Cybersecurity for Texas Community Banks  •  FFIEC CAT • GLBA Safeguards • FDIC 36-Hr Clock • SDVOSB

The FDIC clock starts at 36 hours.
Your core provider won't call you.

The Heartland Tri-State Bank collapse. Evolve Bank & Trust's $185M LockBit breach. These aren't anomalies — they're the playbook ransomware groups now follow on community banks. CoreRecon delivers 24/7 SOC + 30-minute SLA for Texas community banks — with FFIEC CAT, GLBA Safeguards, and FDIC breach notification built in. Texas has 300+ community banks. Most are not ready.

Get your free $2,500 posture assessment → See what's hitting Texas banks right now ↓
🏦
FDIC Computer-Security Incident Notification Rule — 36-Hour Clock Active. Any "notification incident" — a significant cyberattack that causes actual harm to normal operations or customer data — must be reported to your primary federal regulator within 36 hours of determination. GLBA Safeguards Rule requires a designated Qualified Individual, written ISP, MFA, vendor oversight, and annual board report. Neither rule has a small-bank exemption. The clock starts the moment your team determines an incident qualifies — not when your core vendor finally calls you.
300+
Texas community banks — most under $1B in assets, most without a dedicated security team
FDIC Call Report data, IBAT (Independent Bankers Association of Texas)
$185M
Evolve Bank & Trust LockBit breach losses — 7.6M customer records, fintech partners exposed
Evolve Bank SEC 8-K / public disclosures, June 2024
36 hrs
FDIC notification deadline after determining a "notification incident" — no exceptions for community banks
FDIC Computer-Security Incident Notification Rule, 12 CFR Part 304
$6.08M
Average financial sector breach cost — highest of any industry in IBM CODB 2025
IBM Cost of Data Breach Report 2025
Threat Reality — Texas Community Banks

Four incidents.
Every one is transferable.

Community banks run a uniquely concentrated risk environment: core banking systems holding every customer's financial life, wire transfer authority moving millions, ACH batch files, and core-provider integrations with third parties who may not call you for days. Each layer is a separate attack surface with its own adversary profile.

🏚️
Bank Failure via Fraud · Kansas, 2023
Heartland Tri-State Bank
Heartland Tri-State Bank of Elkhart, Kansas failed in July 2023 after its CEO transferred $47.1M in bank funds to crypto accounts controlled by scammers. The fraud was executed through a sophisticated social engineering campaign — the CEO was convinced he was participating in a legitimate crypto investment program. The bank was placed into FDIC receivership in a single weekend. Every dollar of the $47.1M was depositor money. The FDIC loss to the insurance fund: $54.2M. Community bank leadership is the primary BEC target — not the teller line. Source: FDIC press release; DOJ indictment; KS OSBC; Reuters.
💻
Core Banking Breach via Third-Party · 2024
Evolve Bank & Trust
Evolve Bank & Trust (Arkansas; fintech BaaS partner to 70+ startups) was breached by LockBit in June 2024. 7.6M customer records were exfiltrated. Fintech partners including Affirm, Mercury, Wise, Marqeta, and EarnIn notified their own customers. The breach originated through a third-party systems integration — not a direct attack on Evolve's core infrastructure. The LockBit exfiltration included customer SSNs, account numbers, and transaction histories from Evolve's open-banking API stack. Community banks with BaaS or fintech integration partnerships face the exact same third-party attack surface. Source: Evolve Bank statements; LockBit leak site; Reuters; TechCrunch.
🔒
Core Provider Ransomware · 2023
Ongoing Vendor Supply Chain Risk
Jack Henry & Associates (core provider to 1,000+ community banks), Fiserv, and FIS collectively hold the most concentrated banking data in the United States. In 2023, multiple community banks notified customers of data exposure following a breach at their Jack Henry-hosted environment. Core providers are the single-point-of-failure for community banks — a Jack Henry event propagates instantly to every connected bank. The banks themselves had no advance warning and limited forensic access to the affected systems. CoreRecon monitors the network layer around your core integration — the gap your core vendor cannot cover.
💸
BEC Wire Diversion · FBI IC3 2024
Business Email Compromise
FBI IC3 2024: financial sector BEC losses totaled $2.9B+ — the highest of any sector. Community bank wire rooms, CFO email accounts, and loan officer mailboxes are primary BEC targets. Attackers intercept payoff letters, redirect wires on commercial real estate closings, and impersonate senior bank officers to authorize fraudulent transfers. The average community bank wire BEC event results in $500K–$2M in diverted funds. Recovery is nearly impossible once the funds move through crypto intermediaries. FFIEC CAT specifically calls out BEC as a Tier 3 threat scenario requiring documented controls. Source: FBI IC3 2024 Annual Report; FFIEC CAT guidance.
Compliance Landscape — Community Banks

