Share This Page

FDIC’s Incident Detection and Response Program

September 1, 2026 / Source: OIG

The Office of Inspector General (OIG) of the Federal Deposit Insurance Corporation (FDIC) issued its report on the FDIC’s Incident Detection and Response Program

Under Federal law, regulation, and guidance, the FDIC is responsible for safeguarding information, data, and assets from loss, theft, or compromise. To do this, the FDIC must maintain the ability to prepare for, respond to, and resolve computer security incidents. Failure to protect bank, employee, and other sensitive information (e.g., facts, data, or opinions in any medium or form) could cause irreparable financial, reputational, operational, or other harm to the FDIC, individuals, and entities. 

Incidents can come from sources that are external (e.g., nation state actors) or internal to the organization (e.g., employees). The FDIC uses several security tools to support its incident monitoring process. Specifically, the FDIC leverages its Endpoint Detection and Response (EDR) tool to log suspicious activity and send this information to a log repository referred to as the Security Information and Event Management tool. The FDIC also developed an Incident Response Plan as a roadmap for implementing its incident response program and to provide guidance on how to respond to incidents. 

We conducted an audit to determine to what extent the FDIC has implemented processes to detect, respond, and actively defend against cyber threats. Overall, we found that the FDIC has implemented processes to detect, respond, and actively defend against cyber threats. However, in three separate control areas, we found the FDIC could strengthen its existing controls: 

  1. Strengthen Monitoring of EDR Logs: The FDIC can strengthen its monitoring of endpoint detection and response logs to better detect known adversarial techniques such as running malicious code, maintaining access, and avoiding detection;  
  2. Improve Access Control Policies for Involuntary Separations: The FDIC can update its policies for involuntarily separated employees to address the elevated risk present when an employee is involuntarily separated; and  
  3. Enhance Incident Response Testing Process: The FDIC can better align its incident response capabilities testing to National Institute of Standards and Technology (NIST) standards while improving coordination between the Office of the Chief Information Security Officer and the Division of Information Technology. 

The OIG made four recommendations to help improve the FDIC’s ability to detect, respond, and actively defend against cyber threats. The FDIC concurred with all four recommendations and plans to complete all corrective actions by July 31, 2027.