Stressed businessman checking time with deadline pressure, financial documents, and secure bank vault in background.

How Often Should a Community Bank Perform a Cybersecurity Risk Assessment?

July 28, 2026

How Frequently Community Banks Should Assess Cybersecurity Risk

A community bank should complete a formal cybersecurity risk assessment at least once every 12 months and update it whenever a significant change affects the institution’s systems, services, data, vendors or threat exposure.

Annual review is the minimum practical starting point, not the complete schedule. A bank should reassess relevant risks after events such as a core conversion, Microsoft 365 migration, branch opening, merger, ransomware incident, new online banking service or change in a critical technology provider.

For a 25–50 employee community bank, the most effective assessment does more than generate a risk score. It identifies critical assets, evaluates credible threats, measures existing safeguards, documents remaining risk and creates a prioritized remediation plan with owners and deadlines.

What Is a Cybersecurity Risk Assessment?

A cybersecurity risk assessment is a structured evaluation of the ways technology failures, cyberattacks, human mistakes and third-party disruptions could affect the bank’s information and operations.

The assessment should help leadership answer five questions:

  1. Which systems, services and information are most important?
  2. Which threats could compromise or disrupt them?
  3. Which safeguards are currently reducing those risks?
  4. What risk remains after those safeguards are considered?
  5. What additional action should the bank take?

A risk assessment is not the same as a vulnerability scan, penetration test, compliance checklist or security audit. Those activities may supply important evidence, but the risk assessment connects technical findings to the bank’s operations, customers, regulatory responsibilities and strategic priorities.

When Should a Community Bank Update Its Risk Assessment?

A community bank should follow a two-part schedule:

  • Complete a comprehensive review at least annually.
  • Update affected sections after every material change or significant incident.

A bank should not wait for the next annual review when its environment or risk profile has changed substantially.

Changes That Should Trigger an Updated Assessment

  • Adding online, mobile or digital banking services
  • Changing the core banking platform
  • Moving applications or data to the cloud
  • Implementing Microsoft 365 or changing its security configuration
  • Opening, closing or relocating a branch
  • Completing a merger or acquisition
  • Introducing remote or hybrid work
  • Connecting a new critical third-party provider
  • Replacing the managed IT or cybersecurity provider
  • Changing remote-access technology
  • Implementing artificial intelligence tools
  • Experiencing a significant security incident
  • Discovering a material vulnerability
  • Receiving a major audit or examination finding
  • Changing cyber-insurance requirements
  • Introducing new payment, lending or customer-service processes

The update does not always require rewriting the entire assessment. The bank may evaluate the affected system, data, threats, controls and residual risk while preserving unaffected portions of the broader assessment.

The Eight-Part Cybersecurity Risk Assessment Framework

1. Define the Scope and Business Objectives

Begin by defining what the assessment covers. A vague scope creates unreliable results and may leave important systems unexamined.

The scope should identify:

  • Legal entities and business units
  • Branches and physical locations
  • Employees, contractors and third parties
  • Information systems and cloud platforms
  • Customer-facing applications
  • Networks and remote-access services
  • Sensitive information
  • Critical vendors
  • Backup and recovery infrastructure

The bank should also define the business goals of the assessment. Those goals may include preparing for an examination, evaluating a new service, addressing audit findings, supporting cyber-insurance renewal or establishing a multi-year security roadmap.

2. Inventory Critical Assets and Information

A bank cannot assess risk accurately without knowing what it operates and where sensitive information resides.

The asset inventory should include:

  • Servers and virtual machines
  • Employee workstations and laptops
  • Firewalls, switches and wireless systems
  • Mobile devices
  • Microsoft 365 and other cloud platforms
  • Core banking systems
  • Online and mobile banking services
  • Payment and wire-transfer systems
  • Loan and document-management applications
  • Backup platforms
  • Security tools
  • Third-party connections
  • Supported and unsupported software

Classify Information by Sensitivity

The assessment should identify where the bank stores, processes and transmits information such as:

  • Customer account information
  • Social Security and tax identification numbers
  • Payment-card information
  • Loan records
  • Wire-transfer information
  • Authentication credentials
  • Employee records
  • Financial reports
  • Security configurations

Data classification helps the institution apply stronger controls to systems containing the most sensitive information.

3. Identify Credible Threats

The assessment should focus on credible events that could affect the bank rather than an abstract list of every possible cyber threat.