Four frameworks.
All active. All examined.

Community banks face a more complex compliance stack than most realize. FFIEC CAT alone requires documented maturity levels across 5 domains and 494 declarative statements. Stack GLBA Safeguards, the FDIC notification rule, and TDPSA on top — and the compliance picture demands a dedicated security program, not a checkbox exercise.

FFIEC CAT GLBA Safeguards FDIC FIL TDPSA
Framework Applies To Enforcement / Deadline CoreRecon Coverage
FFIEC CAT
Cybersecurity Assessment Tool — 5 domains, 494 declarative statements, maturity tiers 1–5 across Cyber Risk Management, Threat Intelligence, Cybersecurity Controls, External Dependencies, and Incident Management
All FDIC-supervised institutions and state-member banks. FFIEC examiners use CAT as the primary cybersecurity examination framework for community banks. OCC-supervised banks use similar OCC Heightened Standards mapping. FFIEC CAT is the examination standard — examiners assess whether your maturity level matches your risk profile. Banks with inadequate cybersecurity maturity receive MRAs (Matters Requiring Attention) in examination reports. Repeat MRAs can trigger consent orders. No formal deadline — continuous compliance expectation under safety-and-soundness standards. Sentinel Threat intelligence feeds, basic incident detection, email security. Fortress Documented FFIEC CAT Tier 3 controls: SIEM, automated detection, vendor oversight program, annual penetration testing, tested IR plan. Command Full CAT maturity documentation package, board-level cybersecurity strategy, examiner-ready artifacts for all 5 domains
GLBA Safeguards Rule
16 CFR Part 314 — written ISP, Qualified Individual, annual board report, MFA, encryption, IR plan, vendor oversight, annual penetration testing and vulnerability scanning
All financial institutions under FTC jurisdiction — which includes most community banks that engage in financial activities. Banks regulated by banking agencies (OCC, FDIC, Federal Reserve) are subject to equivalent requirements under the Interagency Guidelines establishing Information Security Standards, not the FTC rule, but the substance is nearly identical. Full requirements effective June 2023 under FTC rule; banking agencies have equivalent requirements under GLBA enacted 1999, implemented via the Interagency Guidelines. 30-day breach notification trigger for incidents affecting 500+ customers under FTC version; banking agencies have their own notification timelines. No small-bank exemption. Sentinel MFA deployment, encryption verification, IR plan template, basic ISP framework. Fortress Vendor oversight program for core providers, annual penetration testing, encrypted backup, vulnerability scanning. Command Qualified Individual vCISO designation, written ISP authorship, annual board report — full Safeguards program ownership
FDIC FIL / Computer-Security Incident Notification Rule
12 CFR Part 304 — 36-hour notification to primary federal regulator after determining a "notification incident" (significant attack causing actual harm)
All FDIC-supervised institutions. OCC-supervised banks have equivalent obligations under 12 CFR Part 30, Appendix B. State-chartered non-member banks supervised by FDIC. Community banks are the primary covered population — most community banks are FDIC-supervised. Rule effective May 1, 2022. No small-bank exemption. 36-hour clock runs from the moment a bank determines an incident qualifies — not from when the core vendor discloses, not from when IT understands the full scope. Banks must also require their bank service providers to notify them within 36 hours of a servicer incident. Non-compliance is a safety-and-soundness violation. Sentinel Incident detection, classification support, initial timeline documentation. Fortress 4-hour SLA, forensic investigation support, incident scope determination, notification-ready timeline generation. Command 30-minute SLA, FDIC notification drafting support, legal coordination, full breach management through regulatory close-out
TDPSA
Texas Data Privacy and Security Act — effective July 1, 2024. $7,500/violation civil penalties, 45-day consumer request response
Entities doing business in Texas or serving Texas residents that process or sell personal data above threshold. Community banks that process customer personal data (which is all of them) and meet size thresholds are subject to TDPSA consumer rights provisions for any non-banking activity — e.g., marketing activities, website data collection, third-party data sharing outside the Gramm-Leach-Bliley exemption. TDPSA effective July 1, 2024. TX Attorney General enforcement — $7,500/violation civil penalty. 45-day window to respond to consumer data requests. Financial institutions operating under GLBA have a partial exemption for data processed in a GLBA-regulated capacity, but not for all processing activities. Marketing databases, website analytics, and CRM data outside GLBA scope require TDPSA compliance. Fortress Data inventory for TDPSA-scoped processing, consumer request response framework, DPA compliance support. Command Full TDPSA gap assessment, privacy notice accuracy review, consumer rights program design
CoreRecon Coverage — Purpose-Built for the Core Banking Stack

