Texas Mortgage Cybersecurity — GLBA Safeguards & Wire Fraud Defense

The Wire Fraud Clock Starts Before the Closing Table

31.6 million mortgage records exposed in 2023–2024. loanDepot, Mr. Cooper, First American, LoanCare — every name your borrowers trust has been on a breach notification letter. Texas's 27,000+ licensed MLOs process escrow instructions, SSNs, W-2s, and wire routing numbers in the same inbox as phishing attempts. GLBA Safeguards Rule §314.4 is enforced now. TDPSA private-right-of-action launched July 2024. Your next breach is a public filing.

⚠️
Active Threat: BEC actors are spoofing Texas mortgage broker domains using lookalike homograph attacks (cornerstоnemortgage.com vs. cornerstonemortgage.com). FBI Houston field office issued a private-sector alert in Q1 2026. Average wire diversion loss: $312,000 per incident in Texas residential closings. Funds recovery rate after 24 hours: under 12%.
🎖️
SDVOSB Certified Service-Disabled Veteran-Owned
🏠
San Antonio HQ TX-resident analysts only
30-Minute IR SLA Wire fraud containment before funds clear
📋
GLBA §314.4 Mapped All 9 Safeguards elements covered
💰
$89–$129/Endpoint Month-to-month, no contracts
2023–2025 Mortgage Breach Wave

Every Name Your Borrowers Trust Has Been Breached

The mortgage industry produced six of the top fifteen financial-services data breaches from 2023 to 2025. These aren't abstract statistics — they are NMLS-licensed entities, title underwriters, and servicers your borrowers compare you against. Their breach notifications land in your clients' inboxes weeks after yours would.

loanDepot
Jan 2024 — 16.9M Records
ALPHV/BlackCat ransomware encrypted loan origination systems and exfiltrated 16.9 million customer records including SSNs, DOBs, financial account data, and property information. Systems were offline for 17 days during peak origination. Class action filed in the Central District of California within 72 hours of disclosure. Estimated remediation cost: $26M+. Source: SEC 8-K, Jan 22, 2024.
Mr. Cooper
Oct 2023 — 14.7M Records
Nation-state affiliated threat actor exfiltrated 14.7 million borrower records including names, addresses, SSNs, dates of birth, phone numbers, and bank account numbers from the Nationstar/Mr. Cooper servicing platform. Texas borrowers — Mr. Cooper's Coppell TX headquarters services loans nationwide — represented a material share of affected records. AG investigation opened. Source: Mr. Cooper SEC filing, Dec 2023.
First American / FNF
Nov 2023 — 1.3M+ Records
Fidelity National Financial (FNF) and First American suffered separate ransomware events within 30 days. FNF's ALPHV attack forced a complete shutdown of all IT systems, halting closings across all 50 states for six days. First American independently disclosed a vulnerability exposing 885 million mortgage document images. Combined, these events exposed the title-mortgage data chain's single-point-of-failure architecture. Source: FNF SEC 8-K; First American CA AG filing.
LoanCare (Fidelity)
Nov 2023 — 1.3M Records
LoanCare, an FNF subsidiary and top-10 US mortgage servicer, exposed 1.3 million borrower records through the same ALPHV intrusion that hit the FNF parent. SSNs, loan numbers, and property addresses were included. Texas borrowers filed a class action in the Southern District of Texas (Houston) within 60 days, citing inadequate vendor oversight. Source: TX class action docket 4:24-cv-00031.
Fairway Independent
Feb 2024 — 800K+ Records
Fairway Independent Mortgage, one of the top-5 US retail originators and a significant Texas market player, disclosed a breach affecting 800,000+ borrowers. SSNs, income data, W-2 documents, and bank statements were compromised. The attacker used credential stuffing against Fairway's loan officer portal — the same attack surface used by ~25,000 Texas MLOs at dozens of IMBs. Source: Fairway notification letter, Mar 2024.
Academy Mortgage
Apr 2024 — 270K Records
Academy Mortgage disclosed unauthorized access affecting 270,000+ borrowers. The incident involved the exfiltration of full mortgage application packages: SSNs, employment history, bank statements, asset documentation, and property appraisals. Texas branches in Austin, Dallas, Houston, and San Antonio were included in the affected population. Source: Academy Mortgage CA AG notice, Apr 2024.
📊
The pattern: In every incident above, the initial access vector was either credential stuffing against a loan officer portal, phishing targeting an MLO's email account, or a third-party vendor (LOS, title underwriter, servicer) with excessive network access. All three vectors are addressable with a managed SOC. None require a Fortune 500 security budget.
Threat Intelligence

