Ask the Experts: Performing Effective IT Risk Assessments for Financial Institutions
IT risk assessments remain a cornerstone of a strong information security program, but the way institutions approach them has changed. What was once a periodic, compliance-driven exercise is now expected to be a living process that informs decision-making, prioritizes controls, and keeps pace with evolving threats, technology and regulatory expectations.
In Tandem's Ask the Experts session, Cherry Bekaert's Audrey Magennis and Kirsten Furlong will share practical context on how IT risk assessments are being performed today across banks, credit unions and other financial institutions. They will answer your most commonly asked questions about what examiners expect, where institutions struggle and how to make the process meaningful instead of mechanical.
In this session, you will learn and ask questions about:
- How IT risk assessments have evolved from static reports to ongoing risk management tools
- Common pitfalls institutions face when scoping, scoring and documenting risk
- How to align risk assessments with GLBA, FFIEC and examiner expectations
- Practical approaches to identifying assets, threats, controls and residual risk
- How to keep risk assessments current without overcomplicating the process
Whether you work in risk management, compliance, information security or IT leadership, this discussion will help you build a more meaningful, defensible and effective IT risk assessment program for your financial institution.
Speakers