Built for Jack Henry, Fiserv,
FIS, and your wire room.

Most MSSPs treat a community bank like any other SMB. CoreRecon maps the specific attack surfaces of the banking technology stack — core banking platforms, wire transfer systems, ACH batch files, online banking portals, and loan origination platforms — and monitors the integration points that community banks cannot see on their own.

Core Banking Monitoring
Jack Henry · Fiserv · FIS · Temenos
We monitor the network layer around your core banking integration — credential anomalies on core accounts, unusual data access patterns, and lateral movement from core-connected endpoints. When your core provider has an incident (they don't always call you first), we have visibility into what was happening on your network in the hours before and after. Our onboarding includes a core-specific threat hunt to identify any persistent access established through third-party integration pathways.
Wire Transfer & ACH Protection
BEC Detection on Wire Room Workflows
Wire room email accounts and dual-control workflows are the highest-value attack target in any community bank. We monitor authentication anomalies, email access patterns, and wire approval workflows for BEC indicators — attackers impersonating customers, officers, or correspondent banks to redirect wires. Anomalous wire authorization patterns trigger immediate SOC alert. FBI IC3 2024: financial sector BEC losses = $2.9B+. Your wire room is the most targeted workflow in your bank.
Online Banking & ATM Network
Customer-Facing Attack Surface
Online banking portals and ATM management systems create customer-facing attack surfaces that core providers do not fully monitor. Account takeover via credential stuffing, ATM logical attacks (Jackpotting, Black Box), and malicious code injection on online banking platforms are active community bank threat vectors. We monitor authentication anomalies, unusual transaction patterns on online banking, and ATM management system access for indicators of logical attack activity.
Vendor Risk — Core Providers
Jack Henry · FIS · Fiserv · Symitar
Core providers hold more community bank data than the banks themselves. FFIEC CAT Domain 4 (External Dependencies Management) requires a documented vendor oversight program with risk tiering, security review schedules, and contract oversight. Command tier delivers: vendor cybersecurity due diligence framework, security review schedule for core and critical vendors, contract language review for cybersecurity obligations, and annual vendor risk reporting for your board.
FDIC 36-Hr Incident Management
Pre-Built Notification Playbooks
The FDIC's 36-hour notification clock starts at "determination" — not discovery. CoreRecon's pre-built community bank incident response playbooks are structured around this timeline: immediate classification, 2-hour preliminary assessment, 4-hour formal determination, 36-hour regulatory notification package. Command tier includes FDIC-format notification drafting support and coordination with your general counsel on regulatory reporting. The clock doesn't stop because it's the weekend.
GLBA Qualified Individual — vCISO
Your 16 CFR 314.4(a) Designee
GLBA Safeguards Rule requires a designated Qualified Individual responsible for your information security program — someone with relevant experience who oversees implementation and reports to the board annually. Most community banks cannot justify a $200K–$350K full-time CISO. Command tier's vCISO fulfills this role: ISP authorship, annual risk assessment, annual board report, vendor oversight, and IR plan maintenance. FTC and banking agency guidance explicitly permits an outside party to serve as Qualified Individual.
Transparent Pricing — Community Bank Edition

Three tiers. Published pricing.
Built for 50–200 endpoint banks.

