What presented as an IT emergency was a whole-bank problem
The bank was formed in the early 2000s by consolidating a group of smaller rural charters, and had grown toward $1 billion in assets by lending into one of the most active energy-producing regions in the country. That boom was its advantage and, as events showed, its principal risk. Oil and gas exposure ran near 22 to 23 percent of total loans and real estate near 42 to 45 percent. The engagement began as a technology emergency. A poorly executed online banking conversion had produced customer-facing failures. Underneath sat a fragile environment: a single virtualization layer that was one point of failure, primary and backup data centers a few miles apart and neither hardened, cold-standby backups, no multi-factor authentication, and unlocked removable media. An examination was approaching. What presented as an IT problem was a whole-bank problem. Credit administration, loan and deposit operations, the branch network, the call center, finance, and enterprise risk each showed the pattern that accompanies fast growth without a matching investment in discipline. And crossing $1 billion would bring the bank under the internal-control regime of the Federal Deposit Insurance Corporation Improvement Act, requiring management to assess internal control over financial reporting and an auditor to attest to it.
KEY TAKEAWAY
The findings nobody had commissioned The most consequential findings were not in any report the bank had commissioned. Call center agents held unmonitored maintenance access to every account. Roughly 3,400 active debit cards were still linked to closed accounts, which meant replacement cards could be mailed to non-customers. These were the seams between departments, invisible on any single team’s dashboard and visible only to someone looking across the whole institution. An urgent failure is usually the visible edge of a systemic gap.

