Connect with us

Technology

Why Bank Remediation Falls Short When Institutions Treat Findings in Isolation

Published

on

As the OCC continues to issue and terminate bank enforcement actions, FFERM founder and CEO Dr. Jeffrey L. Edwards says institutions must look beyond closing individual findings and identify the interconnected risk failures that allowed them to develop.

CHARLOTTE, N.C., Aug. 3, 2026 /PRNewswire/ — A consent order can require a bank to correct identified deficiencies. Compliance with the order, however, does not necessarily mean the institution understands the governance, control, or risk-management weaknesses that allowed the problem to develop. Dr. Jeffrey L. Edwards, founder of FFERM Technologies, a financial risk intelligence company, warns that banks under enforcement pressure can mistake completion of required remediation for correction of the underlying risk system.

“Banks often resolve this issue from a short-term perspective so they can get the enforcement action lifted,” Dr. Edwards said. “They address what regulators identified, but not the root of the problem. That means they are treating the symptom, not the cause.”

Enforcement Identifies the Issue, Not Always the Cause
The Office of the Comptroller of the Currency (OCC) says it uses enforcement actions to require bank boards and management to correct deficient practices or violations. Its May actions included a consent order against Community Federal Savings Bank for Bank Secrecy Act and anti-money laundering deficiencies and violations. In July, the OCC announced a cease-and-desist order against United Texas Bank and the termination of four prior actions.

For Dr. Edwards, enforcement identifies what must be corrected. The bank’s risk program must also determine why the problem developed, what other areas may be affected, and whether the same weakness is emerging elsewhere.

A cited deficiency can be connected to broader weaknesses in governance, data, controls, escalation, or board reporting. Correcting the finding may satisfy an immediate regulatory requirement while leaving the institution without a clear understanding of how exposures interact across the organization or where controls are failing.

Operational failures rarely remain isolated. A breakdown involving people, processes, or systems can trigger a chain reaction, creating financial exposure before eventually becoming a regulatory issue. Viewed individually, each risk may appear manageable. Viewed together, they may expose interconnected weaknesses across the organization.

“Bank boards should begin with one question: ‘Why did it happen?'” Dr. Edwards said. “It sounds simple, but people answer it quickly because they think they know. Without evidence, the answer may be opinion rather than fact.”

Static Reports Do Not Explain Risk Behavior
Reports are necessary during remediation, but most capture a single point in time. They can document progress against a finding without showing how the underlying risk is changing, compounding with other risks, or migrating into another part of the institution.

“Reports give you only what you give them,” Dr. Edwards said. “A report is a flat, single-purpose document. It can support a decision, but intelligence provides the information and framework leaders need to make decisions as conditions change.”

Dr. Edwards argues remediation priorities should be based on evidence linking the finding to relevant processes, controls, owners, data, and downstream effects, not on the volume of documentation produced.

Traditional scoring may calculate likelihood and severity without showing which weakness should be addressed first. Dr. Edwards says remediation teams must be able to distinguish the visible consequence from the control failure, creating the broader exposure. Otherwise, the institution may complete remediation tasks without fixing the source of the risk.

Community Banks Need Proportionate, Usable Risk Intelligence
Community and regional banks do not face identical supervisory expectations in every area, but they are still responsible for correcting violations and unsafe or unsound practices. They often must do so with smaller risk teams, less specialized infrastructure, and more limited consulting budgets than larger institutions.

“Small banks do not always have the resources to buy a major enterprise platform or bring in a large consulting firm,” Dr. Edwards said. “But they still need to understand root cause, prioritize remediation, and see how risk is behaving across the institution.”

From Checklist Remediation to Risk Intelligence
FFERM Technologies developed a patent-pending Four-Factor Enterprise Risk Management methodology that evaluates Compounding, Likelihood, Severity, and Predictability. By adding Compounding and Predictability to traditional likelihood and severity scoring, the methodology is designed to help institutions assess risks as interconnected and evolving rather than isolated and static.

During enforcement remediation, the cited finding is rarely the only issue that matters. Banks must determine whether the issue is isolated, whether similar failures exist elsewhere, and which corrective action reaches the source of the problem first.