Average Texas community bank runs 50–200 endpoints: teller workstations, loan officer laptops, wire room PCs, ATM management terminals, and branch admin. Month-to-month. No long-term contracts. 10-endpoint minimum.

Sentinel
$89 / endpoint / month
10-endpoint minimum • ~$4,450–$17,800/mo for typical bank • Month-to-month
  • 24/7 SOC monitoring across all bank endpoints
  • Core banking integration anomaly detection
  • Email security with BEC pattern detection for wire and officer accounts
  • MFA deployment on core banking, email, online banking admin
  • GLBA Safeguards ISP framework and basic documentation package
  • Monthly threat report with financial sector intel
  • FDIC incident classification support
Command
$2,500+ / month
Custom scope • Dedicated vCISO • GLBA Qualified Individual available
  • Everything in Fortress
  • 30-minute SLA — analyst on call within 30 minutes of major alert
  • GLBA Qualified Individual vCISO — your 16 CFR 314.4(a) designee
  • Written ISP authorship, maintenance, and annual board report
  • FDIC notification drafting support and legal coordination
  • FFIEC CAT full maturity documentation across all 5 domains
  • Board-level cybersecurity strategy with examiner-ready artifacts
  • Multi-branch group coverage with consolidated ISP and per-branch SIEM views

Endpoint guidance for Texas community banks: Single-branch bank: 30–60 endpoints. 3–5 branch community bank: 80–150 endpoints. 10+ branch regional community bank: 150–300+ endpoints. Multiply by $89 (Sentinel) or $129 (Fortress) for your monthly estimate. Command tier is fixed-fee custom scope — typical community bank starts at $2,500/mo above endpoint tier.

Free Security Assessment — $2,500 Value

Find out where your core provider integration is exposing your bank right now.

We map your core banking-connected endpoints, identify FFIEC CAT maturity gaps, check BEC vulnerability on your wire room and officer email workflows, and deliver a bank-specific remediation roadmap. No credit card. No commitment. Delivered in 14 days.

Request your free $2,500 assessment →

Delivered within 14 days  •  No credit card  •  SDVOSB-certified team

Free Interactive Tool
What Does a Wire Diversion BEC Event Cost Your Bank?
Model your BEC loss exposure on wire transfers, ACH batches, and commercial loan closing wires. FBI IC3 2024 benchmarks. Get your unrecoverable loss estimate in 60 seconds.
Calculate BEC Exposure →
Free Tool — Breach Cost Calculator
What Would the Evolve Bank Scenario Cost Your Institution?
IBM CODB 2025 breach cost model. Financial sector average: $6.08M. Plug in your endpoint count and customer record count — get your breach cost estimate with regulatory penalty exposure. Know your number before the board asks.
Calculate Breach Cost →
Free Download — 2026 Intelligence Report
Texas Community Banks Cyber Threat Brief 2026
4 named incidents. FFIEC CAT maturity walk-through. 16 CFR 314 checklist. BEC wire-fraud benchmarks from FBI IC3 2024. 35+ verified sources. Designed for community bank boards and GLBA Qualified Individuals.
Download PDF Brief →
Frequently Asked Questions

What Texas bank executives actually ask.

Command tier's vCISO service can fulfill the GLBA Safeguards Rule 16 CFR 314.4(a) Qualified Individual requirement. The rule requires a designated Qualified Individual with relevant experience who oversees your information security program, coordinates implementation, and reports to the board annually. FTC guidance and banking agency interpretations explicitly permit an outside party to serve in this role. Command delivers: ISP authorship and maintenance, annual risk assessment, annual written report to board, vendor oversight program coordination, and IR plan maintenance — covering all eight 16 CFR 314.4 operational requirements. For FDIC-supervised banks, our vCISO coordinates directly with your external auditors and can participate in examiner pre-exam prep sessions.

