SDBA eNews

October 8, 2026

News

SDBA Updates

SDBA Events

Online Education


sdba news

ABA Banking Journal: Fed to split bank supervision into five regions

October 6, 2026 

BowmanThe Federal Reserve will divide its bank supervision into five geographic regions rather than splitting it among the 12 Reserve Bank districts, which should enhance transparency and accountability, Fed Vice Chair for Supervision Michelle Bowman said today.

During a speech at the Community Banking Research Conference in St. Louis, Bowman announced plans to split supervision into five regions that follow state borders rather than the Fed districts. As for the reason, she cited a recent independent review of the Fed’s handling of the 2023 Silicon Valley Bank failure that concluded supervisors did not fully appreciate the extent of the vulnerabilities as the bank grew in size and complexity.

“The execution of Federal Reserve supervision is the responsibility of the vice chair for supervision, but it is conducted by the Reserve Banks,” Bowman said. “As the review noted, for decades that structure has disincentivized a critical link between responsibility and accountability and has been further complicated by a complex web of dozens of committees, resulting in dysfunction when critical decisions are most needed.”

Each new area will be led by a regional leader accountable for all supervisory activity, supported by the existing Reserve Bank footprints but aligned to state boundaries, Bowman said. She didn’t say which states the different regions would encompass, but that they would be informed by the regional structure of the Conference of State Bank Supervisors, which is split into five districts.

“By following state lines rather than Reserve Bank District boundaries, we can coordinate more effectively and efficiently with our state and federal regulatory partners,” Bowman said. “The regional structure creates scale in our operations. It simplifies our leadership structure while preserving local supervision by examiners. They will remain in the existing Reserve Bank locations across each region, continuing to oversee the banks they currently supervise. This approach clarifies accountability and decision-making and enables a consistent application of supervision.”

Re-examining community bank criteria

Bowman also used her speech to highlight several regulatory reforms pursued by the Fed in the past year and a half, most aimed at helping community banks. They include efforts to update and index outdated asset thresholds, to ease regulatory burdens hampering bank mergers and de novo bank formation, and to refocus bank supervision on risks that lead to material financial harm. In addition, she previewed possible changes to come.

“Later this year, the [Fed board] will consider broader structural reforms to bank portfolios defined by asset size and updates to the large bank tailoring framework,” Bowman said. “For the past 15 years, a community bank has been defined as a bank with assets of less than $10 billion. Fixed asset thresholds can push a smaller noncomplex bank into a higher supervisory tier with standards designed for more complex institutions and stronger supervisory scrutiny — like those based on the risk of their activities.”

“By expanding the range of institutions treated as community banks that operate using a traditional community bank business model and relationship banking and appropriately modifying the supervisory expectations and regulatory requirements for these firms, we will preserve safety and soundness while effectively applying appropriately tailored and risk-calibrated supervision and regulation,” she added.

ABA response

In a statement, American Bankers Association President and CEO Rob Nichols said ABA appreciates Bowman’s commitment to risk-focused regulation and supervision, and to continuing to modernize the bank regulatory framework.

“The changes to date, including the renewed emphasis on material risk, the updated community bank leverage ratio and the effort to update and index outdated asset thresholds will allow banks to focus on better serving their customers and communities,” Nichols said. “We look forward to learning more about how Vice Chair Bowman’s plan will strengthen overall supervision, as well as the practical effect it will have on our members.”

Original Article

Back to Top

ABA Banking Journal: GAO finds new trigger leads restrictions could have longer-term benefits

Survey finds young people most likely to fall for phone scamsNew federal restrictions to curb abusive trigger leads should reduce the volume of unwanted solicitations homebuyers receive, with research showing that the marketing practice does little to save consumers money, the Government Accountability Office said in a new report.

Congress last year passed the bipartisan Homebuyers Privacy Protection Act, which prohibits credit reporting firms from selling mortgage applicant information to lenders who then barrage those same consumers with unwanted solicitations. The American Bankers Association supported the bill.

