ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Cyber Compliance: The Board’s Next Enforcement Action Worry

November 2, 2015
Reading Time: 3 mins read

By T.J. Grasmick and Harold Reichwald

What happens if your board drops the ball on cybersecurity? Consider what happened to a hospital network in California. Cottage Health System in Santa Barbara spent $4 million to settle litigation and respond to a federal investigation late last year after its patient records were found to be inadequately protected from public Internet access. When Cottage Health made a claim under its “Privacy” policy, its insurer denied coverage, saying the system and its vendor failed to follow “minimum required practices” that it promised to follow.

Among other things, Cottage Health had promised to test computer security regularly; periodically reassess its exposure to cyber threats; select, oversee, monitor and audit third- party vendors of information security management; and take steps at all times to protect computer systems from unauthorized access. The insurance company claimed that the hospital system failed to meet these minimum standards.

This case relates directly to the fiduciary duties and potential personal exposure of bank directors in cybersecurity risks. It illustrates what will be expected of all companies with computer systems that contain sensitive and private information, and it may well set a minimum standard for banks recovering on cybersecurity insurance policy claims.

As data breaches continue to make news and cost banks money, it’s worth remembering that—as with every risk in banking—the final responsibility for addressing cybersecurity risks rests with the board of directors. Directors should start by conducting a thorough cybersecurity self-assessment using the banking agencies’ free new tool.

The board’s responsibilities for risk management and oversight of cybersecurity include being aware of the vulnerabilities of the bank’s operations to attack, including the potential access points into the bank’s systems, including PINs stolen by cameras at ATMs, sophisticated hacks into the bank’s network or employees logging into the network through unsecured airport Wi-Fi. Boards must also understand the bank’s reliance on external vendors and how it monitors its third-party providers. It is critical to ensure the bank has a tested incident management and response program.

The board and senior management must be proactive in their governance of everything cybersecurity by the next exam. This includes using consultants, engaging counsel, soliciting vendors and training staff and directors with data breach exercises. If the board and management do not take these steps, they can expect management and risk ratings to drop—with a distinct possibility that enforcement actions will follow.

A cybersecurity enforcement action will put M&A or other expansion plans on ice. The next shoe to fall may be civil money penalties against the bank—and potentially against individual directors if the corrective action response is deemed to be materially deficient. Addressing cybersecurity risks belatedly after shortcomings have been identified by examiners or, worse yet, after a significant and successful cyberattack, will entail much higher costs for consultants, enhanced technology and training.

Directors should also consider their bank’s cyber insurance coverage and evaluate whether the bank is meeting its obligations under the policy. Cybersecurity insurance is an evolving product, and many carriers tend initially to deny coverage if policy language is unclear and other policies will be affected by its actions. If insurance companies follow the pattern set when BSA/AML enforcement actions bloomed, they will exclude cybersecurity coverage completely if the bank has had an incident or a regulatory enforcement action, or they will charge absurd premiums as they did for D&O coverage.

Directors of publicly traded banks and bank holding companies should be concerned about shareholder suits after a data breach alleging neglect of fiduciary duties, gross mismanagement and waste of corporate assets arising from the board’s failure to take sufficient steps to protect customers’ personal information.

In these cases, the claims could involve not only the failures that occurred before the cyber attack but also for the way in which the board and management conducted the affairs of the bank as it responded to the data breach.

Bank boards should address cybersecurity issues on a regular basis. At least one director should be thoroughly familiar with the threats posed by a cybersecurity breach, and all directors must be inquisitive, informed and instrumental in governing the bank’s cybersecurity risks. Otherwise, the next examination may be the start of a long, painful and costly regulatory enforcement experience.

T.J. Grasmick and Harold Reichwald are Los Angeles-based partners at the law firm Manatt, Phelps & Phillips, LLP.

Tags: CybersecurityDirectorsProfessional liability
ShareTweetPin

Related Posts

Report: More states creating restrictions on crypto ATMs

Crypto exchange agrees to shut down ‘crypto ATMs’ as part of settlement

Compliance and Risk
October 8, 2026

The cryptocurrency exchange Coinme has agreed to close down its virtual currency kiosk operations in multiple states as part of a settlement with 34 state financial regulatory authorities over alleged Bank Secrecy Act and anti-money laundering violations, according...

Senate Banking Committee forms working groups on flood insurance, bank regulator reform

GAO urges Congress to expand flood insurance coverage for at-risk properties

Compliance and Risk
October 7, 2026

Approximately 86% of high-risk properties lack National Flood Insurance Program coverage, according to the report.

Five tips to juice community bank board performance

New survey probes community banks’ plans for digital assets

Community Banking
October 6, 2026

Double-digit shares of community bankers intend to offer tokenized deposits and stablecoin solutions within the next 12 months, according to the Conference of State Bank Supervisors' 2026 community bank survey released today. 

ABA seeks more coordination among banking agencies in rewriting disclosure rules

ABA seeks more coordination among banking agencies in rewriting disclosure rules

Compliance and Risk
October 6, 2026

As they restructure the processes for making confidential bank information available for public review, regulators should better coordinate their efforts to ensure banks do not face differing disclosure requirements, ABA said.

Fed’s Bowman to keynote ABA Conference for Community Bankers

Fed to split bank supervision into five regions

Community Banking
October 6, 2026

The Federal Reserve will divide its bank supervision into five geographic regions rather than splitting it among the 12 Reserve Bank districts, Vice Chair for Supervision Michelle Bowman said. The Fed also plans to revisit the criteria used...

ABA highlights banker comments seeking stronger ‘know your customer’ rules for originating providers

Lawmakers propose banning SIM boxes used in scam calls

Compliance and Risk
October 5, 2026

A proposed bill would ban the sale and manufacturing of machines that help scammers disguise their phone calls and texts.

NEWSBYTES

Crypto exchange agrees to shut down ‘crypto ATMs’ as part of settlement

October 8, 2026

Fed: Consumer credit increased 1.9% in August

October 8, 2026

Mortgage rates rise

October 8, 2026

SPONSORED CONTENT

The Shift from Demographic Marketing

The Shift from Demographic Marketing

October 1, 2026
Meeting Ag Lending Goals Without Going It Alone

Meeting Ag Lending Goals Without Going It Alone

October 1, 2026
Beyond the Portfolio: The Wealth Manager’s New Role in a Multigenerational World

Beyond the Portfolio: The Wealth Manager’s New Role in a Multigenerational World

September 17, 2026
Banking Technology at a Strategic Crossroads

Banking Technology at a Strategic Crossroads

September 8, 2026

PODCASTS

Podcast: The birth of American money and how it triggered a revolution

October 8, 2026

Podcast: Creating seamless customer experiences

September 30, 2026

Podcast: Telling a different kind of story about community banks

September 28, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.