ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

What Banks Need to Know About New Data Breach Notification Requirements

February 4, 2022
Reading Time: 4 mins read
What Banks Need to Know About New Data Breach Notification Requirements

By David J. Oberly

Given the omnipresent concern about cyber attacks targeting the banking industry, the FDIC, OCC and Federal Reserve recently published a new joint final rule establishing enhanced security incident notification requirements for banking organizations and their service providers.

The final rule is designed to improve the sharing of information about cyber incidents that may impact the nation’s banking system and requires banks to notify their primary federal regulator within 36 hours of determining that a “significant” computer-security incident has occurred. Similarly, bank service providers are now required to notify impacted bank customers as soon as possible of any incident that could materially impact their operations for four hours or more.

The deadline for compliance with the new notification requirements is May 1. Here is a breakdown of these new notification requirements:

Financial institutions

Notification events. For covered banking organizations, the new notification requirements are triggered in the event a bank experiences a “notification incident,” defined as a security event resulting in actual harm to the confidentiality, integrity or availability of the bank’s information system or the information that the system processes, stores or transmits and which has—or is reasonably likely to—disrupt or degrade its: ability to carry out banking operations or deliver banking products or services to a material portion of its customers; business lines which, upon failure, would result in a material loss of revenue or franchise value; or operations which, upon failure or discontinuance, would pose a threat to the financial stability of the nation.

Notification obligations. In the event of a notification incident, banking organizations are required to notify the appropriate agency or agency-designated point of contact of the incident, which can be accomplished through email, telephone or similar methods prescribed by the agencies. The bank must provide its notice no later than 36 hours after a determination has been made that a notification incident has occurred.

Service providers

Notification events. For service providers, the new notification requirements are triggered when a service provider experiences an incident resulting in actual harm to the confidentiality, integrity or availability of the service provider’s information system or the information that the system processes, stores or transmits and which has—or is reasonably likely to—disrupt or degrade the services it provides for a period of four or more hours.

Notification obligations. In the event of a triggering security incident, service providers are required to provide notice of the incident to at least one bank-designated point of contact at each affected bank customer. In the event no bank-designated point of contact has been supplied to the service provider, notification must be made to the bank’s CEO and CIO or two individuals of comparable responsibility and can be accomplished “through any reasonable means.”

In terms of timing, service providers are only required to supply the requisite notice “as soon as possible” after a determination has been made that a triggering security incident has occurred. The 36-hour time limitation imposed on banks does not, however, extend to service providers.

Practical compliance tips

Security incident notification is not a new concept, especially for the already heavily regulated banking sector. With that said, the more aggressive notification requirements set forth in the final rule may require banks and their service providers to make certain modifications to their current security incident policies, procedures and protocols to align them with these new, unique notice requirements. In particular, banks and their service providers should consider taking the following actions well in advance of the May 1, 2022, compliance deadline:

Security incident detection. Ensure that the appropriate practices and protocols are in place to effectively detect any potential security incidents. These practices should also provide the capability to rapidly determine whether any such incident rises to the level of triggering notice under the final rule.

Incident response notification. Update all security incident response plans to ensure the ability to provide notification to any applicable regulatory agencies (in the case of banks) or banking customers (in the case of service providers) within the time limitations prescribed by the final rule. This should include the implementation of clear, easy-to-understand protocols to facilitate notification in a timely manner, as well as up-to-date contact information for all designated points of contact that must receive notice in the event of a triggering security incident.

Service provider contacts. Review all service provider contracts to ensure they address security incident notification requirements in a manner that is consistent with the final rule. Incorporating these new obligations is especially important in light of the obligation imposed on service providers to escalate security incidents to a bank customer’s CEO and CIO in the event that no bank-designated contacts have been given to the service provider. At the same time, service providers must also remember that compliance with the final rule is required even where their contractual obligations conflict with the new notification mandates.

Other intersecting breach notice obligations. Lastly, keep in mind that the notification requirements under the final rule likely diverge from banks’ and service providers’ other existing breach notification obligations. This is because the final rule focuses on security incidents themselves that may impair or otherwise harm operations (that is, the operational impact of security incidents), while other breach notice regimes focus on unauthorized access to personal information (that is, the compromise of personal information associated with a security incident).

David J. Oberly is an attorney in the Cincinnati office of Blank Rome LLP and is a member of the firm’s privacy, security and data protection, biometric privacy and privacy class action litigation groups. He can be reached at [email protected].

Tags: Data breachesData privacyData securityThird-party riskVendor relations
ShareTweetPin

Related Posts

ABA’s Benda testifies before House subcommittee on escalating fraud threats

ABA’s Benda testifies before House subcommittee on escalating fraud threats

Compliance and Risk
September 18, 2025

Banks are working every day to protect their customers from fraud, but they cannot stop criminals by themselves, ABA's Paul Benda said during a congressional hearing on financial fraud.

ABA to FCC: Protect critical calls to bank customers

ABA, NCLC ask Federal Communications Commission to revisit revocation rules

Compliance and Risk
September 18, 2025

ABA and the National Consumer Law Center sent a joint letter asking the FCC to initiate rulemaking to revisit three provisions in its 2024 order on revocation of consent.

ABA: OCC should revise proposed changes to bank merger application process

OCC to divide supervisory functions by bank size

Community Banking
September 18, 2025

The Office of the Comptroller of the Currency will split its bank supervision and examination division into three distinct units based on bank size, reversing a decision earlier this year to combine its supervisory functions into a single...

FDIC withdraws proposed rules on brokered deposits, corporate governance, executive pay

ABA supports creation of independent office to oversee FDIC supervisory appeals

Compliance and Risk
September 17, 2025

A proposal to create an independent office at the FDIC to oversee bank appeals of its supervisory decisions would serve “as a crucial backstop for fair and consistent supervision,” ABA said.

ABA urges House lawmakers to support several banking-related bills

House committee advances four ABA-backed bills

Community Banking
September 16, 2025

The House Financial Services Committee advanced four bills supported by ABA, covering topics ranging from stress testing to community banks.

Senate Banking Committee forms working groups on flood insurance, bank regulator reform

ABA recommends long-term reauthorization, updates to National Flood Insurance Program

Compliance and Risk
September 15, 2025

ABA is urging lawmakers to reauthorize the National Flood Insurance Program for five years and make changes to modernize and improve the program’s stability and affordability, as well as improve compliance requirements for the Flood Disaster Protection Act.

NEWSBYTES

ABA DataBank: Strong demand for air travel in 2025

September 19, 2025

Survey: Most banks preparing for AI, have concerns about stablecoins

September 19, 2025

Treasury seeks input on Genius Act implementation

September 19, 2025

SPONSORED CONTENT

The Connectivity Dividend

The Connectivity Dividend

September 1, 2025

Building Trust with Every Transaction

September 1, 2025
10 Essentials of a New Loan Origination System

10 Essentials of a New Loan Origination System

August 29, 2025
Planning Your 2026 Budget? Allocate Resources to Support Growth and Retention Goals

Planning Your 2026 Budget? Allocate Resources to Support Growth and Retention Goals

August 1, 2025

PODCASTS

Podcast: The ‘capacity crisis’ in leadership today

September 17, 2025

Podcast: AI, third-party risk and the future of partner banking

September 11, 2025

Demographic trends shaping the U.S. banking outlook

July 30, 2025

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2025 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2025 American Bankers Association. All rights reserved.