Why Mortgage Is the New Ransomware Target

Healthcare gets the headlines, but mortgage brokers and IMBs are statistically more attractive to ransomware operators in 2024–2026 on three dimensions: data concentration, operational urgency, and payment capability.

Wire Fraud Vector
A single residential mortgage closing requires 6–12 wire transfer instructions exchanged between buyer, seller, realtor, title company, and lender. Each instruction is sent via email. BEC actors intercept one email thread, substitute their routing and account numbers, and receive the entire proceeds wire. Average Texas residential sale: $387,000 (Q4 2025). The attacker needs one successful email interception to gross a year's salary. The 30-minute window between when wires are initiated and when they "clear" is the containment window CoreRecon is built to exploit.
Escrow Data Concentration
A mortgage application package is the densest PII package in financial services: SSN, DOB, income (W-2 + 1099 + tax returns), employment history, bank statements, 12 months of account activity, credit report, and property valuation data — all in one file. A 25-MLO shop with 200 annual closings holds 200 complete identity theft kits. Dark web sale price: $180–$450 per complete loan file. A mid-size broker's entire pipeline sells for $50,000–$90,000 on RaidForums/BreachForums successor markets.
SSN + Income + Property Concentration
Mortgage data combines three datasets that are normally separated: credit bureau data (SSN + tradelines), IRS data (income + tax returns via 4506-C), and real property data (address + equity + lien position). This combination enables synthetic identity fraud, HELOC fraud, and account takeover that attackers cannot accomplish with any single data source. FBI IC3 2024 report: mortgage/real estate fraud losses exceeded $2.7B — second only to investment fraud.
Operational Urgency = Ransom Payment
A rate lock expires in 30–45 days. A TRID closing disclosure has a 3-business-day waiting period that restarts on any change. A purchase contract closing date cannot slip without amendment. When a mortgage broker's LOS goes down on day 28 of a 30-day rate lock, paying a $75,000 ransom is cheaper than a $400,000 lawsuit from a homebuyer who lost their earnest money. Ransomware operators know this math. CoreRecon's 30-minute SLA is designed to contain and recover before any operational decision is forced.
Texas Regulatory Stack

Five Regulators. One Breach Event. Overlapping Penalties.

Texas mortgage brokers and lenders are supervised simultaneously by the FTC (Safeguards Rule), CFPB (Reg P), NMLS/TDSML, the Texas AG (TDPSA), and — if you service federally-related loans — HUD/FHFA. A single breach event triggers concurrent reporting obligations, independent penalty calculations, and the possibility of simultaneous AG and class-action proceedings.

