BLOG

FAQ – CSBS Cyber Hygiene

August 19, 2026 BY MQMR Blogger

Question: What is a good resource for mortgage companies looking to ensure adequate cybersecurity controls?

 

Answer:

In January 2026, the Conference of State bank Supervisors (CSBS) published a Cyber Hygiene for Financial Institutions Guide (Guide), which is excellent resource for banks and non-banks (collectively, Financial Institutions). The Guide outlines both critical threats Financial Institutions face, such as ransomware and third-party risks, as well as detailing the following ten fundamental cyber hygiene controls and practices:

 

  1. Vulnerability and Patch Management;
  2. End-of-Life Management;
  3. Multi-Factor Authentication (MFA);
  4. Logging and Threat Detection;
  5. IT Asset Management;
  6. Cybersecurity Awareness Training;
  7. Data Backup Programs;
  8. Threat Intelligence Programs;
  9. Third-Party Risk Management; and
  10. Incident Response Planning.

The Guide is set up as separate Fact Sheets addressing each of the controls/practices listed above and serves as a comprehensive tool and reference point for Financial Institutions.