Regulator says cybersecurity failures exposed critical systems to attack; imposes monetary penalties on depository and former CISO, CTO