• Home
  • 5
  • Insights
  • 5
  • The Internal Audit Insight: Fannie Mae’s Cybersecurity and Business Resiliency Supplement
The Internal Audit Insight: Fannie Mae’s Cybersecurity and Business Resiliency Supplement

The Internal Audit Insight: Fannie Mae’s Cybersecurity and Business Resiliency Supplement

by Michael Nouguier | Jul 28, 2025

The latest episode of our Internal Audit Insight series features Mignonne Davis and Chris Williams discussing Fannie Mae’s Information Security and Business Resiliency Supplement (the “Supplement”). Watch below to learn what it is, why it matters, and the steps you need to take to meet the August 12 compliance deadline.

In this short video we walk through the key requirements, including annual penetration testing, a formalized incident response plan, and alignment with industry frameworks like NIST, and explain what they mean for your cybersecurity and business continuity plans.


For a detailed written overview of the Supplement and steps you can take to prepare, read our full blog post here.

Explore More Insights

  • There are no suggestions because the search field is empty.

Some of these items predate Richey May’s restructuring to an alternative practice structure. Richey May is no longer a CPA firm. All Attest services are provided by Richey, May & Co., LLP.

Our Latest Insights

Looking for more industry expertise and to stay up to date? Check out more from the experts at Richey May below:

When Geopolitics Goes Digital: What Iranian Cyber Activity Means for Businesses

A wise wizard’s job is to warn people before things go wrong. Staying alert before the danger...

When Nobody Owns the Problem: IT/OT Convergence Failures at U.S. Utilities

Nation-state actors are exploiting the organizational gap between IT and OT security teams. For...

Lessons from Unanticipated OT and IoT Vulnerabilities at Major Airports

August 24, 2024. Saturday morning at a major international airport in the Pacific Northwest....

Freddie Mac’s Updated Cybersecurity Requirements: January 1, 2026 effective

As of January 1, 2026, Freddie Mac’s enhanced information security requirements are now in effect,...