External Threats

  • Ransomware
  • Phishing and business email compromise
  • Credential theft
  • Account takeover
  • Malware
  • Internet-facing system exploitation
  • Denial-of-service attacks
  • Data theft
  • Supply-chain compromise
  • Payment and wire fraud

Internal Threats

  • Employee mistakes
  • Unauthorized access
  • Excessive user privileges
  • Malicious insiders
  • Lost or stolen devices
  • Improper data sharing
  • Misconfigured cloud services
  • Unapproved software
  • Delayed employee termination

Operational and Environmental Threats

  • Hardware failure
  • Internet or telecommunications outages
  • Cloud-service disruption
  • Critical vendor failure
  • Power outages
  • Fire, flood or severe weather
  • Human error during a system change
  • Loss of key personnel

The bank should use information from security alerts, fraud reports, help desk trends, vulnerability findings, industry intelligence and previous incidents to determine which threats are most relevant.

4. Identify Vulnerabilities and Control Weaknesses

A vulnerability is a weakness that may allow a threat to cause harm. Vulnerabilities may be technical, procedural or organizational.

Common examples include:

  • Unsupported operating systems
  • Missing security patches
  • Weak or reused passwords
  • Incomplete multifactor authentication coverage
  • Excessive administrative privileges
  • Unencrypted laptops
  • Permissive firewall rules
  • Unsecured remote access
  • Inadequate email filtering
  • Unmonitored cloud activity
  • Untested backups
  • Outdated incident-response contacts
  • Unreviewed third-party access
  • Incomplete employee training
  • Missing asset or software inventories

Evidence may come from vulnerability scans, penetration tests, configuration reviews, access reports, audit findings, recovery tests and interviews with employees and vendors.

911 IT’s cybersecurity risk assessment helps organizations identify vulnerabilities, credential exposure and potential areas of financial liability.

5. Evaluate Existing Controls

The bank should identify the safeguards already reducing each risk and determine whether those safeguards are designed and operating effectively.

Administrative Controls

  • Policies and procedures
  • Employee training
  • Background screening
  • Access approval
  • Vendor oversight
  • Incident-response planning
  • Board and management reporting

Technical Controls

  • Multifactor authentication
  • Endpoint detection and response
  • Email filtering
  • Firewalls and network segmentation
  • Encryption
  • Security monitoring
  • Vulnerability scanning
  • Patch management
  • Data-loss prevention
  • Protected backups

Physical Controls

  • Facility access restrictions
  • Visitor management
  • Security cameras
  • Server room protections
  • Environmental monitoring
  • Secure equipment disposal

The assessment should distinguish between a control that exists on paper and one that operates consistently. A policy requiring quarterly access reviews does not reduce risk when the reviews are not completed or documented.

Test Control Effectiveness

Representative testing may include:

  • Verifying multifactor authentication coverage
  • Reviewing terminated-user accounts
  • Confirming that critical devices receive patches
  • Testing security alert escalation
  • Restoring data from backup
  • Reviewing administrator accounts
  • Examining firewall changes
  • Conducting a phishing simulation
  • Testing the incident-response plan

6. Calculate Inherent and Residual Risk

Inherent risk is the exposure associated with an activity before safeguards are considered. Residual risk is the amount that remains after existing controls are applied.

For example, online banking may have high inherent risk because it is internet-accessible, processes sensitive information and may be targeted for fraud. Strong authentication, monitoring and transaction controls may reduce that risk, but they do not remove it entirely.

A Simple Risk Calculation

A community bank may rate each scenario using:

  • Likelihood: How probable is the event?
  • Impact: How severe would the result be?
  • Control effectiveness: How well do existing safeguards reduce the risk?
Likelihood Description
Low The event is unlikely under current conditions
Moderate The event is plausible and has occurred in similar environments
High The event is expected, frequent or supported by active threat activity
Impact Description
Low Limited operational effect with little or no sensitive data involved
Moderate Meaningful disruption, financial cost or restricted information exposure
High Major operational outage, customer harm, fraud, regulatory impact or sensitive data exposure

The rating method may be qualitative or quantitative. Consistency and documented reasoning are more important than creating a complicated mathematical model that leadership cannot explain.

7. Create a Prioritized Remediation Plan

The assessment should produce clear decisions and actions. A report that identifies dozens of weaknesses without ranking them gives leadership little guidance about where to begin.