“Compounding and predictability help banks get closer to the root cause by showing how risk spreads and when it may emerge,” Dr. Edwards said. “The focus is not only the calculation. It is the behavior of the risk and what the institution can do about it.”

About FFERM Technologies

FFERM Technologies is a financial risk intelligence company founded by Dr. Jeffrey L. Edwards, a 30+ year financial services and risk executive. The company developed a patent-pending Four-Factor Enterprise Risk Management methodology that expands beyond traditional likelihood-and-severity scoring to include Compounding and Predictability. FFERM helps financial institutions identify, quantify and prioritize interconnected, systemic risks that traditional models can miss, transforming risk management from a static compliance function into dynamic, forward-looking intelligence. FFERM’s platform is designed for regulated financial institutions, including banks, credit unions, insurers, RIAs and broker/dealers. For more information, visit ffermtech.com.

References

Federal Deposit Insurance Corporation. (2026). 2026 risk review. fdic.gov/analysis/2026-risk-reviewOffice of the Comptroller of the Currency. (n.d.). Enforcement actions. occ.gov/topics/laws-and-regulations/enforcement-actions/index-enforcement-actions.htmlOffice of the Comptroller of the Currency. (2026, May 21). OCC announces enforcement actions for May 2026. occ.gov/news-issuances/news-releases/2026/nr-occ-2026-40.htmlOffice of the Comptroller of the Currency. (2026, July 16). OCC announces enforcement actions for July 2026. occ.gov/news-issuances/news-releases/2026/nr-occ-2026-59.html

Media Inquiries:
Karla Jo Helms
JOTO PR™
727-777-4629
Jotopr.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/why-bank-remediation-falls-short-when-institutions-treat-findings-in-isolation-302841148.html

SOURCE FFERM Technologies

Continue Reading

Technology

SparkLabs and Mirae Asset Launch a Venture Capital Fund for Central Asian Startups

Published

on

By

SEOUL, South Korea, Sept. 20, 2026 /PRNewswire/ — Qazaqstan Investment Corporation (QIC), IT Park Ventures (Uzbekistan), Mirae Asset Venture Investment and SparkLabs Group have signed a term sheet to establish SparkLabs Mirae Silk Road Fund I LP, a new venture capital fund. The fund will be managed by Mirae Asset Venture Investment and SparkLabs Group.

The signing took place in Seoul during the state visits of the Presidents of Kazakhstan and Uzbekistan to Korea and the first Central Asia–Republic of Korea Summit.

During this past week, South Korea and Kazakhstan signed commercial agreements worth US$18.95 billion. Kazakhstan is a country of 20 million people with its core industries being oil and gas, and among the highest producers of iron and silver in the world. Uzbekistan is a country of 39 million people, and they are the largest electricity producer in Central Asia.

Qazaqstan Investment Corporation (QIC) is Kazakhstan’s national fund of funds and are anchor investors along with IT Park Ventures, the venture capital arm of the country’s state technology park. The new venture capital fund will back Central Asian startups at the Series A and later, which are businesses with a proven model that are ready to scale beyond the region. The fund is sector-agnostic but focuses on AI-native companies, where artificial intelligence is core to the product and business model.

“Higgsfield becoming Kazakhstan’s first unicorn was a turning point. It showed that a world-class AI company can be built in Central Asia. And it won’t be the last with more than half of the region’s population is under 30, growing up digital and our governments actively investing in AI. Yet the region is still largely overlooked by international investors, and that’s the opportunity this fund is built for,” explained Aslan Sultanov, Co-founder and General Partner at SparkLabs Mirae Silk Road.

Former Coinbase CTO and Partner at Andreessen Horowitz, Balaji Srinivasan, reopened his Network School in Kazakhstan last month. Telegram launched an AI lab and opened their first regional office in Kazakhstan this past year.

Beyond capital, portfolio companies will gain access to the SparkLabs and Mirae Asset’s global networks, along with hands-on support in expanding into South Korea, the United States and the MENA region.

About the Partners

SparkLabs Group is a network of startup accelerators and venture capital funds that has invested in over 600 startups across 6 continents since December 2013. These companies include OpenAI, SpaceX, Vectara, Kneron, Anthropic, Nex Team, Kraken, GenG, Lyft, MetAI, and others.

