Maryland’s Office of Financial Regulation Is Using New Solution To Monitor Financial Institution Cybersecurity

By Ray Birch

BALTIMORE—Maryland’s Office of Financial Regulation is one of the first states to use a new solution that monitors cybersecurity threats to regulated institutions. The office’s commissioner believes use of the tool could eventually spread across the country.

Called the SecurityScorecard, the regulator said the solution allows the OFR to “further its consumer protection mission.”

Commissioner Antonio Salazar spoke with CUToday.info about the new tool that was rolled out in the final months of last year.

“We've been laying the groundwork on this initiative for several months and rolled it out, at least the announcement, during Cyber Security Awareness Month,” said Salazar. “We're part of the (Wes) Moore Administration, so, we're keeping the governor's commitment to making sure Maryland consumers and financial institutions are secure.”

The tool is being introduced at a time when NCUA is expressing growing concerns over cyber incidents at credit unions. As CUToday.info reported, NCUA Chairman Todd Harper stated during the agency’s October open board meeting that NCUA may consider adjusting the normal operating level of the NCUSIF due to the growing risk third-party cyber incidents present to the fund. Since the NCUA cyber incident notification rule took effect last September, through Aug. 31, there were 1,072 cyber incidents reported involving credit unions, and 742 were related to third parties.

SecurityScorecard is a commercially available product, Salazar explained.

“We first heard about it through the Conference of State Bank Supervisors that had looked into it and shared their thoughts with some other state regulators, like in Connecticut and New York. Today, they've adopted its usage,” he said. “I'm not certain if they're using it for credit unions, but they have been using it. I know that other state regulators are also considering implementing it.”

Antonio Salazar

Security Scorecard uses proprietary technology and has risk-rating tools to provide what the company calls real-time monitoring and evaluation of an organization's cyber security risk. The OFR will utilize the cyber risk scores and reports produced by SecurityScorecard to address cyberthreats by assessing vulnerabilities, tracking improvements, and taking action in collaboration with the financial institutions when a potential threat is identified, Salazar explained.

“SecurityScorecard looks at the outward facing data and things each organization has—such as websites, portals etc.—and they use their scorecard to assess cyber vulnerabilities and the threats to a financial institution,” Salazar said. “We are using this for credit unions, banks and also some non-depository institutions. We'll use the tool to look at institutions that we prioritize based on their risk and impact to Maryland consumers. We'll get reports from SecurityScorecard and share those results with the institution's management. This is a real benefit to them because they can work with their IT professionals to respond to what SecurityScorecard has found.”

Another Tool To Fight Cyber-Crime

The OFR will then follow up with the institutions as they provide updates and responses to whatever SecurityScorecard reports have found.

“We’ll learn what efforts the institutions undertook to mitigate any concerns,” Salazar said.

Salazar reminded that the OFR conducts regular IT and security exams, and SecurityScorecard is another tool to help fight cyber-crime.

“It’s another arrow in our quiver,” he said. “To be clear, this is a passive monitoring tool. We are not going into a financial institution’s system and monitoring it.”

Salazar confirmed the OFR will prioritize security exams for intuitions for which SecurityScorecard returns a higher risk rating.

“Security Scorecard helps us in that regard,” he said. “But I also believe it will benefit a credit union’s management, because their IT people may be telling them one thing about their cybersecurity while SecurityScorecard paints a different picture. It helps to have an unbiased third-party looking at your security. We're pretty excited about it being a good collaborative tool.”

Could SecurityScorecard be used by more state regulators across the nation?

“It’s possible, as I know more state regulators are looking at it,” Salzar said. “But its uptake is hard to predict, because, obviously, the states are paying for it. So, there's budgetary impact.

“To be clear, Maryland financial institutions are putting tremendous effort into securing their systems and they cooperate with us and the federal regulators to fight cybercrime,” continued Salazar. “We see SecurityScorecard as something that will further our mutual goal of ensuring a safe and sound financial system and expanding collaboration and dialogue with the institutions we oversee. We also think this is a tool that will help a financial institution’s management keep cyber security top of mind.”

 

Section: Standard
Word Count: 884
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Maryland-s-Office-of-Financial-Regulation-Is-Using-New-Solution-To-Monitor-Financial-Institution-Cybersecurity