Q&A with Sean Darragh: How Community Financial Institutions Can Build Greater Cyber Resilience

Cybersecurity threats continue to evolve, but for community financial institutions, the challenge extends beyond keeping up with the latest attack. Limited resources, growing third-party dependencies, and new technologies like AI are changing how institutions must think about security and prepare for what comes next.

Sean Darragh, Chief Information Security Officer at CSI, helps lead the company’s approach to information security and risk management. With more than 20 years of experience in financial services, Sean brings a practical perspective on the challenges institutions face today. We sat down with Sean to discuss the evolving threat landscape, where institutions may be underestimating their risk, and what leaders can do to build greater resilience.

As we continue to see the threat landscape evolve, what are the biggest cybersecurity challenges community financial institutions face today?

“The challenge for community banks and credit unions today is that they are fighting an enterprise-scale threat with community-bank-scale resources. Ransomware remains a stand-out risk, with activity across the financial sector reaching its highest recorded levels in recent years. At the same time, the number of cyber incidents targeting financial firms continues to rise year over year.

The second challenge is talent and bandwidth. Most community institutions operate with lean IT and security teams that must balance regulatory exams, vendor due diligence, and incident response alongside day-to-day operations. That challenge has only grown as expectations have evolved. When the Federal Financial Institutions Examination Council (FFIEC) retired its Cybersecurity Assessment Tool, institutions were directed toward frameworks such as the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) 2.0 and the Cybersecurity and Infrastructure Security Agency’s (CISA) Cybersecurity Performance Goals. At the same time, threat actors are using AI to automate and scale their attacks. Community financial institutions are now being asked to keep pace with both, often without the additional resources to do so.”

What assumptions about cybersecurity do you think are putting financial institutions at greater risk?

“The single most dangerous assumption an institution can have is ‘we’re too small to be a target’. Attackers, especially ransomware crews and their affiliates, actively favor smaller institutions precisely because they expect weaker defenses and a higher likelihood of payment. A close second is the assumption that compliance equals security. Passing an exam or completing an annual risk assessment is a snapshot in time, not evidence of ongoing resilience. Threat actors don’t wait for the next exam or audit cycle to attack.

Another assumption worth challenging is that cybersecurity is purely an IT problem. When leadership treats it that way, cyber risk can remain isolated from the broader decisions the institution makes about managing and preparing for risk. This is exactly why NIST CSF 2.0 added the “Govern” function. To push accountability up to leadership and as a signal that regulators no longer see cybersecurity as something that can be fully delegated downward.”

Which emerging cyber threats concern you the most right now, and why?

“Ransomware-as-a-service and its increasingly professionalized affiliate networks are still a major concern for me. Even after the successful shutdown of major groups in recent years, we have seen successor operations regroup and, in some cases, recover lost volume. Further, the danger isn’t just encryption; it’s double extortion, where stolen customer data is threatened with public release regardless of whether a ransom is paid.

I am also deeply concerned with third-party and vendor concentration risk. A growing share of the vendors financial institutions rely on now carry serious, unpatched vulnerabilities, and a single compromised provider can expose dozens of institutions simultaneously through shared platforms or managed services. This is exacerbated by the rise of AI-enabled phishing and deepfake social engineering, which is scaling the threat landscape faster than many community institutions’ controls.”

AI seems to be all anyone is talking about these days. How is it changing the cybersecurity landscape?

“Cybercriminals have been among the earliest adopters of AI, using it to create more-convincing phishing emails and to discover ways to exploit vulnerabilities faster than ever before. Which is why phishing volume against the financial sector remains disproportionately high compared to other industries. What used to require a skilled attacker can now be automated and personalized at scale, lowering the bar for less sophisticated criminals to run convincing campaigns.

For defenders, AI is helping security teams do more with less by automating log analysis, identifying unusual activity, and accelerating tasks that once required significant manual effort. For community institutions, that can help close the resource gap, but it also introduces new risks. Using third-party AI tools without proper oversight can expose sensitive customer or transaction data and create new data-handling concerns.”