Each corrective action should include:

Field What to document
Risk The threat, vulnerability and potential business impact
Recommended control The safeguard or process improvement being proposed
Priority Critical, high, moderate or low
Owner The person accountable for completing the action
Target date The approved deadline
Interim protection Compensating controls used before final remediation
Status Not started, in progress, delayed or completed
Validation Evidence showing that remediation worked

How to Set Remediation Priorities

Prioritize an issue based on:

  1. Operational importance: Could it disrupt critical banking services?
  2. Data sensitivity: Could it expose customer or employee information?
  3. Threat activity: Is the weakness actively targeted or exploited?
  4. Exposure: Is the system accessible from the internet or a third party?
  5. Control dependency: Would failure weaken several other safeguards?
  6. Remediation effort: Can the bank reduce significant risk quickly?

Critical risk should not remain open solely because the permanent solution requires a large project. The bank should consider temporary restrictions, additional monitoring, system isolation or other compensating controls.

8. Report, Approve and Monitor the Results

Management and the board should receive reporting appropriate to their responsibilities. Leadership does not need every technical scan result, but it should understand the most important risks and corrective decisions.

Management Reporting Should Include

  • Scope and methodology
  • Significant changes since the previous assessment
  • Top risks
  • Control weaknesses
  • Overdue remediation
  • Resource requirements
  • Risk exceptions
  • Recommended projects

Board Reporting Should Include

  • The institution’s most material technology risks
  • Significant incidents and trends
  • High-risk findings
  • Management’s remediation plan
  • Material vendor concerns
  • Decisions requiring funding or risk acceptance

Meeting minutes should show that leadership received the results, asked appropriate questions and approved significant decisions.

What Should a Community Bank Cybersecurity Assessment Cover?

A comprehensive assessment should address the following domains.

Governance and Oversight

  • Board reporting
  • Management responsibility
  • Policies and standards
  • Risk acceptance
  • Security budgeting
  • Qualified staffing

Asset and Configuration Management

  • Hardware inventory
  • Software inventory
  • Supported operating systems
  • Secure configuration standards
  • Change management
  • Network diagrams

Identity and Access Management

  • Employee onboarding and termination
  • Multifactor authentication
  • Privileged accounts
  • Remote access
  • Access reviews
  • Service accounts

Endpoint, Network and Cloud Security

  • Endpoint detection and response
  • Firewalls
  • Network segmentation
  • Wireless security
  • Microsoft 365 configuration
  • Cloud access and sharing

Vulnerability and Patch Management

  • Scanning frequency
  • Patch status
  • Unsupported systems
  • Penetration testing
  • Remediation verification
  • Approved exceptions

Email and Employee Security

  • Phishing protection
  • Domain email authentication
  • Security awareness training
  • Phishing simulations
  • Payment verification procedures
  • Incident reporting

Monitoring and Incident Response

  • 24/7 security monitoring
  • Log collection
  • Alert escalation
  • Containment authority
  • Incident documentation
  • Tabletop exercises

Business Continuity and Recovery

  • Backup scope
  • Backup protection
  • Recovery priorities
  • Restoration testing
  • Alternative work procedures
  • Critical vendor dependencies

Third-Party Risk

  • Critical vendor inventory
  • Security due diligence
  • Contract requirements
  • Independent assurance reports
  • Incident-notification obligations
  • Concentration risk
  • Termination planning

911 IT’s managed cybersecurity services can help address technical weaknesses identified across endpoint, email, firewall, cloud and monitoring controls.

Which Risk Assessment Framework Should a Bank Use?

A bank may use an established framework, a regulator-informed process or a methodology developed for its own size and complexity. The selected approach should provide enough structure to produce consistent and defensible decisions.

Potential sources include:

  • NIST Cybersecurity Framework
  • Cyber Risk Institute Profile
  • CISA Cyber Resilience Review
  • Center for Internet Security Controls
  • Applicable FFIEC and banking-agency guidance
  • A qualified third-party risk assessment methodology

The FFIEC Cybersecurity Assessment Tool was sunset on August 31, 2025. Banks should not assume that completing an old CAT spreadsheet represents a current or complete risk-management process. Institutions may still use relevant concepts from prior assessments, but should select and document a current approach appropriate to their environment.

How to Choose a Framework

Evaluate whether the approach:

  • Fits the bank’s size and complexity
  • Addresses financial-services threats
  • Distinguishes inherent and residual risk
  • Connects risks to controls
  • Supports measurable remediation
  • Can be explained to management and the board
  • Produces evidence useful for examinations
  • Can be updated after significant changes

A framework should make the assessment more consistent. It should not turn the process into a checklist that ignores the bank’s actual systems and business risks.

