Skip to the main content.

ABT Blog

Read about mortgage technology solutions topics

Risk Management

A standard perimeter penetration test stops at the network edge while session token theft, mailbox forwarding and malicious app consent happen inside the Microsoft 365 tenant

14 min read

Microsoft 365 Penetration Testing for Financial Institutions

In This Article What a penetration test is, in your regulator's words What your regulator actually requires What Microsoft permits you to test The...

Read More
Microsoft Power Pages admin panel showing Anonymous Access set to Allowed, with customer records flowing out of an open vault

11 min read

Power Pages Misconfiguration: No CVE, No Patch

Two financial regulators flagged a Microsoft Power Pages setting that exposes Dataverse records. No CVE, no patch, and your scanner will not see it.

Read More
An open manila vendor file folder on a desk holding printed audit reports, with a card bearing the Microsoft 365 logo resting on top and a tab labeled VENDOR FILE

17 min read

Vendor Due Diligence on Microsoft 365: What Goes in the File

In This Article The Questionnaire That Comes Back Empty The Passage That Answers This Step One: Document the Limitation Step Two: Obtain Alternative...

Read More
Cyber incident reporting deadlines for financial institutions, showing the 36 hour, 72 hour and 30 day regulatory clocks

12 min read

The 36-Hour, 72-Hour, and 30-Day Incident Reporting Clocks

Three federal rules, three deadlines, and three different definitions of the moment the clock starts. What triggers each one, and what Microsoft 365...

Read More
Windows Hello for Business key abuse and Microsoft Entra ID device registration

15 min read

Windows Hello for Business Key Abuse: What Financial Institutions Need to Verify

Malware already running in a signed-in Windows session can use that user's Windows Hello for Business key to authenticate to Microsoft Entra ID, with...

Read More
Dark editorial illustration of a hijacked Microsoft 365 session quietly reading payroll and finance mail while security alerts stay silent

13 min read

Payroll Pirates: The Microsoft 365 Attack Your Alerts Miss

A Microsoft 365 session-hijacking campaign is reading payroll and finance mail while deliberately avoiding the account-modification signals most...

Read More
A Microsoft Teams AI meeting archive .meeting file flowing into a secure tenant storage vault with a five-year retention dial and Microsoft 365 branding, for financial institutions

13 min read

Microsoft Teams AI Meeting Archives Go Default-On for Financial Institutions

In This Article What Microsoft Teams Starts Doing by Default What a .meeting File Is, and What It Is Not The Five-Year Default Nobody at Your...

Read More
Cyber insurance renewal checklist mapped to a Microsoft 365 security panel showing Microsoft Entra, Microsoft Defender, and Microsoft Purview.

12 min read

Cyber Insurance Requirements Mapped to Microsoft 365 for Financial Institutions

In This Article Cyber Coverage Became a Controls Exam What Carriers Actually Require Now The Control to Microsoft 365 Map Where Microsoft 365 Falls...

Read More
Bank vault protected by a Microsoft 365 security shield deflecting ransomware

9 min read

Ransomware Protection for Financial Institutions

In This Article What a Ransomware Attack Does to a Financial Institution How the Attack Actually Gets In The Controls That Stop Ransomware Your...

Read More

20 min read

AI Governance Assessment for Financial Institutions: The 25-Point Checklist for Banks, Credit Unions, and Mortgage Companies

In This Article The Examiner Question Most IT Directors Cannot Answer What Actually Changed in 2026 Five Microsoft 365 Surfaces That Already Govern...

Read More