Skip to content

Invest2 publishers3 min readPublished Updated

Fed's Bowman tells bank boards to scale cyber spending to their bank's own risk

Michelle Bowman, the Fed's top supervisor, told community bankers that boards own AI-driven cyber risk and must match their cyber spending to their bank's risk. She gave no dollar benchmark, so the standard will only be as strong as the IT examiners who apply it, and she says their approach is tailored to each bank's risk profile.

The Investor · Invest desk

Photograph accompanying Fed's Bowman tells bank boards to scale cyber spending to their bank's own risk
Photo: americanbanker.com

What happened

  • In brief video remarks played at a Fed cyber workshop in Denver, Bowman said the threats banks face have risen "exponentially" as traditional hackers and AI agents spread.
  • Her baseline list covered current asset inventories, phishing-resistant multifactor authentication, identity and access controls, patch management, staff training and incident response testing.
  • She called AI both a defensive tool and an evolving risk, and said many community banks are already exploring how to deploy it safely.
  • Bowman led a Financial Stability Board report on sound practices for responsible AI adoption, and the group is now sorting through public comments gathered over the summer.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • decision Each board has to decide for itself what cyber spending "aligned with the risk and complexity of the institution" means in dollars, because the Fed attached no benchmark to the phrase.
  • exposure With directors and senior managers named as the first owners of cyber risk, an examiner's cyber findings become a governance question for the board as well as an IT one.
  • constraint A budget scaled to one bank's size does little against weaknesses in shared technology that AI can turn into simultaneous disruptions at many institutions.

"Cybersecurity requires proactive risk management by boards of directors and senior management," Bowman said. "It also requires strategic investments in people, processes, and technology that are aligned with the risk and complexity of the institution." [4] The second sentence is a budget rule that leaves each bank to supply the numbers. Her remarks did not include a dollar floor, a share of revenue or a peer benchmark [4]. A board that wants to meet the standard has to pick its own figure and be able to explain it.

The case for a bigger figure comes from the attackers' side. AI, Bowman said, has "the ability to accelerate vulnerability identification, create sophisticated social engineering campaigns, lower the barrier to entry for cyber criminals, and adapt attacks in real time as they are carried out." [17] Those are falling costs for the people mounting attacks. They come on top of the ransomware, business email compromise and vendor data breaches she said banks already face [16].

Enforcement is less settled than the board language suggests. At the Sept. 29 Denver workshop, Bowman said preparing for these threats can be burdensome and challenging for community lenders [2][8]. "That's why we continue to tailor our approach to IT examinations to consider risk profile and emerging threats and risks," she said [9]. She also asked small banks to tell the Fed how it could make its expectations clearer [10].

Examiners could fold the alignment sentence into IT exams and ask boards to show how cyber budgets track risk. Tailoring could instead mean narrower exam scope at small banks, with the sentence left as guidance. A third possibility is that the Financial Stability Board sound-practices report Bowman led, still in comment review, becomes the text examiners point to [14]. I think the first outcome is the likeliest. She put responsibility first and foremost with bank leadership [5], and she said regulators have a role in making sure these risks are addressed [18]. The counter-case is the second path, and her request for feedback supports it: a supervisor still asking what its expectations should say has not yet written the examiner's question. I would be wrong if Fed exam work at community banks keeps treating cyber as a controls checklist and leaves out board oversight of investment.

A size-based rule has a harder problem, raised by a report quoted in PYMNTS's coverage: "By accelerating vulnerability discovery and exploitation across shared technologies, AI can turn weaknesses that once produced isolated incidents into correlated disruptions affecting multiple institutions simultaneously." [13] A community bank can scale its patching and training to its own complexity. Spending more on its own staff will not fix a flaw in technology it shares with other banks.

The Fed's own commitment is events. Bowman said it will keep hosting workshops as part of its "ongoing commitment to identify and equip community banks with resources that may be necessary to combat cyber risks." [15] The banks' own budgets pay for the six practices she listed [1].

What to watch

  • Whether Fed IT examinations at community banks start asking boards to show how cyber budgets track the bank's risk and complexity.
  • The final Financial Stability Board sound-practices report on AI adoption after the summer comment review, and whether US examiners cite it.
  • What small banks send back on Bowman's request for feedback on how the Fed can clarify its cyber expectations.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories