The Heartland Tri-State Bank collapse. Evolve Bank & Trust's $185M LockBit breach. These aren't anomalies — they're the playbook ransomware groups now follow on community banks. CoreRecon delivers 24/7 SOC + 30-minute SLA for Texas community banks — with FFIEC CAT, GLBA Safeguards, and FDIC breach notification built in. Texas has 300+ community banks. Most are not ready.
Community banks run a uniquely concentrated risk environment: core banking systems holding every customer's financial life, wire transfer authority moving millions, ACH batch files, and core-provider integrations with third parties who may not call you for days. Each layer is a separate attack surface with its own adversary profile.
Community banks face a more complex compliance stack than most realize. FFIEC CAT alone requires documented maturity levels across 5 domains and 494 declarative statements. Stack GLBA Safeguards, the FDIC notification rule, and TDPSA on top — and the compliance picture demands a dedicated security program, not a checkbox exercise.
| Framework | Applies To | Enforcement / Deadline | CoreRecon Coverage |
|---|---|---|---|
| FFIEC CAT Cybersecurity Assessment Tool — 5 domains, 494 declarative statements, maturity tiers 1–5 across Cyber Risk Management, Threat Intelligence, Cybersecurity Controls, External Dependencies, and Incident Management |
All FDIC-supervised institutions and state-member banks. FFIEC examiners use CAT as the primary cybersecurity examination framework for community banks. OCC-supervised banks use similar OCC Heightened Standards mapping. | FFIEC CAT is the examination standard — examiners assess whether your maturity level matches your risk profile. Banks with inadequate cybersecurity maturity receive MRAs (Matters Requiring Attention) in examination reports. Repeat MRAs can trigger consent orders. No formal deadline — continuous compliance expectation under safety-and-soundness standards. | Sentinel Threat intelligence feeds, basic incident detection, email security. Fortress Documented FFIEC CAT Tier 3 controls: SIEM, automated detection, vendor oversight program, annual penetration testing, tested IR plan. Command Full CAT maturity documentation package, board-level cybersecurity strategy, examiner-ready artifacts for all 5 domains |
| GLBA Safeguards Rule 16 CFR Part 314 — written ISP, Qualified Individual, annual board report, MFA, encryption, IR plan, vendor oversight, annual penetration testing and vulnerability scanning |
All financial institutions under FTC jurisdiction — which includes most community banks that engage in financial activities. Banks regulated by banking agencies (OCC, FDIC, Federal Reserve) are subject to equivalent requirements under the Interagency Guidelines establishing Information Security Standards, not the FTC rule, but the substance is nearly identical. | Full requirements effective June 2023 under FTC rule; banking agencies have equivalent requirements under GLBA enacted 1999, implemented via the Interagency Guidelines. 30-day breach notification trigger for incidents affecting 500+ customers under FTC version; banking agencies have their own notification timelines. No small-bank exemption. | Sentinel MFA deployment, encryption verification, IR plan template, basic ISP framework. Fortress Vendor oversight program for core providers, annual penetration testing, encrypted backup, vulnerability scanning. Command Qualified Individual vCISO designation, written ISP authorship, annual board report — full Safeguards program ownership |
| FDIC FIL / Computer-Security Incident Notification Rule 12 CFR Part 304 — 36-hour notification to primary federal regulator after determining a "notification incident" (significant attack causing actual harm) |
All FDIC-supervised institutions. OCC-supervised banks have equivalent obligations under 12 CFR Part 30, Appendix B. State-chartered non-member banks supervised by FDIC. Community banks are the primary covered population — most community banks are FDIC-supervised. | Rule effective May 1, 2022. No small-bank exemption. 36-hour clock runs from the moment a bank determines an incident qualifies — not from when the core vendor discloses, not from when IT understands the full scope. Banks must also require their bank service providers to notify them within 36 hours of a servicer incident. Non-compliance is a safety-and-soundness violation. | Sentinel Incident detection, classification support, initial timeline documentation. Fortress 4-hour SLA, forensic investigation support, incident scope determination, notification-ready timeline generation. Command 30-minute SLA, FDIC notification drafting support, legal coordination, full breach management through regulatory close-out |
| TDPSA Texas Data Privacy and Security Act — effective July 1, 2024. $7,500/violation civil penalties, 45-day consumer request response |
Entities doing business in Texas or serving Texas residents that process or sell personal data above threshold. Community banks that process customer personal data (which is all of them) and meet size thresholds are subject to TDPSA consumer rights provisions for any non-banking activity — e.g., marketing activities, website data collection, third-party data sharing outside the Gramm-Leach-Bliley exemption. | TDPSA effective July 1, 2024. TX Attorney General enforcement — $7,500/violation civil penalty. 45-day window to respond to consumer data requests. Financial institutions operating under GLBA have a partial exemption for data processed in a GLBA-regulated capacity, but not for all processing activities. Marketing databases, website analytics, and CRM data outside GLBA scope require TDPSA compliance. | Fortress Data inventory for TDPSA-scoped processing, consumer request response framework, DPA compliance support. Command Full TDPSA gap assessment, privacy notice accuracy review, consumer rights program design |
Most MSSPs treat a community bank like any other SMB. CoreRecon maps the specific attack surfaces of the banking technology stack — core banking platforms, wire transfer systems, ACH batch files, online banking portals, and loan origination platforms — and monitors the integration points that community banks cannot see on their own.