Regulation What It Requires Effective / Enforced Failure Consequence
GLBA Safeguards Rule §314.4
FTC
9 documented program elements: qualified individual, risk assessment, safeguards implementation, service provider oversight, data disposal, encryption, MFA, access controls, incident response plan. Annual written report to board/leadership. Effective June 9, 2023. Full enforcement live. FTC has pursued 3 civil actions against mortgage entities in 2024. Civil penalties up to $51,744/violation/day. Personal liability for the designated "Qualified Individual." Exam finding triggers NMLS report. Class action standing for affected borrowers.
TDPSA — Texas Data Privacy & Security Act
TX AG
Consumer data rights (access, deletion, correction, portability). Data protection assessments for high-risk processing. Opt-out for sale/sharing of personal data. Privacy notice accuracy requirement. Effective July 1, 2024. Attorney General has enforcement authority. 30-day cure period for first violations (expires Jan 1, 2025 for new violations). Civil penalty up to $7,500/intentional violation. Private right of action for data breach victims under TDPSA + Texas Bus. & Com. Code §521. Class action exposure.
CFPB Regulation P
CFPB
Annual privacy notice to all active borrower relationships. Clear disclosure of data-sharing practices with nonaffiliated third parties. Right to opt out of certain sharing. Ongoing. CFPB supervisory authority over IMBs with >$10B in originations; state-chartered entities supervised by TDSML. CFPB supervisory action, public enforcement order, restitution to borrowers. TDSML license suspension or revocation for state-licensed entities.
SAFE Act / NMLS Recordkeeping
TDSML / NMLS
3-year retention of all loan origination records including electronic communications. Written cybersecurity incident disclosure to TDSML within 72 hours of material breach. MLO license renewal contingent on no open regulatory matters. Texas Finance Code Chapter 156. TDSML exam cycle: 18–24 months. Post-2024: cyber incident questionnaire added to examination scope. License suspension, civil money penalty, forced corrective action plan. NMLS record reflects regulatory actions — visible to all state regulators and to CFPB.
SAFE Act Surety Bond Exposure
TDSML
Texas mortgage brokers maintain surety bonds of $50,000–$100,000 depending on loan volume. A cybersecurity-facilitated fraud event that causes borrower loss can trigger a bond claim. Texas Finance Code §156.205. Bond carrier may pursue subrogation against the broker entity if the loss was caused by security negligence. Bond claim + subrogation action. Bond premium increase at renewal. Bond cancellation if carrier drops. License non-renewable without bond. Personal guaranty exposure for small entities.
Financial Modeling

What a $5M Breach Actually Costs a 25-MLO Shop

The IBM/Ponemon "average breach cost" figure ($4.88M in 2024) is a large-enterprise number. For a 25-MLO independent mortgage broker or small IMB with 1,200 annual borrowers, the cost model is different — and in several dimensions, more severe as a percentage of revenue.

Incident Response Retainer
$85K
Forensic IR firm engagement, 72-hr scope, imaging + evidence preservation
Breach Notification
$62K
1,200 borrowers × $52/borrower — notification letters, credit monitoring, call center (12 months)
TX AG Investigation Response
$120K
Outside counsel, document production, settlement negotiation — TDPSA investigation minimum cost floor
Class Action Defense
$380K
Attorney fees through dismissal motion stage. If case proceeds to discovery: $600K–$1.2M before settlement
GLBA FTC Civil Penalty
$155K
3 documented §314.4 element failures × 10-day duration × $5,174/violation — minimum exposure
Bond Claim + Subrogation
$100K
BEC wire fraud event claiming 1–2 borrower wires diverted; carrier exercises subrogation
TDSML License Defense
$45K
Corrective action plan, compliance consultant, exam prep, NMLS disclosure filing
Revenue Loss (Pipeline)
$240K
14-day LOS downtime × average 3 closings/MLO/month × 25 MLOs × $3,800 avg. net revenue/closing
Total Scenario Cost — 25-MLO Shop, 14-Day Outage, 1,200 Borrowers
$1.19M+
💡
The CoreRecon math: Sentinel tier for 75 endpoints (MLO workstations + servers) = $6,675/month. Full-year cost: $80,100. That is 6.7¢ on the dollar compared to the scenario above — before factoring in that CoreRecon's 30-min SLA would have contained the wire fraud event before funds cleared, potentially eliminating the bond claim and class action entirely.
CoreRecon Response Model

The 30-Minute Window That Determines Whether You Recover the Wire

FBI's Financial Crimes Unit operates a SWIFT-aligned Financial Fraud Kill Chain (FFKC) that can freeze and reverse wire transfers — but only if a Financial Institution (FI) submits a Priority Funds Return Request within approximately 72 hours of wire initiation. In practice, the window to stop a wire before it reaches a foreign correspondent bank or is converted to cryptocurrency is under 4 hours. CoreRecon's 30-minute SLA is designed to trigger that chain.

