• Events and Webinars
  • Resources
    • Blog
    • Case Studies
    • News
    • Newsletter
    • Infographics
    • Papers
    • Posters
    • Video
  • Careers
    • Careers at HBS
    • Open Positions
    • Student Opportunities
  • About HBS
    • About Us
    • Leadership
    • Locations
    • Partners
    • Green Initiatives
  • Events and Webinars
  • Resources
    • Blog
    • Case Studies
    • News
    • Newsletter
    • Infographics
    • Papers
    • Posters
    • Video
  • Careers
    • Careers at HBS
    • Open Positions
    • Student Opportunities
  • About HBS
    • About Us
    • Leadership
    • Locations
    • Partners
    • Green Initiatives
HBS logo
HBS Logo
  • Infrastructure
    • CLOUD

      • Cloud Solutions
      • Public Cloud
      • Hybrid Cloud
      • Infrastructure as a Service
      • Cloud Security Solutions
      • Backup, Replication and Disaster Recovery
      • HBS Cloud Hosting Services

      DATA CENTER

      • Data Center Solutions
      • Traditional Data Center
      • Hyperconverged
      • Colocation
      • Directory Services
      • Cloud Email and Calendar Solutions

      NETWORK AND ACCESS

      • Network Infrastructure
      • Enterprise Mobility
      • Wireless Solutions
      • SD-WAN
      • Structured Cabling
      • Staff Augmentation
      Data Center Solutions blue gradient background badge with white text
  • Managed Services
    • MANAGED ONE

      • Managed One Overview
      • Managed Backup and Disaster Recovery
      • Managed Email and Collaboration Security
      • Managed Firewall

       

      • Managed HaaS and SaaS
      • Managed IT Help Desk
      • Managed Network and Server Monitoring

      HBS + PARTNER SOLUTIONS

      • HBS Secure with Verkada
      • HBS Collaborate with Webex
      • Managed XDR
      HBS Managed One Megamenu Graphic
  • Modern Workplace
    • MICROSOFT

      • Microsoft Licensing Management
      • Microsoft Modern Workplace
      • Microsoft Copilot
      • Microsoft Fabric
      • Microsoft Funding Opportunities

       

      • Dynamics 365 Business Central
      • Dynamics 365
      • Dynamics GP

      COLLABORATION

      • Audio Visual
      • Unified Communication Solutions
      • HBS Collaborate with Webex
      HBS Collaborate with Webex blue gradient background badge
  • Professional Services
    • ADVISORY

      • Virtual CISO
      • Virtual CIO
      • Project Management
      • IT Business Consulting

      ENGINEERING SERVICES

      • Staff Augmentation

      AI & ANALYTICS

      • Artificial Intelligence
      • AI Advance
      • AI Predict
      • AI Assist
      • Data Management and Analytics
      • Microsoft Copilot
      • Microsoft Fabric

      APPLICATION INNOVATION

      • Website Development
      • Application Development

      DOCUMENT MANAGEMENT

      • Document Management Services
      • Document and Check Scanners
      Discover your AI Readiness blue gradient background with white text. Bottom right photo of young man in glasses smiling while looking at laptop. Red to green temperature gauge png
  • Security
    • CYBERSECURITY

      • Managed XDR
      • Penetration Testing
      • Vulnerability Scanning
      • Email Security Services
      • Digital Forensics and Incident Response
      • Backup, Replication and Disaster Recovery
      • Firewalls
      • Cloud Security Solutions

       

      • Virtual CISO
      • Virtual Security Team
      • Virtual Security Engineer
      • Cybersecurity Risk Assessment
      • Governance and Compliance
      • SOC 2
      • CMMC
      • Managed Security Awareness Training

      PHYSICAL SECURITY

      • Security Solutions
      • HBS Secure with Verkada
      Cybersecurity Risk Assessment Megamenu Graphic
  • Search
Contact Us
Blog

An Overview of the FFIEC Cybersecurity Assessment Tool

  • Written by: Jeff Hudgens
  • September 14, 2015
FFIEC Cybersecurity Assessment Tool Graphic

An effective risk management program is a critical component of organization’s overall information security. To be effective, an organization not only needs to understand the value of its assets, but also needs a framework to determine its risks, measure the level of maturity of its information security efforts, and determine its progress towards its security goals.

