Few things concentrate the mind like a regulator scheduling an IT exam. For banks and credit unions, cybersecurity isn't just good practice. It's a supervised obligation, and the gap between “we have security” and “we can prove our program” is where findings come from.
The good news: what examiners want is more predictable than it feels. Strip away the acronyms and it comes down to a written program you can evidence.
The GLBA Safeguards Rule: the concrete checklist
If you handle customer financial information, the FTC's updated Safeguards Rule is the clearest statement of the baseline. It requires a written information security program with specific, non-negotiable elements:
- A designated Qualified Individual accountable for the program.
- A written risk assessment.
- Multi-factor authentication for anyone accessing customer information.
- Encryption of customer data at rest and in transit.
- A written incident-response plan.
- Annual penetration testing, plus vulnerability assessments at least every six months where you aren't continuously monitoring.
Notice the pattern: every item is something you must document and demonstrate, not just own.
The frameworks are shifting: know the current one
Examiners' reference points move, and citing a retired one is its own kind of red flag. A notable change: the FFIEC retired its long-used Cybersecurity Assessment Tool as of August 31, 2025, pointing institutions instead toward frameworks like the NIST Cybersecurity Framework 2.0 and CISA's performance goals. The FFIEC IT Examination Handbook remains the underlying baseline examiners work from. For credit unions, the NCUA runs its own Information Security Examination program and assessment tooling.
The takeaway isn't to memorize the alphabet soup. It's that “we did a CAT assessment in 2023” is no longer the answer, and someone needs to be tracking which framework your examiner now expects.
What findings really come from
In practice, exam findings rarely say “you had no firewall.” They say things like: the risk assessment was stale, MFA had exceptions nobody documented, the incident-response plan had never been tested, access reviews weren't happening, or the evidence simply wasn't there. The controls existed; the program discipline didn't. That's the muscle regulators are actually testing.
How iConvergence helps
We treat exam readiness as an engineering problem, not a scramble the month before. We map your environment to the current expectations (GLBA, the FFIEC handbook, NIST CSF 2.0, NCUA where relevant), implement the missing controls, and build the evidence trail so that when an examiner asks, the answer is a document, not a promise. Then we keep it current, because the next exam is always coming.
The bottom line
Passing an IT exam isn't about buying more tools; it's about running a provable program and keeping it current as the frameworks change. Do that, and the exam stops being an event to survive and becomes a status you maintain.
Sources
- GLBA Safeguards Rule requirements (Qualified Individual, MFA, encryption, IR plan, pen testing): FTC, Safeguards Rule: What Your Business Needs to Know.
- FFIEC retirement of the Cybersecurity Assessment Tool (Aug 31, 2025): OCC Bulletin 2024-25.
- Credit-union cybersecurity examination program: NCUA Cybersecurity Resources.