Published Documents


FSSCC and U.S. Treasury Release Financial Services - Sector Specific Goals for Cybersecurity

The financial services sector is one of the most technologically advanced and globally competitive sectors of the U.S. economy, supported by decades of investment, innovation, and strong cybersecurity risk management. However, the sector’s deep interconnectedness with other critical third-party service providers—many of which do not operate at the same maturity level—introduces third-party risks that can impact not only financial institutions but the sector as a whole.

To address these risks without adding new requirements or expanding regulation, the U.S. Treasury and the FSSCC have developed voluntary Financial Services - Sector Specific Goals (FS-SSGs) to complement the CISA Cross Sector Cybersecurity Performance Goals 2.0 (CPGs). These goals create a risk-based pathway to help financial institutions’ third parties calibrate their cybersecurity practices to a subset of existing Gramm-Leach-BlileyAct aligned (GLBA) expectations already reflected in Tier 4 of the Cyber Risk Institute (CRI) Profile. The FS-SSGs were provided to members of the Financial and Banking Information Infrastructure Committee (FBIIC) for their awareness.

The FS-SSGs do not introduce new obligations, requirements, or supervisory expectations. Instead, they draw exclusively from a subset of the Tier 4 diagnostic statements in the CRI Profile and provide a clear, scalable on ramp from CISA’s CPGs 2.0 toward practices already expected of regulated financial institutions under GLBA. This approach strengthens sector-wide resilience by improving clarity—not by increasing regulation.

PURPOSE OF THE FS-SSGS
The FS-SSGs are designed to:

  • Strengthen supply-chain security, a known national vulnerability;
  • Reduce the risk of cascading failures across critical infrastructure;
  • Support a more efficient and predictable ecosystem for financial institutions and vendors;
  • Provide clarity for smaller firms and fintech innovators, reducing compliance confusion; and
  • Leverage industry leadership to avoid heavier regulatory alternatives.

You can find the US FS-SSGs here.

Highlighted Resources

Cybersecurity Profile
The FSSCC Cybersecurity Profile is now managed, updated, and maintained by the Cyber Risk Institute (CRI).

Business Services Resilience and Restoration
This white paper defines key terms used in discussions related to operational resilience, business continuity/disaster recovery, and business restoration.