We publish these executive interviews so that you can hear from leaders who have shaped—and are continuing to shape—the future of banking cybersecurity.
Mary Beth Quist has been a fixture in the world of banking regulation for almost three decades. After starting her career at the Federal Reserve Bank of Richmond as a bank examiner, she joined the Conference of State Bank Supervisors (CSBS), where she has worked for the last twenty-five years.
As Senior Vice President, Bank Supervision, Mary Beth leads the team responsible for coordinating supervisory processes, including cybersecurity, with the 54 state and territorial bank regulators across the United States.
Mary Beth has “grown up professionally at CSBS,” where her daily agenda can include anything from assisting with a crisis impacting the financial sector, to a consultation with a state regulator or coordinating with the federal agencies.
We couldn’t be more honored to add Mary Beth’s perspective to this interview series, which includes:
- Jeff Plagge, former Iowa Superintendent of Banking and longtime community bank CEO.
- Dave Piscitello, “Security Skeptic” and partner at Interisle Consulting Group.
- Cybersecurity pioneer and entrepreneur Paul Walsh.
- Engineer and educator Bill Newhouse.
- Author and speaker Thomas P. Vartanian.
- Erick Cook from Cook Technology Solutions LLC.
- J. Trent Adams from Proofpoint.
- Lorri Janssen Anessi from BlueVoyant.
In addition, stay tuned for our upcoming .Bank podcast series.
Serving the Nation’s Regulators for Three Decades
Q: How did you end up in banking regulation?
During my senior year in college, I had interviews lined up with big accounting firms, and thought that’s where I would end up.
But after an interview with the Federal Reserve, hearing what bank examiners do and the breadth and continual learning the role offered, I walked away knowing that was exactly what I wanted to do.
I started my career with the Federal Reserve Bank of Richmond, the Fifth Federal Reserve District, which covers Virginia, Maryland, the Carolinas, and Washington, D.C. I traveled to small towns across the region, sitting inside community banks, reviewing their books, records, and operations. It was a fascinating way to start a career, seeing a region’s banking system up close and understanding the important role supervision plays in keeping institutions and communities strong.
Q: What prompted you to move from the Federal Reserve to CSBS?
While I was still at the Richmond Fed, I was selected for a two-year interagency assignment at the Federal Reserve’s Board of Governors in Washington, DC. The team developed an examination tool designed to be used across state and federal regulatory agencies.
That’s where I worked with people from the Conference of State Bank Supervisors for the first time. This gave me a much clearer understanding of CSBS’s role and the vital place state regulators fit into the broader regulatory system.
After a conversation with CSBS’s then-CEO, Neil Milner, I was sold on joining CSBS. I saw an opportunity to support the state regulatory system on a national scale—and here I am 25 years later.
Q: How has your role changed over those 25 years?
In many respects, I have grown up professionally at CSBS.
I began as a junior member of the bank supervision team, coordinating with federal agencies and helping develop examination tools. Although my career has remained focused on bank supervision, the scope and strategic significance of my responsibilities have expanded considerably.
Today, I lead the bank supervision team, supporting state regulators, strengthening the state supervisory system, and advancing coordination with our federal counterparts. The mission remains consistent; what has changed is the level of leadership, accountability, and influence I bring to that work.
Q: What does a typical week look like for you?
There’s no such thing as a typical week or day at CSBS. Most of my time goes to connecting with state regulators, coordinating with federal agencies, and working with our internal teams to advance CSBS priorities and support our members.
But my day can change with a single phone call. Anything that threatens an institution’s ability to operate goes to the top of the list. It could be a ransomware incident, a problem with a third-party service provider, or a hurricane hitting a region’s banks.
What CSBS Actually Does
Q: What do you think people get wrong about CSBS?
I think CSBS is often misunderstood. Our members are the 54 state bank regulators across the country, and their responsibilities extend well beyond supervising banks.
At a minimum, they charter and regulate banks in their state, but many of them also oversee a whole range of non-depository entities: mortgage servicers, mortgage brokers, money services businesses, credit unions, pawn shops, and more. Their reach is much wider than most people realize.