T+0 Minutes
Anomaly Detected
CoreRecon EDR flags an unusual email rule creation or forwarding rule added to an MLO's Outlook account. SIEM correlates with a login from an IP not in the MLO's normal geolocation. Alert escalated immediately — no tier-1 ticket queue, no first-response SLA delay.
T+8 Minutes
Account Isolated
CoreRecon analyst confirms credential compromise. Account suspended via Microsoft Entra ID integration. Active sessions revoked. Mailbox access frozen. The attacker loses the ability to intercept further closing instructions or send fraudulent wire modification emails.
T+18 Minutes
Closing Coordinator Alerted
CoreRecon contacts the broker's closing coordinator directly (not via the compromised email). They are informed that any wire instructions sent in the last 2–4 hours from the affected MLO account should be treated as potentially fraudulent. Title company is notified to hold any pending wires pending verbal confirmation.
T+30 Minutes
IR SLA Met — FBI FFKC Trigger Point
If a wire was already sent, your bank's fraud team is now engaged with a documented incident record from CoreRecon. The FFKC Priority Funds Return Request clock starts with law enforcement referral. Funds still in the originating domestic bank have a recovery rate above 80% at this stage.
T+4 Hours
Without CoreRecon — Discovery Point
In a typical unmonitored mortgage shop, the first indication of compromise is a borrower calling to confirm wire instructions — which differ from the original closing disclosure. By this point, the wire has cleared to a money mule account. FBI FFKC recovery at this stage drops below 30%. TDPSA breach notification clock has already started.
CoreRecon SOC

Texas-Resident. Veteran-Owned. 24/7 Staffed. No Offshore.

The mortgage industry's data residency and regulatory requirements create a real problem with offshore SOC providers: GLBA Safeguards Rule §314.4(f) requires documented vendor oversight, and sending borrower PII to offshore analysts triggers additional cross-border transfer considerations under CFPB guidance. CoreRecon resolves this categorically.

🏠
Texas Residency
Every CoreRecon analyst is physically located in Texas. San Antonio headquarters. No routing of Texas borrower data through offshore processing centers. Data stays in-state, consistent with GLBA Safeguards vendor management documentation requirements. Your TDSML examiner will not find a third-country transfer in your vendor risk documentation.
🎖️
SDVOSB Certified
Service-Disabled Veteran-Owned Small Business certification through the SBA. This matters for mortgage companies doing VA loan origination or serving veteran borrowers — your cybersecurity vendor alignment reflects your market values. It also unlocks federal set-aside procurement vehicles if you service government-related mortgages (FHA, VA, USDA, Ginnie Mae pools).
🕐
24/7/365 Staffed
Mortgage fraud doesn't observe business hours. BEC attacks are deliberately timed to late afternoon (post-4pm) when closing coordinators are rushing to meet same-day funding deadlines and wire verification calls are harder. CoreRecon maintains analyst coverage across all shifts including Friday afternoon closing rushes, end-of-month volume spikes, and holiday periods.
🇺🇸
No Offshore Processing
Tier-1 alert triage, incident response, and borrower data handling are performed exclusively by US-based personnel. This is documented in CoreRecon's GLBA Safeguards vendor management disclosures, which are available for your TDSML examination file. No "follow-the-sun" model that routes sensitive mortgage data through India or Eastern European SOC facilities during overnight hours.
CoreReconOS for Mortgage

Transparent Pricing. No Enterprise Contracts. Month-to-Month.

Mortgage is a volume-sensitive, rate-cycle business. Your overhead must flex with origination volume. CoreRecon pricing is per-endpoint, month-to-month, with no long-term contract required. Scale up during refi booms, right-size during rate contractions.

Tier 1
Sentinel
$89/endpoint/month
Ideal for brokers with 5–25 MLOs
  • 24/7 TX-resident SOC monitoring
  • Managed EDR (endpoint detection & response)
  • Email threat protection (BEC/phishing intercept)
  • 30-minute IR SLA for critical incidents
  • GLBA §314.4 element documentation support
  • Monthly security posture report
  • Wire transfer anomaly alerting
  • Covers: MLO workstations, LOS servers, shared drives
Start Assessment
Tier 3
Command
$2,500+/month
IMBs 100+ MLOs, warehouse lenders, servicers
  • Everything in Fortress
  • Dedicated vCISO (GLBA Qualified Individual designation)
  • Board/executive security briefings
  • Incident response retainer (on-call IR team)
  • Warehouse line lender cyber risk questionnaire support
  • Secondary market (Fannie/Freddie/Ginnie) audit prep
  • CFPB exam cybersecurity workpaper preparation
  • Third-party LOS/POS vendor security assessments
  • Custom SLA terms available
Contact Sales

All tiers: month-to-month, no long-term contract, no setup fee. Minimum: 10 endpoints. Typical 25-MLO shop deployment: 75–90 endpoints.