Mirae Asset Venture Investment is the venture capital arm of Mirae Asset Financial Group, one of Asia’s largest independent financial groups with over US$845 billion in assets under management. The company operates worldwide across 18 markets, and manages a fully diversified global investment platform encompassing ETFs, alternative investments, and traditional strategies.

Qazaqstan Investment Corporation (QIC) is Kazakhstan’s national fund of funds and part of Baiterek National Managing Holding. QIC invests in private equity and venture capital funds alongside international and private partners, with the goal of attracting long-term capital into Kazakhstan and developing the country’s investment ecosystem. QIC participates in 19 funds with a combined capitalization of $2.8 billion.

IT Park Ventures is the venture capital arm of IT Park Uzbekistan, the country’s state technology park and the main platform supporting Uzbekistan’s IT industry and tech exports. IT Park Ventures invests in startups from Uzbekistan and Central Asia and co-invests with international funds, connecting regional founders with global capital and markets.

View original content to download multimedia:https://www.prnewswire.com/news-releases/sparklabs-and-mirae-asset-launch-a-venture-capital-fund-for-central-asian-startups-302883810.html

SOURCE SparkLabs Group

Continue Reading

Technology

AECOM Data Breach Investigation: Edelson Lechtzin LLP Probes Class Action Claims After Hackers Allege Theft of More Than 1 TB of Data

Published

on

By

National class action law firm offers free, confidential case evaluations to AECOM employees, clients, and others whose personal information may have been exposed in the reported AECOM data breach.

DALLAS, Sept. 20, 2026 /PRNewswire/ — Edelson Lechtzin LLP, a national class action law firm, is investigating data privacy claims arising from a reported data breach at AECOM, the U.S.-based multinational infrastructure and engineering firm. Anyone who has received a data breach notice from AECOM, or who believes their personal information may have been exposed, can request a free case evaluation.

AECOM data breach — at a glance:

Company: AECOM, a Texas-based, multibillion-dollar multinational infrastructure consulting, engineering, design, and construction management firm.Reported: A cyberattack said to have occurred on or about September 17, 2026, first surfaced on dark web monitoring sites.Hackers’ claims: The group Metaencryptor claimed responsibility for an attack said to involve approximately 1.22 terabytes (TB) of data. Separately, dark web monitoring service Breachsense listed a related AECOM leak of roughly 670GB attributed to a group identified as BrainCipher.Status: The breach and the hackers’ claims remain unconfirmed. AECOM has not publicly detailed the scope or impact.Who may be affected: Current and former AECOM employees, clients, and others whose data AECOM held.Cost to you: Nothing. Case evaluations are free and confidential.

What Happened

According to a September 17, 2026 post on the dark web monitoring site Ransomware.live, the hacker group Metaencryptor claimed responsibility for a cyberattack on AECOM that allegedly affected about 1.22 TB of data. The cybersecurity blog HookPhish similarly reported that Metaencryptor was behind a suspected attack on the engineering firm.

Separately, the dark web monitoring service Breachsense reported an AECOM data leak listed at approximately 670GB, attributed to a group it identified as BrainCipher. Breachsense also indexed thousands of AECOM-linked credentials circulating online, including 27,434 @aecom.com accounts drawn from external breaches and 6,077 credentials tied to aecom.com itself — among them thousands of logins found in “combo lists” and in infostealer malware logs, many with plaintext passwords. Breachsense cautioned that those credentials may belong to either customers or staff and are not necessarily connected to the claimed attack.

The breach has not been confirmed, and important details (including its true scope, the specific data involved, and the number of people affected) are not yet publicly available.

What Personal Information May Be at Risk

The specific data involved in the reported AECOM data breach has not been confirmed. Data breaches like this can expose personal information, increasing the risk of identity theft and fraud. Affected individuals should treat any AECOM breach notification seriously.

Who May Be Affected by the AECOM Data Breach

The investigation focuses on current and former AECOM employees, clients, and anyone else whose personal information AECOM maintained. Anyone who has received a data breach notification from AECOM may face an increased risk of identity theft and fraud and is encouraged to come forward.

Your Legal Options

Edelson Lechtzin LLP is investigating a potential class action to pursue legal remedies on behalf of individuals whose sensitive personal data may have been compromised in the reported AECOM breach. A successful case could recover compensation for losses such as lost time, out-of-pocket costs, and loss of privacy, and could push AECOM to strengthen how it protects personal information. The firm will evaluate your rights and potential claims at no cost.

