DENVER — Federal Reserve Vice Chair for Supervision Michelle W. Bowman urged community banks to strengthen basic cybersecurity practices and test their response plans as criminals use artificial intelligence to make attacks more sophisticated.
In opening remarks at the 2026 Community Bank Cyber Workshop, Bowman said a number of community banks had experienced significant cyber incidents over the past year. Banks continue to face ransomware, business email compromise and breaches involving vendors, she said, while AI can help attackers identify vulnerabilities, craft convincing social engineering campaigns and adjust attacks as they unfold.

“Defending against these risks begins with strong cyber hygiene,” Bowman said in remarks released by the Fed. She cited current inventories of technology assets, multifactor authentication designed to resist phishing, strong controls over who can access systems, and programs to identify and patch vulnerabilities. Employee training and periodic tests of incident response plans also are essential, she said.
Role of Risk Management
Bowman said AI can help banks improve their defenses, but its use requires sound risk management. She pointed to a Financial Stability Board report on responsible AI adoption published over the summer, saying some of its case studies were aimed at smaller financial institutions. She invited community banks to offer feedback on how regulators could make their expectations clearer.
Boards and senior managers must take an active role in cybersecurity and invest in staff, processes and technology suited to their institutions’ risks, Bowman said. She acknowledged that those demands can be challenging for community banks and said the Fed continues to tailor its information technology examinations to banks’ risk profiles and emerging threats.
Tabletop Exercise Held
The two-day workshop, hosted by the Federal Reserve Banks of Chicago, Kansas City, St. Louis, Minneapolis and San Francisco, includes a cybersecurity tabletop exercise and sessions on AI, cyber risk management and examinations. Participants include bankers, regulators, law enforcement officers and industry professionals, including representatives of the Secret Service and the Cyber Risk Institute.
“Cyber readiness is not built through technology alone,” Bowman said. “It requires collaboration with internal and external stakeholders, continuous education and training, and support for those on the front lines: your employees and your customers.”




