Financial Sector Releases Minimum Cyber Guidelines with Support of U.S. Treasury
Washington, D.C.– ​The Cyber Risk Institute (CRI) applauds the Financial Services Sector Coordinating Council (FSSCC) and the U.S. Department of the Treasury for publishing the Financial Services Sector Specific Goals (FS-SSGs), a voluntary set of baseline cybersecurity goals based on the CRI Profile.
These FS-SSGs leverage the CRI Profile’s baseline control objectives, referred to as Tier 4 Diagnostic Statements, to provide practical, sector-specific cybersecurity guidance that aligns with established standards, regulatory expectations, and industry frameworks.
The FS-SSGs serve as a bridge between the Cybersecurity and Infrastructure Security Agency’s (CISA) Cross-Sector Cybersecurity Performance goals (CPGs) and the financial sector’s established expectations reflected in the CRI Profile. Rather than introducing new requirements, the FS-SSGs identify a set of prioritized cybersecurity practices designed to address the most critical risks facing financial institutions and the broader financial services ecosystem.
The financial services sector is highly regulated and mature in cybersecurity risk management practices and, for U.S.-supervised entities, Tier 4 of the CRI Profile represents minimum expectations. However, the sector’s interconnection with vendors and suppliers—many of whom may lack comparable cybersecurity practices—pose a significant risk to the sector. The FS-SSGs seek to address this risk by providing clear guidance to strengthen resilience across the financial ecosystem.
“CRI is honored to have collaborated with the FSSCC, U.S. Treasury, CISA, and other government agencies on this initiative,” said Josh Magri, President and Founder of CRI. “The financial services sector has long recognized that its resilience depends not only on the cybersecurity of individual institutions, but also on the security of the broader ecosystem. The FS-SSGs provide financial institutions and the supply chain with a practical, risk-based resource that bridges CISA's Cross-Sector Cybersecurity Performance Goals and the CRI Profile's Tier 4 Diagnostic Statements, helping organizations strengthen cybersecurity while promoting greater consistency across the sector.”
The FS-SSGs, like the CRI Profile, are voluntary and intended to help organizations strengthen cybersecurity practices and improve resilience. The FS-SSGs are available through CRI at www.cyberriskinstitute.org and the FSSCC at https://fsscc.org/published-posts/ and https://home.treasury.gov/system/files/216/financial-services-sector-specific-goals-082426.pdf.
Media Contact:
Emily Beam
Emily.Beam@cyberriskinstitute.org
September 15, 2026
