logo

Select Sidearea

Populate the sidearea with useful widgets. It’s simple to add images, categories, latest post, social media icon links, tag clouds, and more.
hello@youremail.com
+1234567890

Author: John Moeller

Clients regularly ask me what types of questions regulators are asking or are likely to begin asking about artificial intelligence during examinations. Because there is still relatively little prescriptive examination guidance specific to AI, I find it more useful to focus on the regulatory signals emerging from recent agency documents, supervisory guidance, and public comments rather than trying to predict an exact examiner questionnaire.   Taken together,...

Read More

Ransomware remains one of the most serious cybersecurity threats facing financial institutions. The attack paths are well-documented: stolen credentials, phishing, exposed remote access, weak internal controls — but that familiarity hasn't made organizations less vulnerable. A ransomware event can disrupt operations, limit access to critical systems, trigger customer notification obligations, invite regulatory scrutiny, and force difficult decisions under pressure. The institutions that manage these events best...

Read More

Why industry-specific cybersecurity expertise matters. Not all cybersecurity threats are created equal. Different industries face distinct cybersecurity challenges shaped by regulations, cybersecurity compliance requirements, and evolving cybersecurity threats. Generic cybersecurity vendors often take a one-size-fits-all approach which simply does not work. Failing to account for the unique cybersecurity threats and regulatory complexities that financial institutions and healthcare organizations must navigate can leave these organizations at...

Read More

Why industry-specific cybersecurity expertise matters. Not all cybersecurity threats are created equal. Different industries face distinct cybersecurity challenges shaped by regulations, cybersecurity compliance requirements, and evolving cybersecurity threats. Generic cybersecurity vendors often take a one-size-fits-all approach which simply does not work. Failing to account for the unique cybersecurity threats and regulatory complexities that financial institutions and healthcare organizations must navigate can leave these organizations at...

Read More

Cost-effective cybersecurity services do not need to come with a high price tag. For years, I have said that in cybersecurity consulting, you get what you pay for. Many traditional cybersecurity vendors offer services at a low cost, but their service quality is often lacking which can put your organization at risk. On the other hand, legacy accounting firms typically provide high-quality services—at a steep...

Read More

Cybersecurity should never be a check-the-box exercise. Yet, too often, organizations find themselves stuck with auditors using generic IT audit work programs that fail to address the organization’s specific risks, industry requirements, and business operations. Many legacy accounting firms and traditional cybersecurity vendors often rely on standardized checklists and generic work programs. While this approach might be efficient for them, it often fails to provide...

Read More

Cyber threats are becoming more sophisticated every day, targeting organizations of all sizes with ransomware, phishing attacks, cybersecurity supply chain compromises, and regulatory penalties for non-compliance. With so much at stake, you need a cybersecurity partner that brings real expertise—not just a name-brand firm that pushes critical work to junior staff. One of the most frustrating aspects of working with legacy accounting firms and traditional...

Read More