Skip to content
TRAC GRC Solution
 

Flexible GRC Platform

Simplify cybersecurity risk management and tackle your cybersecurity challenges with ease. TRAC is a powerful GRC tool that automates the tedious risk assessment process and delivers customized results aligned with regulations, best practices, and your strategic goals.

Blog_HeaderGradients-10
Jon WaldmanJuly 31, 2026

A Cybersecurity Perspective on the Proposed CAMELS Changes: What Gets Examined Gets Funded

FFIEC CAMELS Changes and Cybersecurity Governance | SBS
10:06

Read SBS's comment letter and submit feedback through the FFIEC docket before the August 17 deadline.

 

The Federal Financial Institutions Examination Council (FFIEC) recently proposed updates to the CAMELS rating system, the framework regulators use to evaluate the condition of financial institutions. The proposal is intended to improve transparency, consistency, and predictability in supervisory ratings, goals that deserve support. SBS CyberSecurity agrees that institutions should better understand how ratings are determined and that ratings should be tied to meaningful risk.

At the same time, the proposal raises an important question: If cybersecurity and technology weaknesses often emerge months or years before measurable financial losses occur, how should those risks influence supervisory ratings?

That question extends beyond the CAMELS framework itself. It goes to the heart of how financial institutions manage risk in a technology-driven world.

 

Technology Risk Is Business Risk

There was a time when technology was largely a supporting function within a financial institution. That is no longer the case.

Today, core processors, digital banking platforms, cloud services, payment systems, vendor ecosystems, APIs, and other technology relationships play a central role in how institutions serve customers and conduct business. When technology fails, customers feel it. Operations are disrupted. Confidence is affected. In some cases, earnings, compliance obligations, or institutional stability may also be affected.

A ransomware attack, vendor outage, cloud misconfiguration, data breach, or online banking disruption is not simply an IT event. These are business events, operational events, and safety-and-soundness events.

That reality is one reason SBS often encourages financial institutions to think of themselves as technology companies that happen to provide financial services. While that does not mean every institution needs to build software, it does mean technology now supports nearly every critical business function.

 

The Most Important Risks Often Appear Before the Loss

One of the challenges in cybersecurity and technology risk management is that many warning signs emerge long before an institution experiences measurable financial harm.

Weak vendor oversight, aging audit findings, poor patch management, limited testing, incomplete asset inventories, and ineffective board reporting are often early indicators of risk. While these issues may not immediately affect earnings, capital, liquidity, or asset quality, they frequently create conditions that allow a significant incident to occur later.

That is why governance and risk management matter.

Effective cybersecurity begins with understanding risk. Institutions should use risk assessments to identify what matters most, allocate resources appropriately, and make informed decisions based on their unique threat landscape and business objectives.

The purpose of risk management is not to document what went wrong after an event. The purpose is to identify weaknesses, prioritize action, and reduce risk before an event occurs. Cybersecurity programs are most valuable when they help institutions make informed decisions earlier, not when they simply explain outcomes after the fact.

At SBS, we often describe an information security program as a living, comprehensive governance framework. Risk assessments drive decisions. Controls implement those decisions. Independent testing validates those decisions. Reporting and governance improve those decisions over time. The goal is not compliance for compliance's sake. The goal is better decisions and better outcomes.

 

Governance, Controls, and Testing Are Connected

Effective cybersecurity is not a single activity.

In our experience working with financial institutions across the country, successful programs generally share three characteristics. They establish governance through board oversight, policies, accountability, and risk assessments. They implement controls that align with those decisions. And they independently test those controls to determine whether they are working.

All three components matter. Without governance, organizations struggle to prioritize and fund risk management efforts. Without implementation, policies remain words on paper. Without testing, institutions may develop a false sense of confidence about the effectiveness of controls.

Independent testing is particularly important because it provides an objective mechanism for validating people, processes, and technology before weaknesses become incidents, regulatory findings, or losses.

 

What Gets Examined Gets Funded

One observation we have made over the years is that examination priorities often influence organizational priorities.

This is not a criticism of the examination process. It's simply how organizations prioritize risk. Areas that influence supervisory outcomes naturally receive greater attention, discussion, resources, and accountability.

Boards pay attention to what examiners evaluate. Management teams allocate resources to areas that receive scrutiny. Budgets frequently follow risk signals coming from regulators and examiners.

In other words: What gets measured gets managed. What gets examined gets funded.

