Financial Institutions IT Security & Compliance

PYA’s focus on technology is designed to help optimize the integration of business functions and technology.  As technology advances, we help clients find ways to successfully and securely deploy technology that maximizes the value of the investment without compromising privacy, security, and industry compliance requirements.

With decades of industry knowledge and executive-level IT experience, our team helps providers develop or assess their systems and technology strategies by identifying, assessing, and mitigating risks. PYA excels in Business Intelligence, offering customized Data Analytics solutions and state-of-the-art Dashboard and Visualization tools designed to help our clients with timely data-driven decisions.

Our Financial Institutions Information Technology Services

IT Auditing

  • Federal Financial Institutions Examination Council (FFIEC)
  • National Institute of Standards and Technology (NIST)
  • Control Objectives for Information and Related Technologies (COBIT)
  • System and Organization Controls (SOC) Examinations

Business Intelligence

IT Advisory Services

  • Comprehensive IT Assessments 
  • Cybersecurity Assessments 
  • IT Outsourcing Assessments 
  • Pre & Post Mergers & Acquisition IT Assessments 

IT Risk Management & Compliance

  • Risk Management Program Development and IT Compliance Assessments 
  • Cyber Intelligence 

Why Choose PYA?

Visual Map of Bank IT Controls Across FFIEC, NIST, and COBIT

Integrated IT Auditing and Compliance Know-How

PYA aligns IT auditing with FFIEC, NIST, COBIT, and SOC examination needs, helping institutions document controls in a way examiners can follow while reducing remediation cycles.

Practical Analytics and Advisory Support

From customized data analytics and dashboards to comprehensive IT and cybersecurity assessments, PYA pairs hands-on advisory work with decision-ready reporting for leadership and boards.

Relationship-Focused, Independent, and Responsive

PYA’s private ownership reinforces independence, our long-term client relationships guide how we work, and our teams are known for timely responses when institutions need support most.

Financial Institutions IT Security & Compliance Frequently Asked Questions

How should a financial institution determine the scope of an information technology audit or cybersecurity assessment?

The scope should reflect the institution’s products, systems, data, delivery channels, vendors, recent changes, threat environment, prior findings, and regulatory obligations. Critical and internet-facing systems generally require particular attention. Applicable FFIEC, NIST, COBIT, and SOC requirements can help organize the review, but they should not be treated as interchangeable checklists.

How is an information technology audit different from a cybersecurity assessment?

An information technology audit tests defined controls and requirements across an established scope and reports whether those controls are designed or operating as expected. A cybersecurity assessment focuses more directly on threats, vulnerabilities, resilience, and the institution’s ability to prevent, detect, respond to, and recover from an attack. The work may overlap, but one does not automatically replace the other.

What should a financial institution review when outsourcing technology or using a cloud service?

Review the provider’s financial condition, security and control reports, data handling, access controls, incident notification, availability, recovery capabilities, subcontractors, regulatory support, and service history. Contracts should address responsibilities, audit rights, data ownership, retention, termination, and transition assistance. Risk monitoring should continue after onboarding rather than ending when the contract is signed.

What information should a board receive about information technology and cybersecurity risk?

Board reporting should summarize material risks, significant incidents, critical control gaps, remediation status, third-party risk, system resilience, regulatory matters, and trends over time. Measures should use stable definitions and distinguish operational detail from issues requiring governance decisions or risk acceptance. Management should explain the business impact, accountable owner, planned response, and any unresolved exposure.

What should information technology due diligence cover before or after a financial institution merger?

Review applications, infrastructure, data, cybersecurity, identity and access management, vendors, contracts, staffing, business continuity, control gaps, and integration costs. The assessment should identify Day 1 requirements, systems that must remain separate temporarily, data conversion risks, and remediation priorities. Post-close plans should assign ownership and sequence changes according to risk and operational readiness.

 

The PYA Difference

Over our 40-year history, PYA has consistently delivered high-value advisory services to our national client base. Our team is deployed to develop custom plans using proven approaches and work plans.

Independence

Private ownership means we answer only to our clients, not to third-party investors, giving us the freedom to be thorough and thoughtful in our work. We judge our success by our clients’ success.

Relationships

We value long-term relationships and work hard to maintain them. Our commitment to client relationships and the communities we serve remains constant.

Responsiveness

PYA has a reputation among clients for responsiveness. PYA's goal is to respond to calls and emails within 24 hours when possible.

PYA-IT-Cybersecurity-Advisors-Data-Security-Risk-Assessments-2

Contact Our Financial Institutions IT Security & Compliance Team

Team Leader

Mike Shamblin Headshot Mike Shamblin

Managing Principal of Accounting & Advisory and Firm Chief Risk Officer

Subject Matter Experts

John Cross Headshot John Cross

Principal

Jason Hardin Headshot Jason Hardin

Principal and Director of Business Intelligence & Analytics

Stephen Lennon Headshot Stephen Lennon

Chief Information Officer

Erika Walker Headshot Erika Walker

Senior Manager

Andrew Sizemore Headshot Andrew Sizemore

Senior Manager

PYA
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.