859-303-9344 [email protected]

After the FFIEC CAT: A 2026 Bank Cybersecurity Guide for Kentucky Banks and Credit Unions

Last updated: October 2026 · By Brent McKune, President & Owner, UPTech IT

For ten years, many community banks answered “how is our cybersecurity program doing?” with one document: the FFIEC CAT (Cybersecurity Assessment Tool).

That tool is gone. The FFIEC retired the CAT on August 31, 2025, and removed it from its website. A year later, many institutions are still working from an old CAT spreadsheet, and some haven’t picked a replacement.

October is Cybersecurity Awareness Month, and this year’s national theme is “Securing the Next 250.” For community banks and credit unions, securing the next 250 years starts with making sure this year’s exam documentation doesn’t cite a tool that no longer exists. This guide covers what replaced the CAT, which rules and reporting deadlines apply to your institution, and the threats that dominated 2025 and 2026 reporting.

Key takeaways

  • The FFIEC CAT was retired August 31, 2025. No single tool replaced it, and regulators endorse none.
  • The main replacements are NIST CSF 2.0, CISA’s Cybersecurity Performance Goals, the CRI Profile, the CIS Controls, and (for credit unions) the updated NCUA ACET.
  • The tool retired, but the exam standard didn’t. Examiners still expect a documented, risk-based self-assessment.
  • Banks must notify their regulator within 36 hours of determining a notification incident occurred. Credit unions have 72 hours.
  • Third-party vendors, business email compromise, AI-driven social engineering, and ATM jackpotting led 2025–2026 incident reporting.

What happened to the FFIEC Cybersecurity Assessment Tool?

The FFIEC released the CAT in June 2015 as a voluntary tool and announced its sunset in August 2024. It was retired on August 31, 2025. Rather than update it, the agencies pointed institutions to newer government resources such as NIST Cybersecurity Framework 2.0 and CISA’s Cybersecurity Performance Goals (Federal Reserve SR 24-7).

Two points in the sunset guidance matter most for community banks.

First, the CAT was always voluntary, and so are its replacements. The Federal Reserve does not endorse any particular tool. What it expects is that whatever self-assessment you use supports an effective control environment and fits your institution’s risk profile (SR 24-7).

Second, retiring the CAT did not lower the bar. Examinations remain risk-focused. Examiners continue to work from the FFIEC IT Examination Handbook, including its Information Security, Architecture, Infrastructure and Operations, and Business Continuity Management booklets. The CAT was a way to measure yourself against those expectations. The expectations themselves haven’t changed.

In plain terms: nobody will tell you which framework to use, but your examiner will still expect you to show your work.

What replaces the FFIEC CAT?

The alternatives regulators and the Federal Reserve’s “Ask the Fed” sessions pointed institutions toward come down to a short list:

Framework Maintained by Best fit
NIST Cybersecurity Framework 2.0 NIST (government) Institutions that want the most widely recognized baseline, one that vendors, auditors, and insurers already speak
CISA Cybersecurity Performance Goals CISA (government) Smaller institutions that want a prioritized list of high-impact controls
CRI Profile Cyber Risk Institute (industry) Banks that want a financial-sector assessment built on NIST and mapped to regulatory expectations
CIS Critical Security Controls Center for Internet Security (industry) Teams that want concrete, technical control guidance
NCUA ACET National Credit Union Administration Credit unions already familiar with ACET, now updated for NIST CSF 2.0

For credit unions, NCUA updated ACET on September 16, 2025, to incorporate NIST CSF 2.0 content, and the new version is free to download (NCUA). If your credit union already uses ACET, the move is mostly a version upgrade.

For community banks, the practical choice usually comes down to two paths:

  • The CRI Profile, if you want something built for financial services that keeps the CAT’s regulatory feel. The FFIEC’s own webinar on the CAT retirement specifically highlighted the Cyber Risk Institute’s framework (NCUA).
  • NIST CSF 2.0, supported by CISA’s performance goals, if you want the most universal language and a clear list of priorities.

Either is defensible. What isn’t defensible is having no current assessment, or still citing a retired tool in your board reporting.