Compliance Crosswalk

GLBA Safeguards §314.4: All 9 Elements, Mapped to CoreRecon Controls

The FTC Safeguards Rule §314.4 requires nine specific documented program elements. Your TDSML examiner and your warehouse lender cyber questionnaire both reference these. Here is how CoreRecon maps to each element, with the specific deliverable your compliance file receives.

§314.4 Element What the Rule Requires CoreRecon Control / Deliverable Tier
§314.4(a) — Qualified Individual Designate a qualified individual responsible for overseeing and implementing the information security program. Report to board/senior management annually. Command: CoreRecon vCISO serves as your documented Qualified Individual. Sentinel/Fortress: CoreRecon provides written program support; you designate an internal QI. Mapped
§314.4(b) — Risk Assessment Periodic risk assessment identifying internal and external threats to customer information, assessing adequacy of controls, and evaluating likelihood and potential damage of threats. CoreRecon delivers an annual written risk assessment covering LOS, POS, email, borrower portal, and third-party integrations. Updated quarterly for material changes. Mapped
§314.4(c) — Safeguards Design Design and implement safeguards to control risks identified in the risk assessment, including access controls, encryption, and data management practices. CoreRecon manages EDR, email security, MFA enforcement, access review, and encryption-at-rest monitoring. Written safeguards design document provided annually. Mapped
§314.4(d) — Service Providers Oversee service providers by selecting and retaining only those with appropriate safeguards and requiring them by contract to implement and maintain appropriate safeguards. CoreRecon provides a vendor risk assessment template and conducts annual security reviews of your LOS (Encompass, BytePro, Calyx), POS (Floify, SimpleNexus), and title software vendors. Mapped
§314.4(e) — Program Evaluation Evaluate and adjust the information security program in light of results of testing and monitoring, changes in operations, or material changes in business arrangements. CoreRecon delivers quarterly written posture evaluations and notifies you within 48 hours of any material change in your risk posture requiring program adjustment. Mapped
§314.4(f)(1) — Encryption Encrypt customer information in transit and at rest, unless the Qualified Individual approves alternative compensating controls in writing. CoreRecon enforces TLS 1.2+ for all in-transit communications and monitors for unencrypted customer data stores. Exceptions documented and approved by QI in writing. Mapped
§314.4(f)(2) — MFA Implement multi-factor authentication for any individual accessing information systems containing customer information, unless approved alternative controls are documented. CoreRecon enforces MFA across all MLO workstations, LOS access, email, and remote access VPN. MFA coverage report delivered monthly. Mapped
§314.4(h)(2) — Incident Response Establish a written incident response plan to respond to a security event affecting the confidentiality, integrity, or availability of customer information. CoreRecon provides a written IRP tailored to mortgage operations including wire fraud scenarios, LOS ransomware, and email compromise — with CoreRecon's direct-contact escalation path and the FFKC activation procedure. Mapped
§314.4(i) — Annual Reporting Qualified Individual must report to board or senior management, in writing, on the overall status of the information security program and the company's compliance with the Safeguards Rule. CoreRecon drafts the annual §314.4(i) written report for your QI/leadership review and signature. Delivered 60 days before your fiscal year-end to allow review. Mapped
$2,500 Value — Complimentary

Free Security Posture Assessment for Texas Mortgage Brokers

In 90 minutes, CoreRecon delivers a written GLBA §314.4 gap analysis, an email security review covering BEC exposure, an endpoint inventory check, and a prioritized remediation roadmap — at no cost, no obligation. You get the same output a Big 4 firm charges $2,500 for, because we want your business, not your consulting budget.