The new law requires the GAO to assess the value of trigger leads for homebuyers. GAO researchers noted that while industry stakeholders said trigger leads encourage homebuyers to comparison shop for loans, and therefore potentially save money, at least one study concluded that only 3.5% of homebuyers obtained a loan through competing offers based on trigger leads. And that small benefit had to be weighed against several negatives associated with the practice, such as exposing homebuyer information to actors who may engage in fraudulent activities.

Still, the GAO noted that the law only went into effect in March of this year, which is not enough time to determine its effectiveness. “If effectively implemented, these restrictions could limit access to trigger leads and reduce the volume of solicitations homebuyers receive while preserving opportunities to comparison shop,” the agency said.

Original Article

Back to Top

ABA Banking Journal: Meeting Ag Lending Goals Without Going It Alone

October 1, 2026 | AGRI-ACCESS

Meeting Ag Lending Goals Without Going It AloneAgricultural lending has long been built on relationships. Financial institutions know their customers, understand their local markets and play an important role in supporting the farms and agricultural businesses that keep rural communities moving forward. But even a strong borrower relationship does not mean every agricultural loan fits neatly within an institution’s portfolio.

Loan size, concentration limits, lending capacity and risk management considerations can all affect an institution’s ability to finance an opportunity on its own. For lenders looking to continue serving ag customers while managing their portfolio, loan participation can provide another option.

Create capacity without giving up the relationship

When a strong ag opportunity exceeds an institution’s lending capacity or creates portfolio concentration concerns, the answer does not necessarily have to be turning the borrower away. Participation lending allows financial institutions to share portions of a loan with another lender. That can help an institution manage exposure while continuing to serve its customer.

For the originating lender, that distinction matters. The institution can preserve the customer relationship and remain involved in the financing rather than sending a borrower elsewhere because a particular request falls outside its lending limits or portfolio needs. Participation can also create greater flexibility when evaluating future opportunities.

Look beyond individual loan size

Agricultural lending needs can vary significantly from one operation to another. Land purchases, facility investments, equipment, and other capital needs can quickly result in financing requests that challenge an institution’s lending limits or portfolio strategy.

Capacity is an important consideration, but it should not be the only one. Lenders should also consider how an opportunity affects overall portfolio concentration, the institution’s desired level of ag exposure and its ability to continue supporting a borrower as that operation’s needs change.

Participation lending can become part of that broader strategy rather than simply a solution for an unusually large loan.

By creating additional capacity within the portfolio, institutions may be better positioned to evaluate opportunities based on the borrower and the credit rather than capacity alone.

Protect what makes community banking valuable

For many agricultural borrowers, their lender brings more to the table than financing. A local financial institution may understand the operation’s history, business strategy and community in ways that cannot easily be replicated. Those relationships become particularly valuable when producers are making major investments or navigating changing agricultural conditions. A participation strategy can help preserve that value. Instead of replacing the originating lender, the right participation relationship should complement the institution’s existing expertise and customer relationships. That means lenders should look for a participation partner that understands agricultural credit, offers solutions that fit their institution’s needs and allows them to maintain an appropriate role in the relationship.

Make participation part of the strategy

Participation lending is most useful when it is considered before capacity becomes a constraint.

Financial institutions can begin by evaluating where participation could fit within their overall ag lending strategy. Consider questions such as:

  • Where are concentration or lending limits affecting our ability to serve qualified ag borrowers?
  • Are there ag opportunities we would pursue if we had additional lending capacity?
  • Which customer relationships could require greater financing flexibility in the future?
  • What capabilities would we expect from a participation lending partner?

Having those conversations early can give lenders more options when the next opportunity arrives.

For institutions that want to remain active in ag lending, participation can provide another way to balance lending opportunities, portfolio needs and customer relationships.

Agri-Access works with financial institutions to provide agricultural loan participation solutions that help lenders manage risk, create capacity and meet their ag lending goals while maintaining their customer relationships.

