Banking and Finance Law Daily Wrap Up, OVERSIGHT AND INVESTIGATION—FDIC OIG finds cyber detection gaps, slow account removals in incident response program, (Sep 2, 2026)
Organizations Mentioned:Black Elk Energy Offshore Operations, LLC | Plata Latina Minerals Corp.

By Shashi Kant, BALLB, LLM.
An audit found that the agency’s SIEM missed 90 percent of simulated cyberattacks and that the agency was slow to remove terminated employees’ network access.
The Federal Deposit Insurance Corporation’s Office of Inspector General (OIG) released an audit, finding that the FDIC’s security information and event management (SIEM) tool did not generate alerts for 45 of 50 simulated adversarial tests conducted against the agency’s network, a 90 percent miss rate (AUD-26-03, August 2026). The audit, which evaluated the FDIC’s processes to detect, respond to, and defend against cyber threats, also identified delays in removing network access for involuntarily separated employees and gaps in how the agency tests and updates its incident response plans.
Background. Under federal law and regulation, the FDIC is responsible for safeguarding information, data, and assets from loss, theft, or compromise, the OIG said. The agency reported more than 120 incidents to the Cybersecurity and Infrastructure Security Agency in 2024, all scored as low or negligible, and the FDIC stated that none were attributed to a nation-state actor. The OIG noted that CISA has continued to identify cyber threats targeting the financial services sector. The audit covered April 2025 through July 2026 and was conducted under the Government Accountability Office’s Generally Accepted Government Auditing Standards.
Endpoint detection and response gaps. Auditors performed 50 adversarial emulation tests in September 2025 using the open-source Invoke-Atomic tool, simulating techniques mapped to the MITRE ATT&CK framework under an assumed-breach testing environment. The OIG found that the FDIC’s SIEM tool was configured to detect predefined notable events but did not generate one from ingested endpoint detection and response (EDR) logs for 45 of the tests, leaving the simulated activity undetected. The FDIC told auditors that its EDR use case was designed to complement, rather than duplicate, another security tool, and that a significant portion of simulated attack activity may not generate alerts when that other tool is disabled during testing. The OIG recommended that the Director of the Division of Information Technology (DIT) update the FDIC’s content development process based on the test results to identify coverage gaps, and separately recommended updating access permissions on FDIC endpoints to prevent unauthorized users from disabling or interfering with EDR services.
Access control for involuntary separations. The OIG compared involuntary separations to network access removals for calendar year 2025 and found that 2 of 12, or 17 percent, did not have logical access removed until after the employee’s effective separation date, in one case by four days and in the other by three. DIT officials told the OIG that the separation dates were entered into the FDIC’s HR system after the fact and that DIT had not received disablement notifications from the office then responsible for misconduct reviews. The FDIC could not explain why the notifications were not sent, though the OIG confirmed no security incident occurred in either instance. The report cites CISA guidance recommending access revocation within one hour for high-risk separations and within four hours for moderate-risk separations, and states that the FDIC’s access control directive lacked specific timetables tied to the elevated risk of involuntary separations. The OIG recommended that the FDIC’s Assistant General Counsel for Labor, Employment, and Administration update applicable directives to ensure DIT is notified of involuntary separations at or before the employee is notified, and to establish risk-driven timetables for revoking access.
Incident response plan testing. The OIG also found that the FDIC could not document that its Incident Response Plan was tested on its own, stating instead that it is tested as part of the Breach Response Plan. The results of June 2024 testing were not used to update either plan, which was last revised in February 2024, according to the report, and the FDIC’s Cybersecurity Event Recovery Plan was last updated in June 2018. The report states that the FDIC’s testing processes were not aligned to cover the full National Institute of Standards and Technology (NIST) incident response lifecycle from detection through recovery. The OIG recommended that the Director of the Division of Information Technology update testing procedures to align with NIST Cybersecurity Framework functions and ensure that plan updates follow from test results.
FDIC response and next steps. The FDIC’s Chief Information Officer and Acting Chief Information Security Officer submitted a written response on Aug. 25, 2026, concurring with all four recommendations. The OIG said the FDIC’s proposed corrective actions were sufficient to address their intent and considers the recommendations resolved but open pending completion. The FDIC stated it has already implemented role-based access permissions and privileged access certification for a newly deployed EDR tool, pending submission of supporting documentation to the OIG. Remaining corrective actions are due on a rolling basis, with the FDIC’s Legal Division updating separation-notification directives by June 30, 2027, and the Chief Information Officer Organization updating its content development procedures by Mar. 31, 2027, and its incident response testing procedures by July 31, 2027. The OIG said the recommendations will remain open until it confirms the corrective actions are complete and responsive.
MainStory: TopStory CrimesOffenses CyberPrivacyFeed DataPrivacy DataSecurity OversightInvestigations Privacy