The division leverages federal regulations utilized by respective Federal depository banking agencies.  These regulations address standards for developing and implementing administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of customer / member information.  Additionally, these regulations also address standards with respect to the proper disposal of consumer information and response programs for unauthorized access to customer / member information, including customer notification.

Banks
Appendix B to Part 364 / Supplement A to Appendix B to Part 364   

Credit Unions
Appendix A to Part 748   /   Appendix B to Part 748


Communications


Actively Exploited Vulnerability Associated with N-central Software Used by Institutions and Managed Service Providers

We would like to make you aware of potential action needed from your institution to address a recent software vulnerability that is being actively exploited against U.S. financial institutions. On August 1, N-able, Burlington, MA, disclosed a high severity vulnerability impacting all current versions of its N-central product, including both hosted and on prem deployments. This software is used to monitor, patch, and remotely access servers and endpoints. The software is used by:

1. Some managed service providers (MSPs) that are managing an institution’s internal computer network, and

2. Some institutions that manage their own networks remotely (e.g., an institution managing networks in branch locations).

This vulnerability, identified as CVE-2026-18577, can give attackers full and unrestricted access to the MSP or institution’s remote management and monitoring console. To date, there have been sporadic reports of exploitation of this vulnerability across the country, and public reporting from Microsoft notes of potential exploitation of this vulnerability by threat actors to deliver a previously unknown ransomware strain.

Institutions and MSPs may be using either N-central hosted instances (known as NCOD) or versions installed and managed on their premises (N-central on-prem instances). 

ACTIONS TO TAKE NOW:

• Ensure that all on-prem instances of this software, if applicable, have been appropriately patched with the August 6 hotfix and that any additional threat mitigation steps identified by the vendor have been followed. All on-prem instances of the software require manual patching. Institution and/or MSP users should apply the most recent hotfix found at N-central Security Update – August 10, 2026 - N-able. Notably, there have been two hotfixes released, but the most recent version dated August 6 must be applied even if the organization has already applied the earlier hotfix. According to N-able, mitigations have already been applied for users of N-central hosted instances.

• If your institution is using an MSP for network management, you should contact your provider to determine if they are using N-central software and, if so, if their version of the software has been appropriately patched and the threat remediated. 

• If your institution is using any version of N-central software, you should leverage N-able’s free detection tool and closely follow all developing vendor recommended remediation actions to help identify any potential signs of compromise. This tool is publicly available on N-able’s Developer website. It is important to note that the hotfix closes the vulnerability but does not remove a threat actor who may already be present in the environment. Additional mitigation steps are needed to fully address the threat associated with this vulnerability.

CSBS Cyber Hygiene Awareness Campaign for Financial Institutions

CSBS has developed series of resources that will be shared throughout the upcoming year to promote the ongoing awareness of cyber hygiene for financial institutions.  These communications will be shared on this page via the links below.  Please check back periodically for new publications as they are released. 

Series 1 - Cyber Hygiene Actions Your Institution Should Take Today [pdf]
Series 2 - End-of-Life Management & Multi-Factor Authentication [zip]
Series 3 - Vulnerability & Patch Management / Event Logging & Threat Detection [zip]
Series 4 - Cybersecurity Awareness Training & IT Asset Management (ITAM) [zip]
Series 5 - Data Backup & Threat Intelligence [zip]
Series 6 - TPRM & Incident Response [zip]   

Credit Union Artificial Intelligence (AI) Resources

The National Credit Union Administration (NCUA) launched a webpage on ncua.gov that provides credit unions with resources related to the use of Artificial Intelligence (AI). The page was created to assist credit unions as they adopt innovative AI technology and may be useful in evaluating the distinct AI-related challenges. The new webpage provides resources on risk management considerations specific to AI, which may help credit unions make informed decisions when implementing AI or partnering with AI service providers. The resources on the webpage address key areas including AI implementation, risk management, data security, use cases, and cybersecurity risks. The AI resources page may have information of interest to all credit unions, whether the credit union is beginning to explore AI solutions or is seeking to enhance existing AI risk management practices. 

Link to the NCUA AI Resources Page 

Federal Financial Institutions Examination Council (FFIEC) – Cybersecurity Assessment Tool (CAT) Sunset

On August 29, 2024, the Federal Financial Institutions Examination Council (FFIEC) released a statement announcing the sunsetting of the FFIEC Cybersecurity Assessment Tool (CAT), which is no longer available on their website effective August 31, 2025.  While the FFIEC has determined not to update the CAT, new and updated government and industry resources are available that financial institutions can leverage to better manage cybersecurity risks.  For more information, please refer to the CAT Sunset Statement by the FFIEC [PDF]  and to the Frequently Asked Questions (FAQ) created by the Conference of State Bank Supervisors (CSBS) [PDF] to help answer any questions.

CISA - Safeguarding Our Critical Infrastructure

The Cybersecurity and Infrastructure Security Agency (CISA) and the Office of the Director of National Intelligence, released guidance to assist critical infrastructure owners and operators to detect and mitigate efforts by foreign intelligence entities to disrupt U.S. critical infrastructure. 

Get a copy of the document here [pdf]


Cybersecurity Assessment Frameworks


The above list represents the most common frameworks utilized.  The State of Minnesota does not endorse any particular tool. Each institution should select one that best fits their individual needs, capabilities, and risk appetite.  Please see Frequently Asked Questions (FAQ) created by the Conference of State Bank Supervisors (CSBS) [pdf]  for more information.

Additional Assessment Tools