Feature · Cybersecurity

Cybersecurity and continuity oversight, with the evidence attached.

The Cybersecurity landing rolls up the security frameworks, findings, and controls, and Continuity (BCM) tracks plans, business impact analyses, and exercises.

SectionCybersecurity
UpdatedOctober 2026
Continuity plans
Approved
maker-checker
Impact analyses
RTO / RPO
conflicts listed
Exercises
On cadence
tabletop to full
Coverage · every process graded from its plan and last exercise
ProcessPlanCoverage
Core bankingIT disaster recoveryCovered
Wire transfersEnterprise BCPCovered, test due soon
Card processingDepartmentTest overdue
Call centerNoneNo plan
Illustrative product preview. It does not show tenant data.
01 · Cybersecurity

The Cybersecurity landing

The Cybersecurity screen is the information security program at a glance. It shows only the frameworks your institution has enrolled and keeps in scope. Those are the FFIEC IT and business continuity booklets, GLBA, NCUA Chapter VII, and the cybersecurity standards you follow, such as NIST CSF 2.0, the CRI Profile, ISO/IEC 27001, NYDFS Part 500, and PCI DSS. It shows their coverage, the open security incidents with the notices still due, the open findings tagged to those frameworks, and the controls crosswalked to them with each control’s test status.

  • 01Security and continuity frameworks that are enrolled and in scope are shown with their coverage.
  • 02Open security incidents are listed with the notices still due, for members who hold the security read permission.
  • 03Open findings tagged to those frameworks are listed in one panel.
  • 04Mapped controls are sorted with overdue tests first, then tests due soon.
02 · Cybersecurity

The annual report to the board

The Interagency Guidelines ask for a report to the board on the information security program at least annually. The landing generates that report and shows when it is next due and when it was last recorded, from the obligation on the Obligations calendar.

  • 01The due date and the date last reported come from the Obligations calendar.
  • 02The guidelines fix the frequency, so you set the due date to your board cycle.
03 · Cybersecurity

Continuity plans that go in force through approval

Continuity (BCM) is the oversight register for your business continuity program. Each plan has an owner, a type, an exercise cadence, and the recovery time and recovery point it commits to. A plan runs from draft to awaiting approval, in force, and retired, and it goes in force only through a maker-checker approval, never on one person’s say-so.

  • 01Plan types are enterprise BCP, IT disaster recovery, pandemic, department, and other.
  • 02The approval shows the plan’s commitments and any conflict with its business impact analyses.
  • 03Continuity (BCM) is a second-line tracking surface. Zovos does not run a failover.
04 · Cybersecurity

Business impact analyses and recovery-objective conflicts

A business impact analysis records what a process requires: its recovery time objective, its recovery point objective, and its maximum tolerable downtime. Because the requirement and the plan’s commitment are recorded separately, Zovos compares them and lists every recovery-objective conflict, where a plan commits to less than its process needs.

  • 01Each business impact analysis names its process, its criticality, and the plan that recovers it where one exists.
  • 02A conflict between a plan and its business impact analysis is listed, not buried in a document.
05 · Cybersecurity

Exercises, coverage, and findings

The exercise log records each test with its plan, its type, its date, a summary, and a result of pass, partial, or fail. A recorded exercise moves the plan’s cadence clock forward, and the coverage tab grades every process from covered to test overdue, never tested, plan not in force, or no plan. A failed or partial exercise can be promoted to a finding.

  • 01Exercise types are tabletop, walkthrough, functional, and full interruption.
  • 02A failed exercise opens a High finding and a partial one a Medium finding, and the person promoting it can change that.
  • 03A back-dated exercise cannot move a plan’s clock backward.
06 · Cybersecurity

Notification linkage, with no alerts sent

Zovos sends no emergency alerts and holds no contact roster. Your mass-notification platform does that. Zovos emits a signed event when a plan goes in force and when an exercise is recorded, so that platform stays in step with the plan register.

  • 01Two continuity events are sent to the endpoints you configure.
  • 02The Notification linkage tab shows the endpoints and the last delivery.
07 · Cybersecurity

Security evidence from the rest of Zovos

The landing draws on records that live elsewhere in the product. Controls sit in the Control catalogue, and automated control tests run on the security evidence connectors. Vendor SOC report reviews sit in Third parties, where complementary user entity controls are crosswalked to your own controls. The security frameworks are in the shared corpus.

  • 01Tenable and Qualys test vulnerability remediation against your SLA and scan freshness.
  • 02CrowdStrike tests sensor coverage and prevention policy, and Jamf tests disk encryption, screen lock, and operating-system currency.
  • 03Identity, Microsoft 365, and AWS connections run further checks, such as MFA enforcement, device compliance, cloud configuration, and backups.
  • 04The Cyber Hub starter control baseline maps cybersecurity objectives to the FFIEC Information Security booklet, NIST CSF 2.0, the CRI Profile, GLBA, NCUA Part 748, and ISO/IEC 27001.
  • 05The corpus includes NIST CSF 2.0, the CRI Profile v2.2, NIST 800-53 Rev. 5, CIS Controls v8.1, ISO/IEC 27001:2022, SOC 2, and PCI DSS v4.0.1.
Proof points

Grounded in shipped behaviour.

  • A continuity plan goes in force only through a maker-checker approval.
  • Four security evidence connectors (Tenable, Qualys, CrowdStrike, and Jamf) back seven automated control checks.
  • The corpus behind the landing holds 54 frameworks, including FFIEC IT, GLBA, NCUA Chapter VII, and the FFIEC business continuity booklet.

Counts come from the platform's regulatory corpus, connector registry, and seed template library at release. See the documentation for the current values.

FAQ

Questions, answered first.

What is in the Cybersecurity group?
Three screens. The Cybersecurity landing rolls up the security and continuity frameworks, findings, and controls. Security incidents records each incident with its notification deadlines, and Continuity (BCM) tracks continuity plans, business impact analyses, and exercises.
Does Zovos run our disaster recovery or send emergency alerts?
No. Continuity (BCM) is an oversight register. Zovos does not run a failover, sends no alerts, and holds no contact roster. It emits a signed event to your mass-notification platform when a plan goes in force and when an exercise is recorded.
How does Zovos catch a plan that cannot meet its recovery objectives?
Each business impact analysis records the recovery time and recovery point a process requires, and each plan records what it commits to. Zovos compares the two and lists every recovery-objective conflict.
Where do vulnerability and endpoint results come from?
From the Tenable, Qualys, CrowdStrike, and Jamf connectors. Each one runs automated control tests against the controls in your Control catalogue, and the landing shows those controls with their test status.

See cybersecurity on your library.

Bring your controls, a policy, and one regulator paragraph that gives you trouble. We target two-week onboarding.