Explore Agri-Access participation lending solutions.


CISA News: Scan for Good: Using AI to discover and fix high-priority exposures across public services and critical infrastructure

New initiative partners with under-resourced organizations to uncover, remediate exploitable risk at scale.

September 24, 2026 | Ami Luttwak, Gal Nagli

"At a time of evolving threats, defensive vulnerability discovery helps strengthen the nation’s digital infrastructure. Under President Trump’s Executive Order 14409, CISA promotes the lawful and responsible adoption of AI to accelerate vulnerability discovery and strengthen cybersecurity resilience across government, industry, and the essential organizations that support our communities. Together, we can build a resilient ecosystem in which those who protect our society have access to advanced technology and leading cybersecurity expertise." Nick Andersen, Acting Director, CISA

AI is changing exploitability

As AI makes rapid advances, much attention has been given to models discovering new zero-day vulnerabilities, which they do largely by reasoning over and analyzing code. Through our work building the Wiz Red Agent – an AI-powered, context-aware pentester – we saw another gap, with more immediate implications: the security of applications exposed and reachable on the public internet. That is where we chose to focus this project. 

In real-world environments, critical risk often does not come from a single vulnerability in code. It can emerge from the combination of configurations, permissions, identities, APIs, and application behaviors that may appear benign individually but create dangerous attack paths when connected. Historically, finding and understanding these paths at scale required significant time, expertise, and manual investigation. AI is changing that, making it dramatically easier to discover exposed systems, understand how they behave, and connect weaknesses into real attack paths.

We have already seen this shift firsthand. The Red Agent has identified thousands of high and critical exposures in production environments that could put organizations at immediate risk. As these capabilities become more accessible and widespread, security teams will need new tools, expertise, and continuous research to keep pace … resources that not every organization has. Scan for Good brings these capabilities to organizations where successful exploitation could have an outsized impact, including critical infrastructure, public services, healthcare, and nonprofits. Where authorized, we will use the Wiz Red Agent and additional internal AI research capabilities to examine publicly facing websites, APIs, and applications (see below for more details on testing scope and disclosure). This work will help organizations find and fix critical exposures before attackers do, allowing them to stay ahead of adversaries as AI capabilities advance. 

"AI models like Gemini Cyber offer us the opportunity to advantage defenders over attackers. This is especially needed for organizations that serve vital functions in society, but many do not have the resources they need to protect against attacks. Scan for Good rises to this challenge by leveraging AI to uncover risks and protect critical infrastructure, non profits, and other public-interest organizations. In the coming months we will work to scale that impact globally." - Raluca Ada Popa, Head of Gemini Security @ Google DeepMind

What we've learned so far

Below are some examples of ways in which Scan for Good is already helping public-interest organizations and major technology providers find serious internet-facing risks before attackers do. Every example was discovered autonomously by the AI systems powering the program, safely validated by Wiz Research only far enough to confirm real-world impact, and privately disclosed so the affected organization could remediate it.

Public-interest organizations

These examples illustrate early results regarding one of Scan for Good’s stated objectives: to help protect organizations whose security is critical to the communities they serve. 

In each of the cases below, we partnered with the affected organization on remediation efforts. 

  • National archive: An administrator key was exposed on a public web server, enabling read, write, and delete access to 8.8 million files in a nationally significant archive of an EMEA country. We helped remediate the exposure by assigning the correct set of permissions.

  • Public hospital: Missing access controls exposed staff contact information and gave anyone online control of a hospital-wide mobile alert channel. 

  • Private hospital: An unsafe upload on a public appointment-booking site gave control of a hospital server and exposed patient identifiers, clinical information, and consent signatures.

  • Municipality: A public data service exposed sensitive personal, health, and financial information for roughly 5,000 elderly residents. We confirmed the risk without collecting a bulk dataset.