Not sure which framework fits your institution? UPTech IT offers a free 30-minute CAT replacement review. We’ll look at how you assess today, recommend a framework that fits your size and risk, and flag the biggest gaps before your next exam.

Book Your Free CAT Replacement Review

Does the GLBA Safeguards Rule apply to banks?

This is one of the most common points of confusion in financial-sector compliance, and it’s worth getting right.

The FTC Safeguards Rule applies to non-bank financial institutions under FTC jurisdiction, such as mortgage brokers and non-bank lenders. An amendment effective May 13, 2024, requires those businesses to notify the FTC within 30 days of discovering a breach affecting 500 or more people (FTC).

Banks meet their GLBA obligations through the Interagency Guidelines Establishing Information Security Standards, issued by the federal banking agencies under sections 501 and 505 of the Gramm-Leach-Bliley Act (Federal Reserve). Those guidelines are paired with interagency guidance on response programs for unauthorized access to customer information, which covers customer notification.

Why this matters in practice: if a vendor or consultant hands your bank a “GLBA Safeguards Rule checklist” written for FTC-regulated businesses, it may be pointing you at the wrong rule. Build your program around the Interagency Guidelines and your primary regulator’s exam expectations.

Kentucky note: Kentucky’s data breach notification statute does not apply to entities subject to Title V of GLBA (KRS 365.732(8)), and the Kentucky Consumer Data Protection Act, effective January 1, 2026, exempts GLBA-covered financial institutions as well. That doesn’t reduce your obligations. It means your federal program is the one that counts, so it needs to be complete.

Bank cybersecurity incident reporting: know your clock

When something goes wrong, you are working against a federal deadline set by your charter type.

Institution type Who you notify Deadline Source
Banks (OCC, Federal Reserve, FDIC supervised) Primary federal regulator As soon as possible, no later than 36 hours after determining a notification incident occurred OCC Bulletin 2021-55
Federally insured credit unions NCUA As soon as possible, no later than 72 hours after reasonably believing a reportable incident occurred 12 CFR Part 748
Non-bank financial institutions (FTC) FTC As soon as possible, no later than 30 days after discovering a breach affecting 500+ people FTC Safeguards Rule

Some details are easy to miss.

What counts for banks. A “notification incident” is a significant computer-security incident that has disrupted or degraded, or is reasonably likely to disrupt or degrade, your operations, customers’ access to their accounts, or the stability of the financial sector. Ransomware and DDoS attacks are named examples (OCC).

What counts for credit unions. A reportable cyber incident is one that causes a substantial loss of confidentiality, integrity, or availability of a network or member information system, or disrupts vital member services. That includes incidents that start at a CUSO or third-party provider, not just the credit union’s own systems (NCUA Cyber Incident Reporting Guide).

Your service providers have obligations too. A bank service provider must notify your designated contact as soon as possible when an incident has disrupted, or is reasonably likely to disrupt, covered services for four or more hours. If you haven’t named that contact, the rule defaults to your CEO and CIO.

Third-party notices start the credit union clock. For credit unions, the 72-hour window also applies when a third party tells you your data or operations were compromised. The clock starts when you receive that notice or form a reasonable belief an incident occurred, whichever comes first.

Regulator notice is not customer notice. The 36- and 72-hour deadlines cover your regulator. Customer notification runs on a separate track: under the interagency response-program guidance, banks should notify affected customers as soon as possible once misuse of their information has occurred or is reasonably possible. Your incident response plan needs both tracks.

A 36-hour window leaves no time to figure out who is supposed to call the regulator. Put that decision in your incident response plan now, with a named backup.

The 2026 threats community banks and credit unions are facing

Your vendors are your biggest exposure

The clearest data comes from credit unions, because NCUA publishes what it receives. In the first year of NCUA’s reporting rule (September 2023 through August 2024), credit unions filed 1,072 cyber incident reports. Of those, 742, nearly 7 in 10, involved a third-party vendor (NCUA). Those 742 reports traced back to just 13 vendor events, and the largest single event alone accounted for 234 of them (NCUA Board Briefing).

That concentration is the lesson. One vendor compromise can put hundreds of institutions into incident response at the same time. Your own controls can be excellent, and your exposure is still only as good as your weakest critical vendor.