Within CSBS itself, we have a training department that runs everything from classroom-style examiner training to programming for commissioners and executive staff. We have a policy team that tracks federal policy and its potential impact on state laws and regulations. We have a supervision area, where I lead the bank supervision side, and there’s a parallel non-bank supervision team. And we have a legislative group that follows both state and federal legislation on our members’ behalf.
Q: If a bank gets hit with something like ransomware, does CSBS get involved directly?
No. The institution itself reports and communicates directly to its state and/or primary federal regulator.
However, where we do play a role is at the coordination level, through the FFIEC Cybersecurity and Critical Infrastructure Subcommittee (CCIS) and the Financial and Banking Information Infrastructure Committee, or FBIIC.
FBIIC brings together 18 members from state and federal financial regulatory organizations, chaired by the Treasury’s assistant secretary, and focuses on operational and tactical issues tied to critical infrastructure, including cyber and physical events.
The Dual Banking System Is Doing Its Job
Q: Does having a diversified, dual banking system offer real advantages over a more centralized one?
The United States is unique in its banking ecosystem, just by the sheer number and diversity of institutions we have.
Our unique dual banking system is important to how our financial system works, and it’s something CSBS has always strongly supported.
The dual banking system allows banks in the United States to be chartered by either the federal government or individual states, creating a parallel system of banking regulations and oversight. This system is unique, as it allows for both federal and state-level regulation and supervision of banks, ensuring a balance between national and local interests. A banking institution cannot perform most formal activities, such as accepting federally insured deposits, unless it’s chartered by a state or federal regulator.
The number of banks has declined significantly throughout my career. When I started in 1994, we were closer to 10,000 banks; today we’re at about 4,254—of which about 3,470 banks are state-chartered. That’s the impact of mergers, acquisitions, and failures playing out year after year.
It’s probably the single biggest structural shift I’ve watched happen in my career.
Cybersecurity in a World Powered by AI
Q: What’s happening in cybersecurity right now that you think more people should be tracking?
There’s a lot going on today in the cyber space to keep us on our toes. We continue to see ransomware and phishing as prominent threats to our institutions, and we’re also watching emerging threats to critical infrastructure from nation-state actors.
That said, the emergence of artificial intelligence is probably the most immediately impactful event happening in cybersecurity right now.
It’s certainly something that presents a world of potential promise for financial institutions looking to increase productivity in internal processes, combat fraud, and create more meaningful and beneficial interactions for customers. But, for all the potential benefits we might see in using AI in our institutions, AI does introduce a brand-new risk environment to institutions as well.
Q: How is CSBS approaching AI education: for regulators or for banks directly?
Both.
Our primary audience is state bank regulators, and we often partner through the FFIEC or directly with federal banking agencies to reach both state and federal regulators together.
On AI we have a campaign underway, and we’re actively looking to do more direct industry outreach: webinars, and partnerships with others. AI is an area where we believe direct contact with bankers matters.
We recognize that there is a lot of excitement surrounding AI, but also a lot of questions that need to be answered. We’re working to have those conversations and provide materials that can get some of those questions addressed.
The Fraud Accountability Dilemma
Q: How should the responsibility for cybersecurity risk be split between banks and consumers?
I’d say both consumers and institutions are accountable—there are certainly shades of accountability and responsibility on both sides.
Consumer education is significant and genuinely challenging.
I believe consumer awareness, more public awareness education, and training on cyber hygiene are essential. Financial institutions have the benefit of more structured awareness and training on cybersecurity and cyber hygiene matters, and I think that’s absolutely essential to help create the safest and most secure environment to protect customer data and maintain public confidence in the institution. Training within institutions has to run from the teller line all the way up to the executive suite.
Some institutions offer cyber education programs for their customers. I think those types of programs can be very beneficial for consumers when they’re done consistently, updated to address emerging consumer threats, and really incorporated into the customer’s overall experience they have with the institution.
And, of course, education and awareness programs are equally important for institutions to develop and incorporate for their own staff. It’s one way institutions and consumers can be on the same page with respect to fostering good cybersecurity awareness and hygiene.
Today, this awareness and education has to include the risks AI introduces.