Cybersecurity Risk Assessment Versus Other Security Reviews

Review Primary purpose
Cybersecurity risk assessment Identifies threats, safeguards, business impact and residual risk
Vulnerability scan Identifies known technical weaknesses and missing patches
Penetration test Attempts to demonstrate whether selected weaknesses can be exploited
Security audit Evaluates controls against defined criteria or requirements
Compliance assessment Compares practices with specific legal, regulatory or contractual obligations
Business-impact analysis Determines the operational effect of disruptions and recovery priorities
Vendor-risk review Evaluates risks created by a third-party relationship

These activities complement one another. For example, a vulnerability scan may identify an unpatched server, while the risk assessment explains why that server matters, which services depend on it and how quickly the weakness should be corrected.

Should the Bank Complete the Assessment Internally or Use a Third Party?

A community bank may perform the assessment internally, engage an independent specialist or use a combined approach.

Internal Assessment Advantages

  • Employees understand daily operations
  • The bank retains direct ownership of the process
  • Updates may be completed more quickly
  • Leadership can incorporate business context directly

Internal Assessment Limitations

  • Employees may overlook familiar weaknesses
  • Specialized cybersecurity expertise may be limited
  • Technical evidence may be incomplete
  • Staff may be evaluating controls they personally manage

Third-Party Assessment Advantages

  • Independent perspective
  • Experience with other financial environments
  • Specialized tools and security expertise
  • Structured documentation
  • Additional credibility for leadership and auditors

Third-Party Assessment Limitations

  • The assessor may not understand every business process initially
  • A generic assessment may miss institution-specific risks
  • The bank must still own remediation and risk decisions

A practical approach is to combine internal business knowledge with independent technical validation. Bank management should remain actively involved even when an outside provider performs the assessment.

Questions to Ask a Cybersecurity Risk Assessment Provider

  1. Do you have experience with banks or financial organizations?
  2. Which framework or methodology will you use?
  3. Will you evaluate both inherent and residual risk?
  4. Which technical tests are included?
  5. Will you review Microsoft 365, remote access and cloud systems?
  6. Will you assess third-party risk?
  7. How will findings be prioritized?
  8. Will each recommendation include an owner and target timeframe?
  9. Will you provide an executive summary for the board?
  10. Can you help validate completed remediation?
  11. How will sensitive assessment information be protected?
  12. Which activities are excluded from the quoted price?

Common Cybersecurity Risk Assessment Mistakes

Updating Only the Date

An assessment must reflect current systems, services, threats and vendors. Changing the cover page does not demonstrate meaningful review.

Using an Incomplete Asset Inventory

Unknown devices, cloud services and third-party connections create unknown risk. Inventory accuracy should be verified before risk ratings are finalized.

Confusing Inherent Risk With Residual Risk

Inherent risk evaluates the activity before controls. Residual risk reflects what remains after safeguards are applied. Combining the two makes it difficult to determine whether controls are effective.

Rating Every Issue as High

When every finding receives the same priority, leadership cannot allocate resources effectively. Ratings should reflect likelihood, impact, exposure and control strength.

Relying Entirely on Questionnaires

Interviews and questionnaires should be supported by technical reports, configuration reviews, testing and operational evidence.

Ignoring Third Parties

A large portion of the bank’s technology may be operated by outside providers. Critical vendors, cloud platforms and connected services should be included in the assessment.

Producing No Remediation Plan

A list of findings is not a risk-management program. Each significant weakness should have an accountable owner, deadline and validation method.

Closing Findings Without Testing

A completed ticket does not prove that risk was reduced. The bank should verify that the original weakness has been corrected.

Failing to Report Results to Leadership

Management and the board need enough information to approve priorities, allocate resources and accept significant residual risk.

