2026 Cybersecurity Trends: Montana Banks & Credit Unions

Verification note: the FFIEC CAT retirement date below was checked directly against FDIC and OCC guidance. The NCUA/ACET section was corrected after research turned up a distinction our prior coverage had blurred; see the rewritten section below.

First Call has worked alongside Montana banks and credit unions on cybersecurity and compliance for more than 25 years, and this year’s biggest change has less to do with new attack techniques and more to do with what examiners now expect to see. The FFIEC retired its Cybersecurity Assessment Tool this past year, and institutions are increasingly asked to produce evidence that their controls actually work, not just describe them on paper.

The Cybersecurity Assessment Tool, built in 2015, gave institutions a structured way to self-assess maturity levels using standardized controls. Since then, NIST released CSF 2.0 and CISA published updated frameworks that better reflect the current environment, so the FFIEC retired the CAT on August 31, 2025, rather than update it piece by piece.

Credit unions have their own version of this shift, and it happened earlier than most institutions realize. NCUA’s Automated Cybersecurity Evaluation Toolbox (ACET) stopped being the actual examination framework back in 2020, replaced by the Information Security Examination (ISE), which has been the real exam standard since 2023. The ACET Toolbox itself still exists as a free, voluntary self-assessment application that NCUA continues to update and align with NIST CSF 2.0, but it is a self-assessment tool, not what your examiner is actually using to evaluate you. If your credit union has been treating ACET as exam prep, you have likely been preparing against the wrong framework since 2023. Our NCUA IT Requirements guide breaks down the ISE tiers (SCUEP, ISE Core, and ISE Core+) and what each one expects.

Most Montana banks and credit unions we talk with already have real controls in place. Producing the evidence on short notice is usually the harder part: a current MFA enforcement report, a documented access review, a backup restore that has actually been tested, and an incident response plan someone has walked through recently. Having a control on paper and being able to prove it works today are two different conversations with an examiner, and the exam only credits the second one.

NCUA’s 2026 supervisory priorities, published January 14, 2026, make this explicit for credit unions: board-level cybersecurity training and vendor and payment-processor risk assessments are both named as active examination focus areas this year, not background expectations.

  • Vendor risk assessments that exist but have not been updated since the vendor relationship changed
  • Backup and restore testing that happens more often in theory than in practice
  • Access reviews that catch stale logins only when someone happens to notice, rather than on a set schedule
  • Incident response plans that were written once and never rehearsed with the team

These same four gaps show up across the two areas we have covered this month. Our piece on vendor cyber incidents walks through building a vendor risk file examiners can actually review, and our piece on business email compromise covers the verification habits that turn a documented control into a tested one.

Boards are increasingly asked to demonstrate oversight of cybersecurity, not just delegate it to IT. That does not mean board members need to understand every technical control, but it does mean they need a regular, plain-language summary of where the institution stands: which functions have current evidence, which are due for review, and what the plan is for closing any open gaps. A short quarterly briefing built around the same six functions you use for exam prep does double duty, since the material you prepare for your board is largely the same material an examiner will want to see.

Treating compliance as a once-a-year scramble before an exam tends to leave gaps everywhere else on the calendar. A steadier approach maps your current controls to a framework like NIST CSF 2.0, assigns a named owner to each function, and reviews progress on a regular cadence instead of an annual one.

Our Advanced Cybersecurity and Compliance program is built around this evidence-first approach, so the documentation you need for an exam is already sitting in your file when the date arrives, instead of being assembled the week before.

  1. Map your current controls against NIST CSF 2.0’s six functions and note where the documentation is thin.
  2. Prioritize evidence, not just controls: reports, logs, and dated reviews an examiner can actually look at.
  3. Sequence the work against your actual audit calendar so nothing turns into a last-minute scramble.
  4. Revisit the plan on a regular cadence with a named owner for each function, rather than a once-a-year exercise.

Is the FFIEC Cybersecurity Assessment Tool still required?

No. The FFIEC retired the CAT on August 31, 2025, and institutions are being directed toward more current frameworks such as NIST CSF 2.0.

Is NCUA’s ACET still used to examine credit unions?

Not as an examination framework. NCUA replaced ACET with the Information Security Examination (ISE) as its actual exam program back in 2020, and ISE has been the standard since 2023. The ACET Toolbox still exists as a free, voluntary self-assessment application, but it is not what your examiner uses to evaluate you.

What framework should replace the CAT?

NIST CSF 2.0 is the framework most commonly cited as a replacement path, organized around six core functions. The right fit still depends on your institution’s size, complexity, and existing program, so a gap assessment against your actual environment is a better starting point than adopting a framework wholesale.

What do examiners mean by evidence of a control?

Evidence means something an examiner can review directly and see is dated: an MFA enforcement report, a completed access review log, a documented and tested backup restore, or a walked-through incident response exercise, not a policy statement saying the control exists.

Do smaller community banks need to follow the same framework as larger banks?

The core expectations around evidence, documented reviews, and tested plans apply regardless of size, but the scope and complexity of implementation should match your institution’s size and risk profile. A gap assessment against your actual environment is a better starting point than adopting a large framework wholesale.

Get It Touch

Don't hesitate to contact us any time.

Whether you have questions, need support, or are ready to explore new IT solutions, our team is here and eager to help. Reach out to us anytime—we’re just a call or message away!

More Like This

Mastering Cybersecurity Compliance: What You Need to Protect Your Business

The digital world has changed drastically over the past decade, and cybersecurity compliance now stands as a cornerstone of modern business operations. Large organizations face particular challenges—where regulatory requirements create additional layers of complexity. Meeting compliance standards isn’t just about legal checkboxes anymore. Organizations must build genuinely resilient security systems that protect critical data while maintaining business continuity.

Read More

Let's Work Together

Schedule a discovery meeting with one of our Advanced Cybersecurity Experts to discuss how First Call can help you start YOUR Security Transformation!