For banks, the regulatory anchor here is the Interagency Guidance on Third-Party Relationships: Risk Management (June 2023). Examiners use it to evaluate how you select, contract with, and monitor vendors, including the core provider most community banks depend on.

Business email compromise is climbing

NCUA’s 2026 Cybersecurity and Credit Union System Resilience Report counted 588 cyber incidents reported between May 1, 2025, and April 30, 2026, including ATM jackpotting, phishing, email compromise, ransomware, and third-party incidents. That covers a different period than the first-year figure above, so the two totals aren’t directly comparable. Within the new period, business email compromise cases rose to 40 from 27, a 48% increase (NCUA). BEC targets people and process, such as a fake wire instruction or a spoofed executive request, so technical controls alone won’t stop it.

AI-powered social engineering is the top concern

In the 2026 Banking Priorities survey of 252 financial institution leaders by Paducah, Kentucky-based CSI, 27% named AI as their top concern for the year, and AI-enhanced social engineering ranked as the leading cybersecurity threat (CSI). Convincing voice clones and flawless phishing emails remove the red flags employees were trained to spot.

Governance is lagging behind. IBM’s 2025 Cost of a Data Breach research found that 63% of breached organizations either had no AI governance policy or were still developing one, and 16% of breaches involved attackers using AI, most often for phishing or deepfake impersonation (IBM).

ATM security has become a cyber problem

ATM jackpotting forces a machine to dispense cash without a card, a customer account, or bank authorization. In a February 19, 2026, FLASH alert, the FBI reported roughly 1,900 jackpotting incidents since 2020, with more than 700 in 2025 alone and losses above $20 million (FBI IC3).

The attack is part physical and part digital. Attackers usually open the ATM with widely available generic keys, then remove or replace the hard drive to load malware such as Ploutus. The malware hijacks XFS, the software layer that tells the ATM what to physically do, so it can bypass bank authorization entirely. Because it exploits the Windows system underneath, it works across manufacturers. Jackpotting also appears among the incident types credit unions report to NCUA.

The FBI’s recommended mitigations include vibration and temperature sensors on machines and vestibules, auditing for removable-storage use and new processes, and watching for unauthorized remote-access tools such as TeamViewer or AnyDesk. Your ATM and ITM fleet is part of your network and should be monitored like one. UPTech IT’s sister companies work in the ATM industry, so we see this problem from both sides: the hardware and the network it sits on. Learn how PRISM and JackBlock protect ATMs and self-service technology.

A bank cybersecurity checklist for Cybersecurity Awareness Month

Work through these items in October with your IT team, your provider, or your board’s risk committee.

Governance and compliance

  1. Retire the CAT from your documentation. Pick a replacement framework (CRI Profile, NIST CSF 2.0, or the updated NCUA ACET) and complete a baseline assessment.
  2. Update board reporting. Make sure cybersecurity reports reference your current framework, not a retired tool.
  3. Confirm which GLBA standard you follow. Banks follow the Interagency Guidelines. Non-bank lenders follow the FTC Safeguards Rule. Retire any checklist written for the wrong one.
  4. Adopt an AI acceptable-use and governance policy. Define which AI tools staff may use, what data can go into them, and who approves new ones.

Incident response

  1. Put your reporting clock in writing. Banks: 36 hours from determination. Credit unions: 72 hours from reasonable belief. Name who makes the call and who backs them up.
  2. Separate regulator notice from customer notice. Document both tracks and who owns each.
  3. Run a tabletop exercise. Simulate a critical-vendor breach and walk through your first 36 or 72 hours.

Vendors

  1. Give vendors a designated contact. Make sure your core provider and critical vendors know who to notify at your institution.
  2. Review critical vendor contracts. Look for incident notification terms, security requirements, and your right to see assessment results.

People and process

  1. Add a call-back rule for money movement. Verify any change to wire instructions or payment details by phone, using a number already on file, never one from the email.
  2. Refresh phishing and deepfake training. Include AI-generated voice and email scenarios, not just the old examples.

Technical controls

  1. Enforce phishing-resistant MFA on email, remote access, and all administrative accounts.
  2. Confirm EDR or MDR coverage on every endpoint, including servers and teller workstations.
  3. Test your backups. Keep at least one immutable or offline copy and prove you can restore from it.
  4. Patch internet-facing systems first. VPNs, firewalls, and remote-access portals are the most common entry points.
  5. Treat ATMs and ITMs as endpoints. Replace generic keys, add tamper sensors, restrict removable media, and monitor for unauthorized remote-access software.

Many of these controls also show up on cyber insurance applications. Carriers increasingly require MFA, EDR, and tested backups at renewal, so this work pays off twice.

What this means for Kentucky banks and credit unions

Kentucky community banks and credit unions serve their towns in ways large national banks don’t. That also makes them attractive targets: they hold the same sensitive data and run the same core systems as larger institutions, often with a fraction of the security staff.

Many Kentucky institutions also answer to two examiners. The Kentucky Department of Financial Institutions supervises state-chartered banks and credit unions alongside the FDIC, the Federal Reserve, or NCUA. A documented framework gives both examiners the same story to review.

Retiring the CAT gives you room to build a program that fits your size and risk instead of a generic template. That flexibility only helps if someone uses it: pick a framework, document your decisions, and test your response before an examiner or an attacker does it for you.

Ready to replace the CAT and get exam-ready? UPTech IT provides IT services and cybersecurity for Kentucky banks and credit unions, from framework selection and gap assessments to incident response planning and 24/7 monitoring.

Book Your Free CAT Replacement Review

Frequently asked questions

What replaced the FFIEC Cybersecurity Assessment Tool?

No single tool replaced it. When the FFIEC retired the CAT on August 31, 2025, institutions were pointed to NIST Cybersecurity Framework 2.0, CISA’s Cybersecurity Performance Goals, the Cyber Risk Institute’s CRI Profile, and the CIS Critical Security Controls. Credit unions can continue using NCUA’s ACET, which was updated in September 2025 to incorporate NIST CSF 2.0. Regulators do not endorse any particular tool.

Is the FFIEC CAT still required?

No. The CAT was always voluntary, and it has been retired and removed from the FFIEC website. Examiners still take a risk-focused approach and expect a self-assessment method that supports an effective control environment and matches your risk.

What do examiners use now that the CAT is gone?

Examiners continue to rely on the FFIEC IT Examination Handbook and a risk-focused approach. The CAT was a self-assessment tool, not the exam standard, so the underlying expectations have not changed.

Does the GLBA Safeguards Rule apply to banks?

The FTC Safeguards Rule applies to non-bank financial institutions under FTC jurisdiction. Banks meet their GLBA information security obligations through the Interagency Guidelines Establishing Information Security Standards, issued by the federal banking agencies.

How long does a bank have to report a cyber incident?

Banks supervised by the OCC, Federal Reserve, or FDIC must notify their primary federal regulator as soon as possible and no later than 36 hours after determining that a notification incident has occurred.

How long does a credit union have to report a cyber incident to NCUA?

Federally insured credit unions must notify NCUA as soon as possible and no later than 72 hours after reasonably believing a reportable cyber incident occurred. The same window applies after a third party notifies the credit union of a compromise.

Do Kentucky’s data privacy laws apply to banks and credit unions?

Kentucky’s breach notification statute (KRS 365.732) and the Kentucky Consumer Data Protection Act, effective January 1, 2026, both exempt institutions subject to Title V of GLBA. Banks and credit unions meet those obligations through their federal information security programs instead.

What is ATM jackpotting?

ATM jackpotting is an attack that forces an ATM to dispense cash without a card, customer account, or bank authorization. Attackers typically gain physical access, then load malware such as Ploutus onto the machine’s hard drive. The FBI reported more than 700 incidents in 2025, with losses exceeding $20 million.


This article is for general information and is not legal advice. Confirm requirements with your counsel and primary regulator.

About the author: Brent McKune is President & Owner of UPTech IT, a Lexington-based managed IT and cybersecurity provider serving businesses across Central Kentucky. He holds a BBA from the University of Kentucky and an MBA from Midway University, along with the CPHIMS certification, and has worked across IT, healthcare technology, and financial services.

Related Posts