GLBA §314.4 Gap Analysis BEC Email Exposure Review Endpoint Inventory Audit MFA Coverage Check Dark Web Scan (MLO Emails) Written Remediation Roadmap
$2,500
FREE
No Obligation
Book Assessment →
Competitive Positioning

CoreRecon vs. Arctic Wolf, Huntress, Critical Start

Arctic Wolf, Huntress, and Critical Start are credible MDR providers. They have real technology, real customers, and real capabilities. Here is where CoreRecon wins on the dimensions that matter most to a Texas mortgage broker.

Capability / Wedge CoreRecon Arctic Wolf Huntress Critical Start
TX-Resident Analysts (No Offshore)
SDVOSB Certification
Published Pricing (No Sales Call Required)
30-Minute IR SLA (Wire Fraud Specific)
GLBA §314.4 Written Program Included
NMLS Exam Prep Documentation
Mortgage-Specific BEC Detection Rules
Month-to-Month (No Annual Contract)
Minimum Endpoint Count ≤ 25 (10 min) (50+) (100+)
Technology Depth (EDR + SIEM + Network)
Brand Recognition / Enterprise References

✓ = full capability / clearly available. ≈ = partial or requires add-on. ✗ = not available or not documented. Arctic Wolf and Critical Start are enterprise-focused and typically require 100+ endpoint minimums and 12-month contracts. Huntress is strong on SMB/MSP channel but lacks mortgage-specific compliance deliverables and TX SOC residency.

Texas-Specific Exposure

TDPSA Private-Right-of-Action: Texas Borrowers Can Sue You Directly

Texas Data Privacy & Security Act — Effective July 1, 2024

TDPSA (Texas Business & Commerce Code Chapter 541) creates an individual private right of action for Texas residents whose sensitive personal data is exposed due to a controller's failure to implement reasonable security measures. Mortgage borrower data — SSNs, financial account numbers, income data, credit information — qualifies as sensitive personal data under TDPSA §541.001(23).

Unlike CCPA (California) or CPA (Colorado), TDPSA does not limit the AG's right to pursue cases where the controller had a cure period but failed to remediate. And unlike most state privacy laws, TDPSA private plaintiffs can file directly in Texas district court without a class certification requirement for individual claims. For a 25-MLO broker with 1,200 borrowers, each borrower is an independent potential plaintiff.

What this means operationally: You need to be able to demonstrate, in writing, that you implemented reasonable security measures for borrower data. "We had antivirus" is not a reasonable security measure under TDPSA in 2026. "We have a GLBA §314.4 program managed by a TX-resident MSSP with documented controls, monitoring, and incident response" is. CoreRecon provides the documentation trail that makes "reasonable security" a defensible legal position.

AG Enforcement
Texas Attorney General Ken Paxton's office has signaled mortgage and financial services as a 2025–2026 TDPSA enforcement priority. The AG's data privacy unit issued guidance in Q3 2024 specifically addressing financial institution obligations. Civil penalty: $7,500 per intentional violation. Each borrower record that was not adequately protected constitutes a separate violation under the AG's enforcement theory.
Class Action Combination
Post-breach, Texas borrowers' counsel has been filing under both TDPSA and the Texas Breach Notification Act (Texas Bus. & Com. Code §521.053) simultaneously. The combination creates two independent damages theories: TDPSA: statutory damages per violation; §521.053: actual damages + attorney fees. A class of 1,200 Texas borrowers with $500 average actual damages = $600,000 before attorney fees — achievable for any mid-size IMB.
The Defense Strategy
The best TDPSA defense is a pre-breach reasonable-security paper trail. Courts have consistently held that entities with documented, actively maintained security programs that still suffer breaches face materially lower liability exposure than entities that cannot demonstrate any program existed. CoreRecon's documentation deliverables — risk assessments, written program, quarterly posture reports — are designed to survive litigation scrutiny.
Frequently Asked Questions

Straight Answers for Texas Mortgage Operations

What is the minimum endpoint count to start with CoreRecon? +

Ten (10) endpoints. This covers a small independent broker with 3–5 MLOs and shared infrastructure. For context, a typical 5-MLO broker shop has 5 MLO laptops, 1–2 servers (LOS, file share), 1 network appliance, and 1–2 admin machines = 9–10 endpoints. The minimum means you're not locked out because you're not "enterprise-sized." There is no enterprise contract requirement, no minimum term, and no setup fee.