On 30 June 2015, an FFIEC press release announced the organization’s new cybersecurity assessment tool, which was designed “to help institutions identify their risks and assess their cybersecurity preparedness.” The assessment tool takes a “2x5” approach – there are two parts involved in its use, and each part uses five categories to frame the analysis involved. This leads to slightly different outcomes– the inherent risk analysis results in an overall inherent risk profile assigned to one of five levels, while the analysis of cybersecurity maturity results in a determination of maturity level for each of the five domains provided.

Determining an Inherent Risk Profile

Let’s break down the tool a bit. The first part focuses on helping an organization determine its inherent risk profile. To do this, the tool uses five analysis categories:

  1. Technologies and Connection Types
  2. Delivery Channels
  3. Online/Mobile Products and Technology Services
  4. Organization Characteristics
  5. External Threats

At the end of the analysis, the resulting inherent risk profile is assigned one of five potential levels:

  1. Least
  2. Minimal
  3. Moderate
  4. Significant
  5. Most

Determining Cybersecurity Maturity Levels

The second part focuses on determining a cybersecurity maturity level for each of five domains. Each domain has assessment factors to help scope the analysis required. The domains and assessment factors are:

  1. Domain 1: Cyber Risk Management and Oversight Assessment factors: Governance; Risk Management; Resources; Training and Culture
  2. Domain 2: Threat Intelligence and Collaboration Assessment factors: Threat Intelligence; Monitoring and Analyzing; Information Sharing
  3. Domain 3: Cybersecurity Controls Assessment factors: Preventative Controls; Detective Controls; Corrective Controls
  4. Domain 4: External Dependency Management Assessment factors: Connections; Relationship Management
  5. Domain 5: Cyber Incident Management and Resilience Assessment factors: Incident Resilience Planning and Strategy; Detection, Response, and Mitigation; Escalation and Reporting

The resulting analysis within each of the five domains leads to a maturity level. These are:

The tool does not provide an overall level of organizational cybersecurity maturity. Management should combine the results of the analysis with other information and analysis to make that determination.

As part of the overall information included with the tool, the FFIEC has provided a mapping of the tool’s baseline statements to the FFIEC IT Examination Handbook. The information also includes a Cybersecurity Assessment Tool-to-NIST Cyber Security Framework (CSF) mapping for those organizations that reference the CSF. Unfortunately, there is no extended mapping to the NIST 800-53 controls.

Finally, you should know that this new tool is not automated. There will be elbow-grease and hard work involved. However, if you are interested in a different approach to building your organization’s risk profile and understanding its cybersecurity maturity, and you like using 2x5s, this tool may be for you. To check it out yourself, visit the FFIEC’s website at: https://www.ffiec.gov/cyberassessmenttool.htm

Related Content

Risk Matrix Likelihood Impact

Risk Assessment: Likelihood and Impact

Assess risk effectively with the risk assessment likelihood and impact matrix. This decision-making matrix assesses risk based on the likelihood and impact of threats in your organization.

Learn More »

Cybersecurity Risk Assessment

Optimize your security with an HBS Cybersecurity Risk Assessment. Identify vulnerabilities, manage risks, improve your cybersecurity posture.

Explore More »
numbers and data

IT Company Assessing Risk to Protect Clients

A company managing clients’ IT infrastructure can’t afford a breach. That’s why this IT solution provider took recommendations from their colleagues and hired HBS to conduct a risk assessment.

Read More »
  • Governance, IT Leadership, Organizational Resilience, Policies, Risk Management
Blog

Connect:

[email protected]  |  800.236.7914

HBS logo

HQ | 1700 Stephen Street
Little Chute, WI 54140
Locations

HBS Remote Support | Service & Technical Support | E-Bill Portal
Standard Terms & Conditions | Cookie Policy | Privacy Policy | Onboarding Form | End User Agreements | E-Bill FAQ | Site Map
Any purchase is governed by the HBS Standard Terms and Conditions.
©2026 Heartland Business Systems. All rights reserved.

Halo from HBS
This chat may be recorded as described in our Privacy Policy.