Recommended Steps to Protect Yourself

Review your account statements and credit reports regularly and stay alert for suspicious activity.Confirm whether your information was involved in the AECOM incident.Preserve any letters or emails you received about the breach.Consider placing fraud alerts and enrolling in credit monitoring.

Contact Us for a Free Case Evaluation

Speak confidentially with a data privacy attorney today: Marc Edelson, Esq., Edelson Lechtzin LLP, 411 S. State Street, Suite N-300, Newtown, PA 18940; Phone: 844-696-7492; Email: medelson@edelson-law.com; Web: www.edelson-law.com. Or click HERE to request a free consultation.

About Edelson Lechtzin LLP

Edelson Lechtzin LLP is a national class action law firm with offices in Pennsylvania and California. In addition to data breach litigation, the firm handles class and collective actions involving securities and investment fraud, federal antitrust violations, ERISA employee benefit plans, wage theft, and consumer fraud.

Media and Partnership Inquiries: Use the contact information above to connect with our team regarding interviews, co-counsel opportunities, and referral partnerships.

Legal Notice: This press release may be considered Attorney Advertising in some jurisdictions. Prior results do not guarantee a similar outcome. The reported data breach and the hackers’ claims described above are unconfirmed.

View original content to download multimedia:https://www.prnewswire.com/news-releases/aecom-data-breach-investigation-edelson-lechtzin-llp-probes-class-action-claims-after-hackers-allege-theft-of-more-than-1-tb-of-data-302884076.html

SOURCE Edelson Lechtzin LLP

Continue Reading

Technology

iScreen Reaches No. 1 in Graphics & Design Across 94 Markets Following iOS 27 Update

Published

on

By

Extra-large widget experiences, iOS 27-inspired themes and new customization tools drive iScreen’s latest global growth

LOS ANGELES, Sept. 20, 2026 /PRNewswire/ — iScreen, a mobile customization app for iOS and Android, announced that it has reached No. 1 in the Graphics & Design category across 94 countries and regions following its latest iOS 27-focused update.

The update expands iScreen’s Home Screen customization experience with new extra-large widgets, iOS 27-inspired themes, layouts optimized for new screen proportions, and AI-assisted design tools.

Extra-Large Widgets

Built for the larger widget canvas available in iOS 27, iScreen’s new extra-large widgets go beyond simply scaling up existing formats. The collection includes Photo, Album, Music, Calendar, Interactive Refrigerator and Quick Launch widgets, among others. Users can also customize content, layouts and visual styles to create more functional and expressive Home Screen experiences.

iOS 27-Inspired Themes and iPhone Duo Theme Support

iScreen has introduced new iOS 27-inspired themes that combine coordinated wallpapers, transparent-style widgets, icons and other visual elements into complete Home Screen setups.

Selected themes have also been optimized for iPhone Duo’s screen proportions and display dimensions, with wallpapers, widgets and icons adjusted to better fit the new format while maintaining a cohesive visual experience.

AI-Assisted Home Screen Design

iScreen is also testing AI Home Screen Designer with a limited group of users. The feature generates coordinated design suggestions based on users’ preferences for style, color and visual elements, combining wallpapers, widgets and icons into a unified setup.

“The latest iOS update has opened up new possibilities for mobile personalization,” said the iScreen team. “We want to turn those capabilities into practical and creative experiences that make Home Screen design easier and more expressive.”

About iScreen

iScreen is a mobile customization app offering widgets, wallpapers, themes and Home Screen customization tools for iOS and Android devices. With more than 100 million users worldwide, iScreen has ranked No. 1 in Graphics & Design across 94 countries and regions and has been featured by Apple Editorial in 128 countries for five consecutive days.

Official Website: iScreen – Phone Style, iScreen it!
iOS Download: ‎‎iScreen – Widgets & Wallpaper App – App Store
Android Download: iScreen Google Play

View original content:https://www.prnewswire.co.uk/news-releases/iscreen-reaches-no-1-in-graphics–design-across-94-markets-following-ios-27-update-302883972.html

Continue Reading

Trending