Industry insiders say FFIEC’s review of existing guidance suggests changes are imminent. The ICBA’s Cary Whaley hopes regulators place more responsibility on banks’ third-party service providers. Vendors that provide core processing and online services to community banks should be held accountable for ensuring technology and platforms are up-to-date, he says. Even a single breach could put a small bank out of business, Whaley says. “We all have to be protected,” he says. But how much security does every institution need? That’s a relative question.”]
Source: https://www.bankinfosecurity.com/ffiec-vendors-role-in-web-authentication-a-3322