How long does onboarding take, and will it disrupt our LOS or pipeline operations? +

Standard onboarding completes in 5–7 business days for a 10–75 endpoint environment. EDR agent deployment is silent and non-disruptive — no reboots required for most endpoints, no application conflicts with Encompass, BytePro, Calyx, or Floify LOS/POS platforms. Email security integration (BEC detection layer) goes live within 24 hours via MX record change or connector configuration — takes approximately 20 minutes with your IT contact or email admin. We have never caused a closing delay due to onboarding.

Can CoreRecon serve as our GLBA §314.4 Qualified Individual? +

Yes — under the Command tier, CoreRecon's vCISO can formally serve as your designated Qualified Individual. The Safeguards Rule allows the QI to be an employee or a qualified outside service provider. We will accept the QI designation in writing, maintain the required documentation, deliver the annual §314.4(i) board/management report, and be available for TDSML examination questioning. Sentinel and Fortress tiers provide all QI support documentation — you designate an internal individual who relies on our program infrastructure.

Does CoreRecon support NMLS bond reporting and TDSML cybersecurity examination requirements? +

Yes. TDSML added a cybersecurity questionnaire to its examination scope starting in 2024. CoreRecon provides a pre-examination preparation packet that addresses every question on the current TDSML cybersecurity examination guide, including incident history, program documentation, vendor oversight records, and risk assessment currency. For NMLS bond reporting: if a cybersecurity-related fraud event occurs that requires bond notification, CoreRecon prepares the written incident summary for your bond carrier and provides documentation supporting any subrogation defense.

We use Encompass (ICE Mortgage Technology) — does CoreRecon integrate with it? +

Yes. CoreRecon's EDR and SIEM have pre-built integration profiles for Encompass 360 and Encompass SmartClient. We monitor for unusual Encompass API access patterns, credential sharing across LO accounts, bulk loan file export events, and privilege escalation on the Encompass administrator account. We also conduct annual security configuration reviews against ICE Mortgage Technology's recommended Encompass security hardening guide. Calyx Point, BytePro Express, Floify, and SimpleNexus are also in our integration library.

How does CoreRecon handle the wire fraud scenario — what exactly happens if we get a BEC alert? +

The exact sequence: (1) CoreRecon's email security layer flags a suspicious outbound message from an MLO account that matches BEC wire instruction patterns; (2) an analyst reviews within minutes and escalates if confirmed; (3) within 30 minutes, you receive a direct phone call (not just an email) from a CoreRecon analyst with specifics on which account was compromised and which transactions are at risk; (4) we provide a written incident summary within 2 hours for your bank's fraud team, which is the document your bank needs to initiate an FBI FFKC Priority Funds Return Request. We maintain a direct line to FBI Houston's Financial Crimes Unit for urgent FFKC escalations.

Our warehouse lender requires a cybersecurity attestation — can CoreRecon support that? +

Yes. Warehouse lenders (Texas Capital Bank, Western Alliance, Flagstar, etc.) increasingly include cybersecurity questionnaires in their annual IMB due diligence process. CoreRecon provides a completed warehouse lender cybersecurity questionnaire response package under the Command tier, covering: security program documentation, incident history, penetration testing recency, encryption standards, access control evidence, and third-party audit status. Fortress tier clients receive a template and guidance. Most questionnaires take 2–3 hours to complete with CoreRecon support vs. 2–3 weeks without.

What happens to our data if we cancel CoreRecon service? +

Upon contract termination, CoreRecon removes all EDR agents from your endpoints within 48 hours of your request. We provide you with a complete export of all security event logs, incident reports, and compliance documentation generated during your service period — this is your property, required for TDSML examination records, and you receive it in a format compatible with standard SIEM and document management systems. We retain no customer data beyond the retention period in our data processing agreement. You own all your compliance documentation.