FFEIC Cybersecurity Assessment Tool

FFIEC Cybersecurity Assessment Tool

Due to the increasing volume and sophistication of cyber threats, the FFIEC developed the Cybersecurity Assessment Tool

(Assessment) on behalf of its members to help institutions identify risks and determine their cybersecurity maturity.

The content of the Assessment is consistent with the principles of the FFIEC Information Technology Examination Handbook (IT Handbook) and the National Institute of Standards and

Technology (NIST) Cybersecurity Framework, as well as industry-accepted cybersecurity practices.

The Assessment provides institutions with a repeatable and measurable process to inform management of their institution’s risks and cybersecurity preparedness and consists of two parts:

  • Inherent Risk Profile
  • Cybersecurity Maturity 

The Inherent Risk Profile identifies the institution’s inherent risk before implementing controls.

The Cybersecurity Maturity includes domains, assessment factors, components, and individual declarative statements across five maturity levels to identify specific controls and practices that are in place. While management can determine the institution’s maturity level in each domain, the Assessment is not designed to identify an overall cybersecurity maturity level.


To complete the Assessment, management first assesses the institution’s inherent risk profile based on five categories:

  • Technologies and Connection Types
  • Delivery Channels
  • Online/Mobile Products and Technology Services
  • Organizational Characteristics
  • External Threats

Management then evaluates the institution’s Cybersecurity Maturity level for each of five domains:

  • Cyber Risk Management and Oversight
  • Threat Intelligence and Collaboration
  • Cybersecurity Controls
  • External Dependency Management
  • Cyber Incident Management and Resilience


If you are interested in Drummond’s FFIEC Risk Assessment Services, please complete this form below and let us know how we may help you get started.

Privacy Preferences

When you visit our website, it may store information through your browser from specific services, usually in the form of cookies. Here you can change your Privacy preferences. It is worth noting that blocking some types of cookies may impact your experience on our website and the services we are able to offer.

Click to enable/disable Google Analytics tracking code.
Click to enable/disable Google Fonts.
Click to enable/disable Google Maps.
Click to enable/disable video embeds.
Our website uses cookies, some from third-party services. Define your Privacy Preferences and/or agree to our use of cookies.