Average Texas community bank runs 50–200 endpoints: teller workstations, loan officer laptops, wire room PCs, ATM management terminals, and branch admin. Month-to-month. No long-term contracts. 10-endpoint minimum.
Endpoint guidance for Texas community banks: Single-branch bank: 30–60 endpoints. 3–5 branch community bank: 80–150 endpoints. 10+ branch regional community bank: 150–300+ endpoints. Multiply by $89 (Sentinel) or $129 (Fortress) for your monthly estimate. Command tier is fixed-fee custom scope — typical community bank starts at $2,500/mo above endpoint tier.
We map your core banking-connected endpoints, identify FFIEC CAT maturity gaps, check BEC vulnerability on your wire room and officer email workflows, and deliver a bank-specific remediation roadmap. No credit card. No commitment. Delivered in 14 days.
Request your free $2,500 assessment →Delivered within 14 days • No credit card • SDVOSB-certified team
Command tier's vCISO service can fulfill the GLBA Safeguards Rule 16 CFR 314.4(a) Qualified Individual requirement. The rule requires a designated Qualified Individual with relevant experience who oversees your information security program, coordinates implementation, and reports to the board annually. FTC guidance and banking agency interpretations explicitly permit an outside party to serve in this role. Command delivers: ISP authorship and maintenance, annual risk assessment, annual written report to board, vendor oversight program coordination, and IR plan maintenance — covering all eight 16 CFR 314.4 operational requirements. For FDIC-supervised banks, our vCISO coordinates directly with your external auditors and can participate in examiner pre-exam prep sessions.
The FDIC Computer-Security Incident Notification Rule (12 CFR Part 304) requires you to notify your primary federal regulator within 36 hours of "determining" that a notification incident has occurred — a significant attack that actually disrupts, degrades, or impairs normal operations or results in unauthorized access to sensitive data. The clock starts at determination, not discovery. CoreRecon's 30-minute SLA means you receive an incident classification within 30 minutes of detection. Command tier includes FDIC-format notification drafting support and coordination with your general counsel — so you're not drafting a regulatory notification from scratch under time pressure. We provide the forensic timeline documentation, the affected-systems inventory, and the impact assessment that FDIC notifications require. The 36 hours is enough time if you're organized. It's not enough if you're still trying to understand what happened.
Yes. CoreRecon monitors the network-layer integrations between your endpoints and core banking platforms — credential anomalies on core accounts, unusual data access patterns, and lateral movement from core-connected endpoints into your internal infrastructure. We instrument the network traffic at the integration layer between your local infrastructure and the hosted core environment. We don't replace your core provider's own security controls; we monitor the attack surface that exists between your network and theirs. This is the exact gap that the 2023 Jack Henry-related community bank incidents exposed — the breach was at the integration layer, not the core's own infrastructure. Our onboarding includes a core-specific threat hunt looking for persistent access through those integration pathways.
Fortress tier gets most community banks to documented FFIEC CAT Maturity Level 3 (Intermediate) baseline across the five domains. Maturity Level 3 requires: documented cybersecurity strategy aligned to business risk (Domain 1), proactive threat intelligence monitoring and sharing (Domain 2), automated detection controls and full-time dedicated cybersecurity staff or equivalent (Domain 3), documented vendor oversight and contract controls for critical third parties (Domain 4), and tested incident response plans with post-incident analysis (Domain 5). Command tier adds the board-level cybersecurity strategy documentation and examiner-ready artifacts for all five domains — the gap between Tier 3 and Tier 4 is mostly documentation and board engagement, which the Command vCISO delivers. Most Texas community banks start at Tier 1–2 and need 6–12 months of documented controls to reach Tier 3 in an examination.
FFIEC CAT Domain 4 (External Dependencies Management) is the most consistently cited gap in community bank examinations. Fortress tier delivers the foundational vendor oversight program: risk-tiering of critical vendors (core, item processing, online banking, ATM management), documented security review schedules, contract language review for cybersecurity obligations, and an annual vendor risk report. Command tier adds the board-level vendor oversight strategy, a formal third-party risk management (TPRM) program aligned to FFIEC guidance, and direct support for examiner-specific questions about your vendor oversight program. The examiner question is usually: "Can you show us your vendor risk tiers, your last security review for your top 5 vendors, and what your contract says about breach notification?" Command tier delivers that package.
At 95 endpoints, Fortress tier runs $12,255/month ($129 × 95). That covers: everything in Sentinel (24/7 SOC, core banking anomaly detection, BEC detection on wire room workflows, MFA deployment, monthly threat intel reports) plus FFIEC CAT Tier 3 controls documentation, vendor oversight program for your core provider, annual penetration testing, encrypted immutable backup with quarterly restore testing, 4-hour SLA with community bank incident response playbooks, quarterly vulnerability scanning, and FDIC notification timeline documentation support. Month-to-month — no contracts. Command tier ($2,500+/month additional) adds the GLBA Qualified Individual vCISO, written ISP authorship, annual board report, 30-minute SLA, and FDIC notification drafting support. For a 95-endpoint bank at Fortress + Command, you're at roughly $14,755/month — and you have a complete GLBA-compliant security program with examiner-ready artifacts.
Texas community banks are the most financially concentrated target in the SMB landscape — customer deposits, wire authority, and core-provider integrations that can take you offline in hours. Our free assessment maps your core attack surface, checks FFIEC CAT maturity gaps, and delivers a bank-specific remediation roadmap. No credit card. No commitment.
Request your free $2,500 assessment →Delivered within 14 days • No credit card • SDVOSB-certified team