The FDIC Computer-Security Incident Notification Rule (12 CFR Part 304) requires you to notify your primary federal regulator within 36 hours of "determining" that a notification incident has occurred — a significant attack that actually disrupts, degrades, or impairs normal operations or results in unauthorized access to sensitive data. The clock starts at determination, not discovery. CoreRecon's 30-minute SLA means you receive an incident classification within 30 minutes of detection. Command tier includes FDIC-format notification drafting support and coordination with your general counsel — so you're not drafting a regulatory notification from scratch under time pressure. We provide the forensic timeline documentation, the affected-systems inventory, and the impact assessment that FDIC notifications require. The 36 hours is enough time if you're organized. It's not enough if you're still trying to understand what happened.

Yes. CoreRecon monitors the network-layer integrations between your endpoints and core banking platforms — credential anomalies on core accounts, unusual data access patterns, and lateral movement from core-connected endpoints into your internal infrastructure. We instrument the network traffic at the integration layer between your local infrastructure and the hosted core environment. We don't replace your core provider's own security controls; we monitor the attack surface that exists between your network and theirs. This is the exact gap that the 2023 Jack Henry-related community bank incidents exposed — the breach was at the integration layer, not the core's own infrastructure. Our onboarding includes a core-specific threat hunt looking for persistent access through those integration pathways.

Fortress tier gets most community banks to documented FFIEC CAT Maturity Level 3 (Intermediate) baseline across the five domains. Maturity Level 3 requires: documented cybersecurity strategy aligned to business risk (Domain 1), proactive threat intelligence monitoring and sharing (Domain 2), automated detection controls and full-time dedicated cybersecurity staff or equivalent (Domain 3), documented vendor oversight and contract controls for critical third parties (Domain 4), and tested incident response plans with post-incident analysis (Domain 5). Command tier adds the board-level cybersecurity strategy documentation and examiner-ready artifacts for all five domains — the gap between Tier 3 and Tier 4 is mostly documentation and board engagement, which the Command vCISO delivers. Most Texas community banks start at Tier 1–2 and need 6–12 months of documented controls to reach Tier 3 in an examination.

FFIEC CAT Domain 4 (External Dependencies Management) is the most consistently cited gap in community bank examinations. Fortress tier delivers the foundational vendor oversight program: risk-tiering of critical vendors (core, item processing, online banking, ATM management), documented security review schedules, contract language review for cybersecurity obligations, and an annual vendor risk report. Command tier adds the board-level vendor oversight strategy, a formal third-party risk management (TPRM) program aligned to FFIEC guidance, and direct support for examiner-specific questions about your vendor oversight program. The examiner question is usually: "Can you show us your vendor risk tiers, your last security review for your top 5 vendors, and what your contract says about breach notification?" Command tier delivers that package.

At 95 endpoints, Fortress tier runs $12,255/month ($129 × 95). That covers: everything in Sentinel (24/7 SOC, core banking anomaly detection, BEC detection on wire room workflows, MFA deployment, monthly threat intel reports) plus FFIEC CAT Tier 3 controls documentation, vendor oversight program for your core provider, annual penetration testing, encrypted immutable backup with quarterly restore testing, 4-hour SLA with community bank incident response playbooks, quarterly vulnerability scanning, and FDIC notification timeline documentation support. Month-to-month — no contracts. Command tier ($2,500+/month additional) adds the GLBA Qualified Individual vCISO, written ISP authorship, annual board report, 30-minute SLA, and FDIC notification drafting support. For a 95-endpoint bank at Fortress + Command, you're at roughly $14,755/month — and you have a complete GLBA-compliant security program with examiner-ready artifacts.

Core Down? Active Breach? 24/7 Emergency Response
FDIC clock ticking? Ransomware on the core? We respond in 30 minutes.
No retainer required for emergency response. SDVOSB-certified. No voicemail.
📞 (800) 955-2596 Or submit emergency intake form →
Free Security Assessment — $2,500 Value

Find out what your core banking network looks like to an attacker.

Texas community banks are the most financially concentrated target in the SMB landscape — customer deposits, wire authority, and core-provider integrations that can take you offline in hours. Our free assessment maps your core attack surface, checks FFIEC CAT maturity gaps, and delivers a bank-specific remediation roadmap. No credit card. No commitment.

Request your free $2,500 assessment →

Delivered within 14 days  •  No credit card  •  SDVOSB-certified team