efforts to shore up its own information security measures, according to the Office of Inspector General’s 2023 audit of the CFPB’s information security, or infosec, program. Despite notching a “level 4” — of a possible 5 — rating for its infosec operations, the CFPB was deemed “level 3” or below in three of five information security functions. In fact, the agency’s rating since 2021 has worsened in two categories graded by the audit: data-loss prevention and contingency planning.

Interestingly, the Sept. 29 report makes no mention of the data breach that occurred at the watchdog agency this year. The incident allegedly involved an employee who forwarded spreadsheets with names and transaction-related numbers for the accounts of 256,000 consumers, as well as confidential supervisory information for more than 40 financial institutions, to a personal email account. The OIG performance audit started in March — just one month after the CFPB data breach.

A seal at the Consumer Financial Protection Bureau (CFPB) headquarters in Washington, D.C.
Photographer: Samuel Corum/Bloomberg

Even so, this year’s audit includes only one new recommendation for infosec improvement, namely, to maintain a comprehensive schedule for documenting, testing and updating contingency plans. The CFPB’s contingency planning function was rated a “level 2,” the score given for a system that is documented but not consistently implemented.

Contingency planning, also referred to in the audit as the “recover” function, relates to the restoration of systems that are compromised or breached. The audit noted that the CFPB failed to test in accordance with annual testing requirements.

“Specifically, the CFPB had not tested one Executive Order (EO) critical system since FY 2021, and it had scheduled testing for two other systems but had not yet completed the testing,” according to the report. A footnote states that “CFPB officials indicated that administrative changes prevented the CFPB from performing its annual testing for this contingency plan.”

A unique element of the report is that it includes the CFPB’s responses to the OIG’s findings and guidance. On the topic of contingency planning, the CFPB’s chief information officer Chris Chilbert notes that the agency expects to develop the requisite policies and supporting procedures, along with the contingency plan testing schedule, by the fourth quarter of fiscal 2025.

Aside from the new recommendation, the report mentions that a pair of contingency planning instructions from previous audits remain outstanding. In fact, those issues are among several that have been languishing. While an appendix in the report describes four open recommendations that the CFPB completed this year, it details nine unresolved issues — five from last year, two from 2018, one from 2017 and one from 2014.

The oldest open recommendation in the audit calls for the CFPB to strengthen its vulnerability management practices by implementing an automated solution and process to periodically assess and manage database and application-level security configurations. So far, the CFPB has completed the latter task, implementing an application-level scanner. As for the database security component, the CFPB bought the scanning tool but won’t likely implement it until early 2024.

Meanwhile, one of the outstanding recommendations from the 2018 audit may not reach completion until the end of 2024. The task calls for the CFPB to determine whether established processes and procedures for management of user access are effective.

Over the years, the CFPB has called out companies for data breaches. In July 2019, the agency reached a deal with Equifax to pay $700 million for violating the Consumer Financial Protection Act because of a data breach. In August 2022, CFPB Director Rohit Chopra said that “financial firms that cut corners on data security put their customers at risk of identity theft, fraud and abuse.”

Further, the CFPB typically assigns deadlines to consent orders with financial services companies. For instance, when now-defunct auto lender Security National Automotive Acceptance Co. failed to comply with a 2015 consent order related to illegal debt collection tactics, the CFPB tacked on another $1.25 million penalty.

Perhaps the CFPB should hire staffers to bolster its infosec practices before it steps up enforcement actions against financial services companies.

Editor’s note: This article first appeared on Auto Finance News, a sister publication to Bank Automation News. 

Tags: CFPBPremiumregulation
Previous Post

Digitalization allows U.S. Bank to expand reach

Next Post

Inside look: The hunt for AI talent

Related Posts

A flag displaying Capital One's logo
Risk & Security

Capital One’s Evan Baker to speak at FinAi Lending Summit

July 20, 2026
fintech icon on abstract financial technology background
Risk & Security

Q&A with Luis Pinedo on his move from Santander to ThetaRay

July 13, 2026
Lock on top of lines of code
Risk & Security

Nasdaq Verafin developing AI agents to tackle AML compliance

July 13, 2026
Next Post
Photo courtesy of Bank of America

Inside look: The hunt for AI talent

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

The Buzz Podcast

SPONSORED

Build an Antifragile Strategy to Outperform the Market

July 14, 2026

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

 [wt_cli_manage_consent]

Connect

twitter linkedin podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account