Question: What is a good resource for mortgage companies looking to ensure adequate cybersecurity controls?
Answer:
In January 2026, the Conference of State bank Supervisors (CSBS) published a Cyber Hygiene for Financial Institutions Guide (Guide), which is excellent resource for banks and non-banks (collectively, Financial Institutions). The Guide outlines both critical threats Financial Institutions face, such as ransomware and third-party risks, as well as detailing the following ten fundamental cyber hygiene controls and practices:
- Vulnerability and Patch Management;
- End-of-Life Management;
- Multi-Factor Authentication (MFA);
- Logging and Threat Detection;
- IT Asset Management;
- Cybersecurity Awareness Training;
- Data Backup Programs;
- Threat Intelligence Programs;
- Third-Party Risk Management; and
- Incident Response Planning.
The Guide is set up as separate Fact Sheets addressing each of the controls/practices listed above and serves as a comprehensive tool and reference point for Financial Institutions.