How can community financial institutions balance innovation and digital transformation without introducing unnecessary cyber risk?

“I believe the key is building security into the procurement and design process from day one, rather than bolting it on after a new product or partnership has already launched. Every new integration should go through a risk assessment that asks not just ‘does this work’ but ‘what does this expose and who else now has access to our data or systems’. Institutions that treat security as a gate at the end of the innovation pipeline, rather than a partner throughout it, end up either introducing risk they didn’t intend to or slowing innovation to a crawl out of fear.

The second half of that balance is vendor governance. Community institutions rarely build fintech capabilities in-house; they rely on partners to deliver them. That makes strong third-party risk management critical to innovating with confidence. Moving quickly without compromising security requires ongoing monitoring and a strong understanding of how data is handled before a partnership goes live.”

Cybersecurity often happens behind the scenes. How does a strong security program ultimately strengthen customer trust?

“That is so true! Customers rarely see the firewall rules, the vulnerability scans, the patching, or the incident response drills, but they absolutely feel the consequences when those things fail: fraudulent transactions, data breach notifications, or a mobile app that’s down for days after an attack. A strong, largely invisible security program is what allows customers to bank online and share sensitive financial information without a second thought. That quiet reliability is a core part of the value a financial institution provides, even if it never shows up in a marketing brochure.”

Looking ahead three to five years, what do you believe will have the biggest impact on cybersecurity in banking?

“Ahhh yes, let us peer into the crystal ball… If I had to forecast based on what I am seeing now, I would say the integration of AI into both offense and defense will likely be the single biggest force reshaping this space. As generative AI lowers the cost of running sophisticated social engineering and fraud campaigns, financial institutions will need AI-powered defenses just to keep pace.

Practically, security operations that still rely on manual review and legacy rule-based detection will fall behind rapidly. Regulatory frameworks will continue evolving in response, and proposals like mandatory 72-hour cyber incident reporting for critical infrastructure sectors suggest examiners will expect faster detection and disclosure than institutions have historically been built for.

Another major shift will be around third-party and ecosystem risk management. As community institutions increasingly rely on shared cores, cloud infrastructure, and integrations, the industry’s collective risk becomes more concentrated among a smaller number of critical vendors. This means a single vendor compromise has the potential to affect dozens or hundreds of institutions simultaneously. Over the next several years, I expect more standardized, continuously updated vendor risk-sharing frameworks, driven both by regulation and institutions’ own recognition that a single annual questionnaire can no longer keep pace with how quickly this risk evolves.”

If you could give every community bank CEO one piece of cybersecurity advice, what would it be?

“Many unhelpful responses jump to mind… But in all seriousness, treat cybersecurity as a business risk you personally own, not a technical problem you delegate and forget. The institutions that handle incidents best are usually the ones where the CEO and board were engaged long before an attack happened. They asked the hard questions, made sure their response plans actually worked, and gave security a real seat at the leadership table.

If you only remember one thing, let it be this: when an incident does happen, what matters most is how prepared your institution is to respond. Those moments leave little room to figure things out as you go, which is why preparation must start well before an incident occurs. That level of readiness doesn’t happen by accident, and it doesn’t happen in the IT department alone. It happens because leadership decided, ahead of time, that it mattered enough to invest in.”

1080  215 1080 Sean Darragh
Sean Darragh, Chief Information Security Officer

Sean Darragh is the Chief Information Security Officer at CSI, where he leads data security strategy and enterprise technology initiatives. With more than 20 years of experience in the financial services sector, Sean is a seasoned IT and security professional with a diverse background spanning information security, risk management, and operational leadership across multiple organizations.

Get In Touch

Are you looking for the edge to outperform the competition? CSI is a full-service technology and compliance partner.

Let’s talk