Community banks, credit unions, RIAs
The examination, the ISE, Regulation S-P, and the document request list. We know the paper each one arrives on.
What arrives
- The exam, and the MRA
- The examination itself, and the Matters Requiring Attention it leaves behind. The FFIEC Cybersecurity Assessment Tool sunset on 31 August 2025, and the expectation to measure and manage did not.
- The ISE
- The NCUA Information Security Examination, with its SCUEP, CORE and CORE+ tiers, each control needing evidence in hand.
- Reg S-P
- The SEC Regulation S-P amendments. An incident response program, 30-day individual notice, and a compliance date of 3 June 2026 for smaller entities.
- The document request list
- The SEC Division of Examinations request list, including a complete inventory of every vendor with access to customer information.
- The 72-hour rule
- NCUA cyber incident notification under 12 CFR Part 748, running from when the incident is reasonably believed to have occurred.
What the Institute has found here
The Vigil LibraryInstitute
The Compliance Mirage: Why Regulatory Checkboxes Fail to Predict Breach Outcomes
Policy · June 2026
Read itInstitute
The SMB Security Paradox
Analyst · February 2026
Read itInstitute
AI and the Expanding Attack Surface: How Generative Tool Adoption Creates New Risk Vectors in Mid-Market Businesses
Analyst · June 2026
Read itStart the conversation
A short, plain conversation about the outside view, with an advisor who knows the paper.