This is particularly relevant for cybersecurity leaders, chief information officers, and risk officers. When examination findings consistently highlight governance, independent testing, remediation discipline, and resilience planning, those activities tend to receive board attention and budget support. When those same areas are perceived as having less influence on supervisory outcomes, competing priorities can naturally take precedence.

As financial institutions continue to face increasingly sophisticated cyber threats, growing third-party dependencies, operational resilience challenges, and expanding technology ecosystems, we believe it remains important that governance, cybersecurity, resilience, and independent testing maintain strong visibility within the supervisory process.

 

A Conversation Worth Having

The CAMELS proposal has also sparked broader discussion about whether technology and operational resilience deserve more explicit recognition within the supervisory framework. Technology risk now spans multiple disciplines. Governance, cybersecurity operations, third-party risk, resilience planning, incident response, and independent testing all contribute to an institution's ability to operate safely and reliably. These concepts already exist throughout FFIEC guidance and the NIST Cybersecurity Framework. The question is whether they deserve greater visibility within the overall supervisory rating process.

SBS expressed support for adding a dedicated Technology & Operational Resilience component to the CAMELS rating system, building on a similar recommendation submitted during the public comment period by retired OCC Bank IT Analyst Vincent J. Buono, CISA, CISM. The goal is not to create unnecessary complexity. Rather, it is to acknowledge that technology risk now plays a foundational role in the safety and soundness of financial institutions.

SBS expands on Mr. Buono’s suggestions by recommending a nine-domain structure for a new Technology & Operational Resilience component. These domains are designed to align with existing regulatory expectations while recognizing how technology risk has evolved.

  1. Technology Governance & Risk Management
  2. Information Security Program Management
  3. Cybersecurity Operations & Technical Controls
  4. Third-Party & Cloud Risk Management
  5. Technology Operations & Infrastructure Management
  6. Incident Response & Cyber Recovery
  7. Business Continuity & Operational Resilience
  8. Independent Testing & Assurance
  9. Emerging Technology & Digital Innovation Risk

 

Whether that visibility comes through enhancements to the existing framework or through a separate rating component, the underlying principle remains the same: Technology governance, cybersecurity operations, operational resilience, vendor oversight, and independent validation are not secondary concerns. They are leading indicators of how effectively an institution can identify, manage, and recover from risk.

 

What the Proposed FFIEC CAMELS Changes Mean for Cybersecurity Governance

The financial industry has spent years recognizing cybersecurity as a business risk rather than merely a technical issue. We believe that perspective remains important as regulators consider updates to the CAMELS framework.

Strong cybersecurity governance is not a paperwork exercise. Independent testing is not a checkbox. Operational resilience is not a future consideration.

These disciplines help institutions identify risk, implement controls, validate effectiveness, and improve over time. Together, they directly contribute to financial institutions' ability to operate safely and serve customers reliably.

In modern banking, cybersecurity and technology resilience are not separate from safety and soundness. They are safety and soundness.

The goal is not to wait until a technology failure becomes a financial event. The goal is to identify and address governance, control, and resilience gaps before they become safety-and-soundness concerns.

 

Read SBS's FFIEC Comment Letter

The FFIEC is accepting public comments on the proposed CAMELS revisions through August 17.

We encourage financial institution leaders, board members, CIOs, CISOs, risk professionals, and compliance teams to review the proposal and participate in the process. Thoughtful industry feedback helps shape how supervisory expectations evolve and how technology risk is evaluated in the future.

Read SBS's comment letter and submit feedback through the FFIEC docket before the deadline.

Blog_Lock&Line-Gray

 

avatar

Jon Waldman

Jon Waldman is the Co-Founder and President of SBS CyberSecurity, where he oversees the SBS service teams and the SBS Institute. For more than 20 years, Jon has helped hundreds of organizations identify and understand cybersecurity risks to allow them to make better and more informed business decisions. Jon's passion for cybersecurity training and education led him to be a driving force in the development of the SBS Institute. Designed for the banking industry, the Institute provides specialized cybersecurity education and now offers more than 10 certification courses, with State Association partnerships in 30+ states.

Jon maintains his CISA, CRISC, and CDPSE certifications. He received his Bachelor of Science in Computer Information Systems and his Master of Science in Information Assurance with an emphasis in Banking and Finance Security from Dakota State University, a Center of Academic Excellence in Information Assurance Education designated by the NSA.