Texas Community Banks Face a Cybersecurity Reckoning — Here's How to Respond
With the FFIEC CAT retired, GLBA 2023 amendments in force, and TDPSA active, TX community banks face a compounding compliance burden with no SOC to manage it. Here's what you need to do now.
In May 2026, Texas Capital Bank disclosed a data breach affecting 86,067 Texans. Names and Social Security numbers, in the wrong hands. By July, a class action lawsuit had been filed in federal court.
This is not a story about a bank that got unlucky. It's a story about what happens when institutions with $35 billion in assets still don't have adequate cybersecurity — and what that means for every community bank in Texas that shares a correspondent, a regulator, or a regulator's attention with them.
The Threat Is Already Inside the Building
The Texas Department of Banking — the agency that supervises the 214 state-chartered banks holding $443.4 billion in assets across this state — put it plainly in January 2025: cybersecurity is "the greatest risk facing the financial services industry and possibly the country."
The threat isn't generic. Two axes matter right now:
Volt Typhoon, operating from the People's Republic of China, has been pre-positioning inside U.S. critical infrastructure since at least 2021. The Texas DOB's own Director of Cybersecurity, Phillip Hinkle, described this as "a reassessment of the approach used by both industry and regulators."
Volt Typhoon uses legitimate system tools — PowerShell, WMI, built-in Windows administration — to move laterally without deploying detectable malware. Basic signature tools miss it. The only effective defense is continuous monitoring of administrative activity and 12-month log retention. Most community banks retain logs 30 to 90 days. That gap is exactly what Volt Typhoon exploits.
Ransomware groups specifically target financial institutions because they have cyber insurance and high willingness to pay. The FDIC's own guidance acknowledges that smaller institutions face the same threat actors as large banks — with a fraction of the security resources.
Texas ranked #2 nationally in IC3 losses in the last reporting cycle, with $1.35 billion in losses and 41,557 complaints. Community banks are the originating institution for most of the wire fraud that flows through that number.
The TX DOB's Director of IT Security Examinations, Ruth Norris, has been explicit: MSPs "often require full access/control of your network." If your MSP gets compromised, your core banking network is compromised.
A majority of sub-$2B Texas community banks rely on MSPs for day-to-day IT management. Most of those MSP relationships include privileged credentials — domain admin or equivalent — that are rarely rotated and frequently reused across customer environments. Examiners are now specifically probing MSP access controls, vendor network segmentation, and the compensating controls you've put in place.
The FFIEC CAT Is Gone. Now What?
The FFIEC Cybersecurity Assessment Tool officially sunset on August 31, 2025. The FDIC, OCC, and Federal Reserve have all moved examiners to NIST CSF 2.0, the CRI Cyber Profile, or CIS Controls v8 as the new baseline. The TX DOB's August 2024 Industry Notice was direct: banks should transition now and examiners will probe four CISA fundamentals as the practical proxy for maturity:
- Patching — critical vulnerabilities patched within 30 days
- Multi-factor authentication — all accounts accessing information systems
- Logging — and specifically logging routine administrative activity, not just security events
- End-of-life system management — no more running Windows Server 2012 R2 on life support
The 2026 FDIC exam framework replaced the old URSIT rating with a single overall IT rating. The stakes are higher. Specific examination questions now include:
- Privileged access management (not just whether logging exists — whether routine administrative activity is logged and retained)
- MSP access controls and vendor network segmentation
- Volt Typhoon threat awareness and response posture
Community banks that haven't formally mapped their controls to NIST CSF 2.0 are already behind. The transition doesn't happen at the next exam cycle — it's happening during it.
GLBA Safeguards Rule: What the 2023 Amendments Actually Require
The FTC's Standards for Safeguarding Customer Information, amended in 2023 and effective June 9, 2023, added meaningful new requirements for banks and non-banking financial institutions:
- Written incident response plan, tested, covering specific scenarios including ransomware
- Annual penetration testing (not optional, not advisory — required)
- MFA required for all accounts that access information systems
- Encryption of all customer data at rest and in transit
- 30-day FTC breach notification for breaches affecting 500+ consumers
Penalties are not theoretical. Up to $100,000 per willful violation. Individual officer and director personal liability. State AG enforcement actions — Texas AG Ken Paxton's office has been active. And enforcement actions are public records. They show up in correspondent bank reviews, cyber insurance underwriting, and M&A due diligence.
Every community bank examiner encounter is now effectively a cybersecurity exam. The days of IT being a back-office function are over.
Texas Has Its Own Rules — And Its Own Enforcement
Beyond the federal framework, Texas has layered on:
Governed by Texas Business & Commerce Code §541 (SB 2105, signed by Governor Abbott June 18, 2023). Administered by the Texas AG. Banks handling typical consumer deposit volumes will almost certainly meet the threshold (>$10M annual revenue from personal data sale or >50,000 TX consumers).
Key obligation: 30-day notification to the TX AG when 250 or more Texas residents are affected by a breach — separate from and in addition to the federal notification requirement. Civil penalties up to $10,000 per violation, injunctive relief. No federal trigger required — TX AG enforces independently.
The Department's cybersecurity examination team, led by Director Ruth Norris, is specifically reviewing:
- MSP privileged credential management
- End-of-life system compensating controls
- Privileged access management implementation depth
GLBA requires annual pen testing. TDPSA requires 30-day AG breach notification. FFIEC/NIST requires documented risk assessments. The FDIC IT exam reviews privileged access management. No community bank under $2B in assets has a full-time compliance team to manage all of this simultaneously. That's not a deficiency — it's a market signal.
