// POSTS TAGGED "community-banking"
Community Banking.
All posts tagged community-banking.
← back to all postsThe Vendor of My Vendor Is My Vendor
Jack Henry, IDScan.net, and LexisNexis. Three companies that aren't banks, all of them a community bank's problem, and not one of them chosen by the bank. Why the failures keep landing a tier or two below the line where your vendor program stops looking.
The Most Expensive Attack on Your Bank Won't Use Malware
Business email compromise still outearns ransomware every year, and it beats banks that have EDR, MFA, and a clean exam. The control that stops it is a process, not a product, and most institutions never test it.
Your Vendor's Auditor Is Also a Vendor
SR Bancorp's breach came through the firm hired to audit its controls. Most vendor risk programs never ask who has access to the data behind the audit itself.
When Your Vendor Gets Breached, You Find Out Last
A fintech software vendor got hit with ransomware and up to 1.35 million banking customers were exposed. Most of their banks did the questionnaire, got the SOC 2, and still found out months late. The control that matters isn't the one you audited.
Your AI Policy Doesn't Cover the Part That Can Actually Hurt You
79% of organizations are deploying AI agents. 6% have updated their governance to match. The gap isn't in the models. It's in what those agents are connected to.
Your Incident Response Plan Is Modeling the Wrong Threat Actor
LockBit dominated tabletops for years. The ransomware ecosystem has rotated. The groups hitting organizations right now are not the ones your IR team practiced against, and that gap has consequences.

"We Have an AI Policy" Is the New "We Passed the Audit"
OpenAI just admitted prompt injection isn't getting solved, and companies are wiring AI agents into production anyway. A policy document is not a control.

The AI Questionnaire Your Vendors Aren't Ready For
Your vendors' employees are using AI tools. That means your data is flowing to model providers you've never assessed. Here are the questions to start asking.

Concentration Risk Wasn't Just About Loans
Community banks have managed concentration risk for a century. Then we handed every customer record to a handful of SaaS aggregators. ShinyHunters is teaching us what that actually costs.

The Framework Trap: When Compliance Kills Security
Security frameworks were built to guide programs, not replace thinking. Do security right and compliance follows. Here's why most organizations have it backwards.