Minnesota’s Nonbank Data Security Law (Minnesota Statutes Chapter 46A), passed by the 2024 Minnesota Legislature, adopts a model law proposed by the Conference of State Bank Supervisors (CSBS). The law tracks the updated federal Safeguards Rule.

NonBank Data Security Law [PDF]     Minnesota Statutes Chapter 46A

Communications


Actively Exploited Vulnerability Associated with N-central Software Used by Institutions and Managed Service Providers

We would like to make you aware of potential action needed from your institution to address a recent software vulnerability that is being actively exploited against U.S. financial institutions. On August 1, N-able, Burlington, MA, disclosed a high severity vulnerability impacting all current versions of its N-central product, including both hosted and on prem deployments. This software is used to monitor, patch, and remotely access servers and endpoints. The software is used by:

1. Some managed service providers (MSPs) that are managing an institution’s internal computer network, and

2. Some institutions that manage their own networks remotely (e.g., an institution managing networks in branch locations).

This vulnerability, identified as CVE-2026-18577, can give attackers full and unrestricted access to the MSP or institution’s remote management and monitoring console. To date, there have been sporadic reports of exploitation of this vulnerability across the country, and public reporting from Microsoft notes of potential exploitation of this vulnerability by threat actors to deliver a previously unknown ransomware strain.

Institutions and MSPs may be using either N-central hosted instances (known as NCOD) or versions installed and managed on their premises (N-central on-prem instances). 

ACTIONS TO TAKE NOW:

• Ensure that all on-prem instances of this software, if applicable, have been appropriately patched with the August 6 hotfix and that any additional threat mitigation steps identified by the vendor have been followed. All on-prem instances of the software require manual patching. Institution and/or MSP users should apply the most recent hotfix found at N-central Security Update – August 10, 2026 - N-able. Notably, there have been two hotfixes released, but the most recent version dated August 6 must be applied even if the organization has already applied the earlier hotfix. According to N-able, mitigations have already been applied for users of N-central hosted instances.

• If your institution is using an MSP for network management, you should contact your provider to determine if they are using N-central software and, if so, if their version of the software has been appropriately patched and the threat remediated. 

• If your institution is using any version of N-central software, you should leverage N-able’s free detection tool and closely follow all developing vendor recommended remediation actions to help identify any potential signs of compromise. This tool is publicly available on N-able’s Developer website. It is important to note that the hotfix closes the vulnerability but does not remove a threat actor who may already be present in the environment. Additional mitigation steps are needed to fully address the threat associated with this vulnerability.

CSBS Cyber Hygiene Awareness Campaign for Financial Institutions

CSBS has developed series of resources that will be shared throughout the upcoming year to promote the ongoing awareness of cyber hygiene for financial institutions.  These communications will be shared on this page via the links below.  Please check back periodically for new publications as they are released.

Series 1 - Cyber Hygiene Actions Your Institution Should Take Today [pdf]
Series 2 - End-of-Life Management & Multi-Factor Authentication [zip]
Series 3 - Vulnerability & Patch Management / Event Logging & Threat Detection [zip]
Series 4 - Cybersecurity Awareness Training & IT Asset Management (ITAM) [zip]
Series 5 - Data Backup & Threat Intelligence [zip]
Series 6 - TPRM & Incident Response [zip]  

CISA - Safeguarding Our Critical Infrastructure

The Cybersecurity and Infrastructure Security Agency (CISA) and the Office of the Director of National Intelligence, released guidance to assist critical infrastructure owners and operators to detect and mitigate efforts by foreign intelligence entities to disrupt U.S. critical infrastructure. 

Get a copy of the document here [PDF]

Updated Nonbank Ransomware Self-Assessment Tool (R-SAT) – Available now!

Download the updated Nonbank Ransomware Self-Assessment Tool (R-SAT) today to evaluate your institution’s cybersecurity posture. This critical and repeatable cybersecurity tool is easy to use, and designed to assist nonbank companies of all sizes assess their readiness for ransomware attacks.  This updated Nonbank R-SAT was developed collaboratively by CSBS, state bank examiners, the Bankers Electronic Task Force, and the U.S. Secret Service in response to the increasing cyber threat environment and evolutions in company control environments.

Link to the updated Ransomware Self-Assessment Tool (R-SAT)


Information Technology Resources