What a Breach Actually Costs — Beyond the Headline Number
The direct costs are only the beginning:
$250,000 to $1,000,000 for a community bank-scale forensic investigation. Before any litigation. The FDIC, OCC, and TX DOB will all be involved. Examination findings become part of the public record.
The Texas Capital Bank class action filed in July 2026 is the playbook. Plaintiffs' attorneys don't need to prove negligence to file — they need to show the breach happened and customer data was exposed. Discovery then demands your internal security documentation, examination findings, vendor contracts, and incident response records. All of it.
When a community bank's fraud rate or breach rate spikes, its correspondent bank faces its own regulatory scrutiny. The rational response: impose additional verification requirements, increase fees, or terminate the relationship. For a community bank relying on a correspondent for ACH processing, wire settlement, and cash management, losing that relationship is operationally existential.
Texas Capital's breach creates enhanced scrutiny across its correspondent network. If you share correspondents with them, expect additional verification requests. CoreRecon's community bank vertical page covers the full correspondent risk picture.
The cyber insurance market has tightened materially. Carriers require evidence of MFA implementation, privileged access management controls, and tested incident response plans before binding coverage. A bank that can't demonstrate documented controls faces either an exclusion of ransomware coverage or 2-3x premium increases at renewal.
Named Incidents That Should Be in Every TX Community Bank CISO's Briefing
A fintech providing mortgage and lending technology to financial institutions disclosed a breach affecting consumer and mortgage applicant data. Multiple originating banks were named in regulatory scrutiny. The OCC/FDIC/Fed joint guidance on fintech due diligence (August 2021) was cited in examination findings. If you use MeridianLink or a similar lending pipeline provider, your regulators consider their security your security.
Disclosed a breach affecting 16.6 to 17 million individuals. Reported cost to LoanDepot: approximately $27 million. This is the reference point for what a mid-size fintech breach costs in investigation, notification, and remediation. The question for community banks is: what's in your API data flow that bypasses your perimeter controls?
A named incident affecting tens of thousands of members. Credit unions operate under NCUA supervision but face the same threat landscape as community banks — and the same correspondent bank scrutiny. The same MSP relationships, the same fintech API exposures, the same examiner questions.
The pattern across all three: third-party fintech relationships create data flows that bypass bank perimeter controls. If the fintech's API is compromised, the core bank's customer data is exposed. The FDIC, OCC, and Fed all issued guidance in August 2021 requiring comprehensive due diligence before fintech relationships and ongoing monitoring. Most community banks don't have the vendor management infrastructure to meet that standard — which is exactly why it's showing up in examination findings.
A Practical Path Forward — Five Things You Can Do This Quarter
The cost of getting ahead of this is not trivial. The cost of falling behind is measured in regulatory actions, litigation, correspondent relationships, and cyber insurance premiums you can't afford.
Texas Capital Was a $35 Billion Institution. They Still Got Breached.
Texas Capital Bank manages significant correspondent relationships. Its breach ripples outward — correspondent banks face enhanced scrutiny, examiners pay more attention to institutions sharing that network, and cyber insurance underwriters sharpen their pencils.
The class action filed in July 2026 isn't just a Texas Capital problem. It's the litigation playbook that every plaintiff's attorney in Texas will reference for the next community bank breach. Discovery demands your internal security documentation, your examination findings, your vendor contracts, your incident response records. All of it produced under penalty of sanction.
Correspondent banks are already responding: additional verification requirements, fee increases, and in some cases, termination notices for institutions that can't demonstrate adequate controls. If you share correspondents with Texas Capital or any institution that's disclosed a breach in the past 24 months, you are already in that scrutiny.
The question for every community bank in Texas isn't whether this will happen to you. It's whether you'll do something about it before the examination findings arrive — or after the class action does.
Free Cybersecurity Posture Assessment
A 15-minute call reviewing your current examination posture, MSP exposure, NIST CSF 2.0 gap status, and cyber insurance readiness. No commitment, no contracts. Start your free assessment — or learn more about CoreRecon's community bank vertical.
Start Free AssessmentCoreRecon is a Texas-based service-disabled veteran-owned small business (SDVOSB). Our Sentinel, Fortress, and Command service tiers all have published pricing available. We offer a free cybersecurity posture assessment at /assessment. We know TDPSA because we're subject to it as a Texas business. We know CJIS because Texas banks handling criminal justice-adjacent data need a vendor who does too.
Our 30-minute response SLA means a human sees your alert within 30 minutes of a detected threat — not a ticket in a queue, not an automated email. For a bank with no in-house SOC, that's the difference between a contained incident and a regulatory event.
A U.S. Marine Corps veteran and founder of CoreRecon, a Texas-based service-disabled veteran-owned cybersecurity firm. We know what operational continuity means. And we know the examination is coming.
Sources: CoreRecon threat intelligence analysis — 42 verified sources including TX DOB IN 2025-01, TX DOB August 2024 Industry Notice, FDIC 2026 IT Exam Framework, FTC Safeguards Rule (16 CFR Part 314, 2023 revision), TDPSA (TX Bus. & Com. Code §541), FBI IC3 2024 Report ($1.35B TX losses), CISA Volt Typhoon advisory, TX DOB Director Phillip Hinkle statements, TX DOB Director of IT Security Examinations Ruth Norris guidance, OCC/FDIC/Fed fintech due diligence guidance (August 2021), Texas Capital Bank breach disclosure (May 2026), LoanDepot SEC 8-K (Jan 2024), MeridianLink breach notification (Nov 2023), Texas Dow Employees Credit Union breach disclosure, CISA NIST CSF 2.0, CIS Controls v8.
Source tag: v41_community_bank_blog