A 30-Day Cybersecurity Risk Assessment Process

Days 1–5: Define Scope and Gather Records

  • Identify systems, locations and vendors in scope
  • Collect prior assessments and audit findings
  • Confirm asset and software inventories
  • Gather network and data-flow diagrams
  • Identify critical information and business processes

Days 6–12: Identify Threats and Vulnerabilities

  • Review security incidents and fraud activity
  • Analyze vulnerability and patch reports
  • Review Microsoft 365 and identity controls
  • Evaluate endpoint, firewall and email protection
  • Interview business and technology owners

Days 13–18: Evaluate Controls

  • Review access approvals and terminations
  • Confirm multifactor authentication coverage
  • Test security-alert escalation
  • Review employee training
  • Examine third-party controls and contracts
  • Test representative backups

Days 19–23: Rate and Prioritize Risks

  • Assign likelihood and impact ratings
  • Evaluate control effectiveness
  • Calculate residual risk
  • Identify quick improvements
  • Prioritize major projects

Days 24–27: Build the Remediation Plan

  • Assign accountable owners
  • Establish target dates
  • Define interim safeguards
  • Estimate budgets and resources
  • Document risk-acceptance decisions

Days 28–30: Report and Approve

  • Prepare the executive summary
  • Present significant risks to management
  • Brief the board or responsible committee
  • Approve funding and priorities
  • Schedule recurring progress reviews

Real Results From Security Assessments

One 911 IT client reported that a security audit identified weaknesses that could then be corrected before they developed into larger problems. The client described the practical information and peace of mind produced by the assessment as significantly more valuable than its cost.

Financial-services clients also describe 911 IT as proactive in recommending security improvements rather than waiting for a system failure or incident. One client credited the team with supporting network protocols associated with strict IRS and PCI security requirements, while another valued receiving recommendations informed by 911 IT’s experience with other financial organizations.

Long-term clients repeatedly emphasize that 911 IT takes ownership of issues, responds promptly and follows work through to complete resolution. That follow-through is essential because an assessment creates value only when identified weaknesses are corrected and verified.

Learn more about 911 IT’s experience providing IT support for CPAs and financial firms.

Frequently Asked Questions

Is an annual cybersecurity risk assessment enough?

An annual comprehensive review is a practical minimum, but the bank should also update the assessment after material technology, business, vendor or threat changes. Continuous monitoring and targeted assessments should occur throughout the year.

Who should own the risk assessment?

Management should own the risk-management process. IT employees, the information-security officer, compliance personnel, business leaders, vendors and independent specialists may contribute evidence and expertise.

Does the board need to approve the assessment?

The appropriate approval process depends on the bank’s governance structure and policies. The board or responsible committee should receive meaningful reporting about material risks, significant findings and management’s remediation plan.

How long should a cybersecurity assessment take?

A focused assessment for a 25–50 employee bank may take several weeks, depending on scope, documentation quality, system complexity and the availability of technical evidence. A rushed questionnaire completed in a few hours is unlikely to provide a complete picture.

Is a vulnerability scan a cybersecurity risk assessment?

No. A vulnerability scan identifies selected technical weaknesses. A risk assessment evaluates threats, business impact, existing controls and remaining exposure across technical, administrative and third-party areas.

Should every finding be fixed immediately?

Critical risks should receive prompt attention. Other findings should be prioritized based on likelihood, impact, exposure and available safeguards. Delayed remediation should have an approved plan and interim protection.

Can the bank use its previous FFIEC Cybersecurity Assessment Tool results?

Previous results may provide useful historical context, but the FFIEC Cybersecurity Assessment Tool was sunset in 2025. The bank should use a current methodology and ensure that its assessment reflects present systems, threats and controls.

Can a managed IT provider perform the assessment?

An MSP can contribute technical expertise and evidence. The bank should consider whether independent validation is necessary when the same provider is evaluating controls it implemented or manages.

What should happen after the assessment?

The bank should approve priorities, assign owners, track remediation and verify completed work. Material risks and overdue actions should be reported regularly to management and the board.

Turn the Risk Assessment Into a Security Roadmap

A cybersecurity risk assessment should help the bank make better decisions. It should identify where the institution is most exposed, which existing safeguards work and where investments will reduce the greatest amount of risk.

911 IT provides cybersecurity assessments, managed IT, 24/7 threat monitoring, cloud management and business-continuity services for organizations in Salt Lake City and throughout Utah. Our local team helps financial organizations identify vulnerabilities, prioritize corrective action and maintain the technical evidence required to demonstrate progress.

Request a confidential cybersecurity risk assessment to identify vulnerabilities, credential exposure and areas of potential financial liability. You can also schedule a 10-minute discovery call or contact 911 IT to discuss your bank’s assessment requirements.

This article provides general educational information and is not legal, regulatory or compliance advice. Financial institutions should consult their primary regulator, legal counsel and qualified compliance professionals regarding requirements that apply to their circumstances.