BID® Daily Newsletter
Sep 17, 2026
BID® Daily Newsletter
Sep 17, 2026

Article Lead Image

National Preparedness Month Part 1 - Be Prepared, CFIs

Summary: A rising number of natural disasters, coupled with ever-increasing technology risks and heightened regulatory oversight surrounding disaster recovery, have escalated the importance of board-level disaster preparedness planning. With September being National Preparedness Month, now is the perfect time for CFIs to revisit their disaster recovery plans.

Key Insights

  • Every $1 invested in disaster resilience saves $13 through job protection, reduced damage, and sustained output.
  • Noncompliance with disaster recovery regulations can cost community financial institutions up to $1MM per day in penalties.
  • Effective plans should address physical closures, digital disruptions, and third-party vendor vulnerabilities together.
In 1907, after coming across a group of boys reading a military scouting manual he had written, British Army general Robert Baden-Powell was inspired to create a non-military survival skills guide for boys called Scouting for Boys that became the origin of the Boy Scouts. According to Scouting legend, in 1910 the Boy Scout movement was brought to America by Chicago publisher William D. Boyce after he got lost in the fog on a visit to London and was assisted by a British Scout who would not take a tip for his assistance.  
Boy Scouts of America (now Scouting America), was established to train young men to become responsible citizens and community leaders by training them in survival skills, all of which centered around the motto “be prepared.” With September marking National Preparedness Month, now is the perfect time for community financial institutions (CFIs) to take a page from the Boy Scouts by ensuring that they have adequate disaster readiness plans in place.

Rising Stakes of Disaster Recovery Plans

At a time when the number of natural disasters that occur each year has been increasing, coupled with heightened regulatory oversight regarding disaster recovery and an ever-increasing number of technology and operational risks, it is more important than ever for the boards of CFIs to ensure that their disaster preparedness plans are effective and up to date. Disaster recovery plans cannot be static and need to take a comprehensive approach to reducing risks.
While many organizations previously treated disaster recovery plans as an administrative cost, the benefits of proactive planning are tangible. According to The Preparedness Payoff: The Economic Benefits of Investing in Climate Resilience, a US Chamber of Commerce and Allstate study, a $1 investment in disaster resilience returns $13 in savings by protecting jobs, limiting physical damage, and sustaining economic output. And with CFIs serving as the main revenue source that both individual customers and small- to medium-sized businesses (SMBs) rely on following disasters, ensuring their ability to remain operational themselves is imperative, particularly in the wake of heightened regulatory oversight. 

Risk-Based Oversight

The regulatory landscape has been shifting towards a more tailored risk-based approach. The Office of the Comptroller of the Currency (OCC) has been actively seeking to streamline the operational, cybersecurity and model risk oversight for banks with $30B or less in assets by eliminating non-statutory exam requirements that don’t make sense for smaller institutions. Nonetheless, financial institutions still face the risk of hefty fees and penalties for noncompliance with mandatory disaster recovery and business continuity plans, which means the need to take a wide-ranging approach that encompasses everything from physical to cyber risks. Under the Federal Deposit Insurance Act, penalties for noncompliance with disaster recovery plans can be as high as $1MM per day.
For board members and executive leadership, it could be worth asking whether your organization's disaster preparedness plan takes a collective approach to both physical and digital risks — including potential fallout from disruptions that impact third-party providers.
Three of the biggest areas your CFI disaster plans should consider focusing on are:
  • Branch closures. The possibility of physical branch closures are mostly due to events such as major storms, flooding, or power grid outages. The number of billion-dollar natural disasters rose to an average 22.4 per year between 2020 and 2024, up from 3.2 per year between 1980 and 1984, according to the National Oceanic and Atmospheric Administration (NOAA). Given this reality, emergency protocols should outline thresholds and triggers for remote work, mobile branch deployment, and offline cash operations.
  • Digital continuity disruptions. In a world where digital banking has become commonplace, customers rely on seamless access to mobile banking and ATM access. Disaster preparedness measures need to incorporate back up plans for the possibility that either their core processors or services from third-party technology providers could go down.
  • Cyber threats. With 81% of financial institutions having experienced at least one unauthorized network access incident in the past year, according to Wipfli’s 2026 State of Banking and Credit Union Report, disaster preparedness plans need to take a collective approach to digital and physical risks.

Checking All the Boxes

Organizations should consider having a board-level checklist that covers governance oversight, scenario exercises, communication plans, vendor continuity coordination, and dashboard metrics linked to regulatory expectations. Comprehensive plans should check the following boxes:
  • Governance oversight. Organizations need to clearly define which executives are authorized to activate emergency procedures and how the enactment of emergency protocols will be communicated, both to key individuals and employees at large. 
  • Scenario exercises. Beyond outlining recovery strategies, organizations should routinely engage in worst case scenario exercises to ensure that their plans are adequate. This can be done using simulations incorporating physical risks, such as hurricanes, and the impact they can have on digital networks, such as a core network outage.
  • Third party vendor precautions. Emergency preparedness plans should extend beyond an organization’s own operations to third-party relationships that can also impact services. According to the Federal Financial Institutions Examinations Council (FFIEC), management needs to be aware of the disaster preparedness plans of critical third-party providers and should include such organizations in any testing or exercises, all of which should be outlined in contracts with outside providers.  
  • Communications. Emergency preparedness plans should include pre-written messaging, both internal and external. Having prepared language for customers and the media is important as this can help ensure clear messaging and reduce people’s concerns.
  • Measurable Metrics. The FFIEC suggests that management should routinely provide boards with detailed, measurable metrics outlining testing outcomes that demonstrate how business continuity plans meet risk and regulatory requirements.
With September being National Preparedness Month, now is the perfect time for CFIs to focus on disaster preparedness at the board level. Doing so not only helps ensure that organizations can maintain operations when disaster strikes, but that they can be certain they remain compliant with ever-changing regulatory requirements. Disaster preparedness is also important to an organization’s reputation. A well-thought-out plan that allows CFIs to continue operating under worst case conditions is important for customers’ confidence in their financial institution. 
In Part Two of this National Preparedness Month series, we'll explore how financial institutions can also play a meaningful role in guiding SMB clients toward stronger preparedness practices, creating benefits that extend well beyond any single storm season.
Subscribe to the BID Daily Newsletter to have it delivered by email daily.

Related Articles:
FinCEN's 314(b) Update: A New Tool Against Payments Fraud
In June, FinCEN updated guidance that financial institutions can now share incidents of suspected fraud with each other under the Patriot Act’s safe harbor provision. Such real-time sharing can be particularly beneficial in stymieing instant payment fraud. We detail action items for community financial institutions to consider.
To "DExit" or Not to "DExit" - That Is the Question for CFIs
A growing list of companies are redomiciling from Delaware to another state, dubbed “DExit,” to take advantage of perceived more advantageous business climates.