  • Public rail operator: A leaked production database exposed active administrator sessions, enabling control of routes, schedules, service announcements, and administrator accounts. We helped the operator secure the system before public transportation could be disrupted.

Foundational digital infrastructure

In addition to under-resourced and public sector organizations, Scan for Good also focuses on essential tech platforms that provide the digital backbone of society. Below are several examples; as with the previous, we partnered with the affected company on remediation efforts following disclosure. 

  • Leading AI training-data platform: Missing access controls utilizing a NoSQL Injection created a path to leak and alter customers’ proprietary AI-training data and projects.

  • Website-building and commerce platform: A zero-day flaw in a shared payments service exposed customer names, card brands, expiration dates, and partial card numbers across multiple stores. We confirmed it was a platform-wide issue.

  • Enterprise data and AI platform: Vulnerable public CI/CD workflows exposed credentials for an internal issue tracker and production marketing database, putting internal tickets, proprietary data, and customer records at risk. We worked with the provider to secure the workflows, rotate the credentials, and remediate downstream exposure. Read the first part of the published case study.

  • Cloud infrastructure provider: A credential exposed in public website code could have been used to publish malicious software across over 500 production container images supporting a flagship AI service. We proved the reach without changing an image and worked with the organization on containment.

Across these cases, a small public signal – be it a forgotten route, a missing permission check, or an exposed credential – quickly and autonomously escalated access to sensitive data, infrastructure, or administrative control. Scan for Good uses that speed for defense: find the path early, prove only the impact needed, and help close before it becomes an incident, working in collaboration with the affected teams.

This work builds on earlier Wiz Research into Base44, DeepSeek, Moltbook and Snowflake. In these instances, simple public exposure led to significant impact. Scan for Good applies those lessons more broadly and, after remediation and coordinated disclosure, shares the patterns anonymously so defenders can adapt.

Acting before an attack: Commitment to proactive security 

Our goal is simple: find serious risks, help organizations fix them, and do so before those risks are exploited. We will prioritize infrastructure where a successful attack could cause meaningful harm, including public services, critical infrastructure, nonprofits, open-source projects, and under-resourced organizations.

We will only conduct testing where it is authorized, either where the organization has an authorized bug bounty program or established vulnerability disclosure policy, or with explicit authorization. Any organization concerned about an exposed service can apply for a Scan for Good assessment. Every potential finding will be reviewed and validated by a human researcher. AI can help us investigate and explore more systems and possibilities, but humans will remain responsible for confirming impact and making disclosure decisions.

When we identify a serious issue, we will contact the affected organization privately, provide clear technical information, and work with the team to support remediation where appropriate.

Scaling Scan for Good with Gemini 3.8 Flash Cyber

Scan for Good uses advanced cyber models for automated defense, with a goal of creating ecosystem-scale impact. In this sense, it shares some common DNA with Google DeepMind’s Fairwind Program (Fairwind was designed as a way to safely provide defenders early access to powerful frontier capabilities). 

Our partners at Google DeepMind were critical to both initiatives: the AI-powered tooling behind Scan for Good is powered by the Gemini family of models, especially the new Gemini 3.8 Flash Cyber. Through our collaboration with the Google DeepMind team, Gemini 3.8 Flash Cyber’s frontier cybersecurity performance is helping uncover complex attack paths in foundational AI and cloud technology, and fueling Wiz as we work with public services, nonprofits, and other critical infrastructure providers to ensure they stay ahead of AI-powered adversaries.

In the coming months, we’ll release more details on how Google DeepMind is helping us continuously improve our Red Agent use case. We also look forward to sharing real-world examples of how Gemini 3.8 Flash Cyber has had an impact on organizations around the world through Scan for Good.

Turning AI insight into collective knowledge

Scan for Good is not only about fixing exposures. It also aims to help the broader security community understand how AI is changing exploitability, and which weaknesses are truly meaningful. After the findings we report have been remediated, we plan to publish anonymized research detailing the underlying vulnerability patterns, the impact AI had on practical exploitability, and how organizations can put this into practice in scanning their own environments. We will focus on the lessons rather than the affected organization.

