ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Cyber Compliance: The Board’s Next Enforcement Action Worry

November 2, 2015
Reading Time: 3 mins read

By T.J. Grasmick and Harold Reichwald

What happens if your board drops the ball on cybersecurity? Consider what happened to a hospital network in California. Cottage Health System in Santa Barbara spent $4 million to settle litigation and respond to a federal investigation late last year after its patient records were found to be inadequately protected from public Internet access. When Cottage Health made a claim under its “Privacy” policy, its insurer denied coverage, saying the system and its vendor failed to follow “minimum required practices” that it promised to follow.

Among other things, Cottage Health had promised to test computer security regularly; periodically reassess its exposure to cyber threats; select, oversee, monitor and audit third- party vendors of information security management; and take steps at all times to protect computer systems from unauthorized access. The insurance company claimed that the hospital system failed to meet these minimum standards.

This case relates directly to the fiduciary duties and potential personal exposure of bank directors in cybersecurity risks. It illustrates what will be expected of all companies with computer systems that contain sensitive and private information, and it may well set a minimum standard for banks recovering on cybersecurity insurance policy claims.

As data breaches continue to make news and cost banks money, it’s worth remembering that—as with every risk in banking—the final responsibility for addressing cybersecurity risks rests with the board of directors. Directors should start by conducting a thorough cybersecurity self-assessment using the banking agencies’ free new tool.

The board’s responsibilities for risk management and oversight of cybersecurity include being aware of the vulnerabilities of the bank’s operations to attack, including the potential access points into the bank’s systems, including PINs stolen by cameras at ATMs, sophisticated hacks into the bank’s network or employees logging into the network through unsecured airport Wi-Fi. Boards must also understand the bank’s reliance on external vendors and how it monitors its third-party providers. It is critical to ensure the bank has a tested incident management and response program.

The board and senior management must be proactive in their governance of everything cybersecurity by the next exam. This includes using consultants, engaging counsel, soliciting vendors and training staff and directors with data breach exercises. If the board and management do not take these steps, they can expect management and risk ratings to drop—with a distinct possibility that enforcement actions will follow.

A cybersecurity enforcement action will put M&A or other expansion plans on ice. The next shoe to fall may be civil money penalties against the bank—and potentially against individual directors if the corrective action response is deemed to be materially deficient. Addressing cybersecurity risks belatedly after shortcomings have been identified by examiners or, worse yet, after a significant and successful cyberattack, will entail much higher costs for consultants, enhanced technology and training.

Directors should also consider their bank’s cyber insurance coverage and evaluate whether the bank is meeting its obligations under the policy. Cybersecurity insurance is an evolving product, and many carriers tend initially to deny coverage if policy language is unclear and other policies will be affected by its actions. If insurance companies follow the pattern set when BSA/AML enforcement actions bloomed, they will exclude cybersecurity coverage completely if the bank has had an incident or a regulatory enforcement action, or they will charge absurd premiums as they did for D&O coverage.

Directors of publicly traded banks and bank holding companies should be concerned about shareholder suits after a data breach alleging neglect of fiduciary duties, gross mismanagement and waste of corporate assets arising from the board’s failure to take sufficient steps to protect customers’ personal information.

In these cases, the claims could involve not only the failures that occurred before the cyber attack but also for the way in which the board and management conducted the affairs of the bank as it responded to the data breach.

Bank boards should address cybersecurity issues on a regular basis. At least one director should be thoroughly familiar with the threats posed by a cybersecurity breach, and all directors must be inquisitive, informed and instrumental in governing the bank’s cybersecurity risks. Otherwise, the next examination may be the start of a long, painful and costly regulatory enforcement experience.

T.J. Grasmick and Harold Reichwald are Los Angeles-based partners at the law firm Manatt, Phelps & Phillips, LLP.

Tags: CybersecurityDirectorsProfessional liability
ShareTweetPin

Related Posts

ABA, BPI seek transparency around Fed stress tests

Fed: Stress test results show large banks can withstand economic shock

Compliance and Risk
June 24, 2026

Large banks are well positioned to weather a severe recession and would be able to continue to lend to households and businesses, according to the results of the Federal Reserve’s annual stress tests.

New York State issues guidance on AI-related cybersecurity risks to financial institutions

Survey: Most banks experienced recent rise in cyberattacks

Compliance and Risk
June 24, 2026

A majority of U.S. bank executives said they have seen an increase in the number of cyberattacks on their institutions in the past year and have boosted their cybersecurity budgets as a result, according to the most recent...

NIST releases draft guidelines for AI cybersecurity

‘Five Eyes’ nations warn AI cybersecurity threats only months out

Compliance and Risk
June 24, 2026

Organizations have only months to prepare for the cybersecurity challenges posed by new artificial intelligence models, making cyber resilience “integral to advancing business continuity,” the leaders of the "Five Eyes" cybersecurity agencies warned in a joint statement.

G7 cybersecurity group urges financial institutions to prepare for quantum computing

White House directs agencies, contractors to protect systems from quantum computing

Compliance and Risk
June 23, 2026

Government agencies and contractors would be required to take steps to protect their systems from threats posed by quantum computers under a pair of executive orders signed by President Trump.

Regulators take issue with discrimination definition in proposed appraisal standards

FHA ends field review requirement for certain mortgages

Compliance and Risk
June 23, 2026

The Federal Housing Administration will no longer require lenders to obtain appraisal field reviews for a selection of FHA-approved mortgages, instead making the reviews optional.

FinCEN proposes severing Cambodian firm as institution of primary money laundering concern

FinCEN takes further steps to sever Cambodian firm from U.S financial system

Compliance and Risk
June 23, 2026

FinCEN proposed taking additional actions to cut off U.S. financial access to a Cambodian firm that allegedly serves as a conduit for laundering money obtained through romance scams and other cybercrimes.

NEWSBYTES

Trump declines to sign housing bill into law

June 24, 2026

Fed: Stress test results show large banks can withstand economic shock

June 24, 2026

ABA offers principles to guide changes to payments system access

June 24, 2026

SPONSORED CONTENT

Why Your Systems Keep Slowing Down — and What to Do About It

Examiners Are Now Looking at Your Non-Core Systems

June 11, 2026
Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

June 1, 2026
A Modern Blueprint for Serving High-Net-Worth Families

A Modern Blueprint for Serving High-Net-Worth Families

May 28, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

AI Is in Your Bank. Is Your Cloud Contract Governing It?

May 20, 2026

PODCASTS

Podcast: Talent and innovation in community banking

June 18, 2026

Podcast: Understanding bank regulators’ guidance on illegal immigration

June 11, 2026

Podcast: Creating a feeling of welcome, for customers and new bankers

May 28, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.