Q: Should banks be investing in identity-centric security to prove to a customer they’re dealing with the right bank?
Yes, this is very important.
It ties back to training and awareness that addresses everything going on in cyberspace right now, including some genuinely unbelievable deepfake attempts. Being able to give your customers assurance that they’re dealing with the actual bank, and not a lookalike, is huge. It’s peace of mind.
But it’s only getting more challenging with the advancement of AI. The tools threat actors have at their disposal today are creating far more believable, targeted, and dangerous phishing, vishing, and deepfake campaigns than ever before for everyone. And there is a need, now more than ever, for tools to provide assurances to end users that they are engaging with who they’re supposed to be engaging with.
The controls required as part of the .Bank domain registration process and mandatory security requirements help assure customers that they are indeed engaging with trusted institutions and not with criminals posing as legitimate institutions.
Don’t Forget the Fundamentals
Q: CSBS partnered with SecurityScorecard. How does that help regulators?
CSBS’s partnership with SecurityScorecard gives our state regulatory members the ability to access and implement cybersecurity ratings technology themselves.
In practice, a regulator can enroll their institutions in the program and receive a report card rating on each institution’s cybersecurity posture.
It’s another tool in the toolbox for regulators. We also use it internally at CSBS to rate our own vendors, and banks are using the same platform to support their own vendor and third-party risk management efforts.
Q: Do you think community banks understand how vulnerable they actually are?
I think we’re well past the “if it’s going to happen” stage; most banks are thinking in terms of “when”…or at least they should be.
Community banks are actively putting defenses in place, and anything regulators can do to help with that matters.
Last year, CSBS published a Cyber Fundamentals guide. It came out of something we were seeing consistently across examinations nationwide: the attacks that were actually succeeding were exploiting basic, foundational gaps—not novel vulnerabilities.
The guide lays out 10 core controls institutions can use to evaluate their own practices, plus a set of questions boards should be asking. The idea is for institutions to abandon some of the muscle memory associated with some of these common practices and re-focus on implementing these controls and practices to the most beneficial degree possible. Although these are things that all institutions do regularly, we wanted to encourage a bit of introspection to bring these controls front and center.
Q: Some people in this industry see regulators as an adversary. Does that match your experience?
That has not been my experience. Most state bank regulators do not approach supervision as an adversarial exercise or with the intent to “bring the hammer down.”
I see it more of a mutual relationship. Banks and their regulators generally work well together—that doesn’t mean they always agree.
Examiners bring more than oversight: they also provide perspective, guidance, and insight into sound practices. At their best, they help institutions understand their risk profile, identify opportunities to strengthen operations, and respond effectively to emerging challenges. The relationship is far more collaborative than it is often perceived to be.
That partnership is especially important in today’s complex cyber environment. The more closely regulators and banks work together, the better positioned we are to achieve our shared objective: a safe, sound, and resilient financial system.
Banks Can Do a Lot to Fight Against Cybercrime
Our state and national banks are facing serious threats from many angles. Here’s what they can do to maintain a secure environment for their customers and shareholders.
Start With the Fundamentals
Real-world attacks continue to exploit basic gaps more often than exotic ones. CSBS’s Cyber Hygiene Fundamentals guide includes 10 core controls, plus board-level questions to ask senior management.
Assess Vendors With Verified Rating Tools
Cybersecurity ratings platforms, like SecurityScorecard, give banks and regulators alike a quick, report-card view of a bank’s, or a vendor’s, cyber posture.
Train Everyone, Continuously
Cyber hygiene training has to run from the teller line to the executive suite, and it needs to include how AI is affecting attack and defense.
Understand Regulators Are Your Partner
Examiners are consultants and advisors as much as evaluators. Leaning into that relationship tends to produce a stronger security posture.
Switch to a .Bank Domain
To combat rising deepfakes and spoofing, banks must prioritize identity-centric security. Adopting a .Bank domain provides mandatory, verified controls that give your customers immediate, visible trust.
To learn more about .Bank and stay ahead of the cybersecurity curve, we invite you to sign up for our monthly newsletter to receive exclusive banking and cybersecurity insights.