We hope this work gives defenders a practical view of what offensive AI can do today, where traditional approaches may fall short, and how exposure-management programs need to evolve.

Responsible research

Scan for Good is built around authorization, minimal and non-destructive validation, human oversight, private disclosure, and clear stopping points. We will minimize interaction with live systems, avoid unnecessary access to sensitive information where possible, and give organizations a reasonable opportunity to remediate.

We will not treat model-generated hypotheses as vulnerabilities. Findings will be validated by experienced researchers, and deeper testing will only happen where it is authorized.

Scan for Good is our effort to turn advances in AI into an advantage for defenders: finding critical exposures before attackers do, helping organizations remediate them, and sharing what we learn so the broader security community can adapt.

Organizations concerned about exposed infrastructure can apply for a Scan for Good assessment at wiz.io/scan-for-good/apply.

Original Article

Back to Top

Updates banner

Order your 2027 South Dakota Bank Directory

2027 directoryThe South Dakota Bank Directory provides detailed information on all South Dakota banks including addresses, telephone numbers, important contact names and additional pertinent information. The directory also contains information on the SDBA, banking associations, regulatory agencies, endorsed vendors, associate members and South Dakota officials.

Place your order for your 2027 SD Bank Directory!

All member banks, associate members, and endorsed vendors receive one complimentary copy.

Back to Top

SDBA Events

2026 NEXT STEP: Emerging Leaders Summit

October 28-29, 2026 | The Lodge at Deadwood | Deadwood, SD

EL Summit 26

NEXT STEP: Emerging Leaders Summit is more than a conference—it's a leadership experience designed to cultivate, connect, engage and empower South Dakota's future bank leaders. Combining thought-provoking presentations, interactive workshops and meaningful networking, the Summit creates space for emerging leaders to step away from their daily responsibilities, invest in their personal and professional growth, and build lasting connections with peers from across the state.

Throughout the day, participants will strengthen their leadership skills, discover new perspectives, exchange ideas and gain practical tools they can immediately apply within their banks and communities. Whether developing greater self-awareness, tackling real-world challenges or expanding their professional network, attendees will leave inspired, better connected and prepared to take the next step in their leadership journey.

Details + Registration

Back to Top

UBP October 2026Participants will learn how to assess and analyze a bank’s financial performance by working with data from real institutions. Using financial statements from one sample financial institution along with statements from their own banks, participants will become familiar with the ins and outs of balance sheets and income statements and learn how to apply key performance metrics to the data presented in these documents.

Having learned how to interpret and analyze a bank’s financial statements, participants will gain deeper insight into the factors affecting bank performance. Later sessions in this course will address ways in which performance may be hindered or improved by funding strategies and risk management. Ultimately, participants will be able to review a bank’s financial statements to identify strengths and weaknesses and be able to recommend changes that will lead to improved performance.

In the final session of this course, participants will put what they have learned into practice. Participants will analyze a new data set, rate the bank’s performance and suggest strategic adjustments that might benefit the bank.

Details + Registration

Back to Top

Online Education

online ed

Participating in learning opportunities outside the bank can be challenging. Take advantage of the SDBA's extensive selection of webinars and on-demand training to enhance your banking expertise directly from your computer.

GSB Online Seminars
OnCourse Learning
SBS Institute
ABA Training

 


compliance alliance

 

Learn how to put compliance management solutions from Compliance Alliance to work for your bank, by contacting (888) 353-3933 or [email protected] and ask for our Membership Team. For timely compliance updates, subscribe to Bankers Alliance’s email newsletters. 

Back to Top


SDBA eNews Archive
View past issues of the SDBA eNews

Advertising Opportunity
Learn more about sponsoring the SDBA eNews

Questions/Comments
Contact the SDBA at 605.224.1653 or via email