ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
ADVERTISEMENT
Home Compliance and Risk

What Banks Need to Know About New Data Breach Notification Requirements

February 4, 2022
Reading Time: 4 mins read
What Banks Need to Know About New Data Breach Notification Requirements

By David J. Oberly

Given the omnipresent concern about cyber attacks targeting the banking industry, the FDIC, OCC and Federal Reserve recently published a new joint final rule establishing enhanced security incident notification requirements for banking organizations and their service providers.

The final rule is designed to improve the sharing of information about cyber incidents that may impact the nation’s banking system and requires banks to notify their primary federal regulator within 36 hours of determining that a “significant” computer-security incident has occurred. Similarly, bank service providers are now required to notify impacted bank customers as soon as possible of any incident that could materially impact their operations for four hours or more.

The deadline for compliance with the new notification requirements is May 1. Here is a breakdown of these new notification requirements:

Financial institutions

Notification events. For covered banking organizations, the new notification requirements are triggered in the event a bank experiences a “notification incident,” defined as a security event resulting in actual harm to the confidentiality, integrity or availability of the bank’s information system or the information that the system processes, stores or transmits and which has—or is reasonably likely to—disrupt or degrade its: ability to carry out banking operations or deliver banking products or services to a material portion of its customers; business lines which, upon failure, would result in a material loss of revenue or franchise value; or operations which, upon failure or discontinuance, would pose a threat to the financial stability of the nation.

Notification obligations. In the event of a notification incident, banking organizations are required to notify the appropriate agency or agency-designated point of contact of the incident, which can be accomplished through email, telephone or similar methods prescribed by the agencies. The bank must provide its notice no later than 36 hours after a determination has been made that a notification incident has occurred.

Service providers

Notification events. For service providers, the new notification requirements are triggered when a service provider experiences an incident resulting in actual harm to the confidentiality, integrity or availability of the service provider’s information system or the information that the system processes, stores or transmits and which has—or is reasonably likely to—disrupt or degrade the services it provides for a period of four or more hours.

Notification obligations. In the event of a triggering security incident, service providers are required to provide notice of the incident to at least one bank-designated point of contact at each affected bank customer. In the event no bank-designated point of contact has been supplied to the service provider, notification must be made to the bank’s CEO and CIO or two individuals of comparable responsibility and can be accomplished “through any reasonable means.”

In terms of timing, service providers are only required to supply the requisite notice “as soon as possible” after a determination has been made that a triggering security incident has occurred. The 36-hour time limitation imposed on banks does not, however, extend to service providers.

Practical compliance tips

Security incident notification is not a new concept, especially for the already heavily regulated banking sector. With that said, the more aggressive notification requirements set forth in the final rule may require banks and their service providers to make certain modifications to their current security incident policies, procedures and protocols to align them with these new, unique notice requirements. In particular, banks and their service providers should consider taking the following actions well in advance of the May 1, 2022, compliance deadline:

Security incident detection. Ensure that the appropriate practices and protocols are in place to effectively detect any potential security incidents. These practices should also provide the capability to rapidly determine whether any such incident rises to the level of triggering notice under the final rule.

Incident response notification. Update all security incident response plans to ensure the ability to provide notification to any applicable regulatory agencies (in the case of banks) or banking customers (in the case of service providers) within the time limitations prescribed by the final rule. This should include the implementation of clear, easy-to-understand protocols to facilitate notification in a timely manner, as well as up-to-date contact information for all designated points of contact that must receive notice in the event of a triggering security incident.

Service provider contacts. Review all service provider contracts to ensure they address security incident notification requirements in a manner that is consistent with the final rule. Incorporating these new obligations is especially important in light of the obligation imposed on service providers to escalate security incidents to a bank customer’s CEO and CIO in the event that no bank-designated contacts have been given to the service provider. At the same time, service providers must also remember that compliance with the final rule is required even where their contractual obligations conflict with the new notification mandates.

Other intersecting breach notice obligations. Lastly, keep in mind that the notification requirements under the final rule likely diverge from banks’ and service providers’ other existing breach notification obligations. This is because the final rule focuses on security incidents themselves that may impair or otherwise harm operations (that is, the operational impact of security incidents), while other breach notice regimes focus on unauthorized access to personal information (that is, the compromise of personal information associated with a security incident).

David J. Oberly is an attorney in the Cincinnati office of Blank Rome LLP and is a member of the firm’s privacy, security and data protection, biometric privacy and privacy class action litigation groups. He can be reached at [email protected].

ADVERTISEMENT
Tags: Data breachesData privacyData securityThird-party riskVendor relations
ShareTweetPin

Related Posts

Senate bill would remove reputational risk from bank supervision

Fed removes reputational risk from bank exams

Compliance and Risk
June 23, 2025

The Fed has started the process of removing references to reputation and reputational risk from its supervisory materials, “and, where appropriate, replacing those references with more specific discussions of financial risk.”

OCC to merge community bank, large bank supervision departments

OCC to outline process for criminal referrals

Compliance and Risk
June 23, 2025

The OCC will issue a report detailing which regulatory violations can be referred to the Department of Justice for criminal prosecution, part of a larger effort to combat alleged overcriminalization of federal regulations.

ABA, BPI seek transparency around Fed stress tests

ABA, Financial Services Forum offer recommendations for Fed stress capital buffer reform

Compliance and Risk
June 23, 2025

ABA joined the Financial Services Forum in proposing changes to the Federal Reserve’s stress capital buffer requirement for large banks.

FBI: Crypto-related fraud losses increased 45% in 2023

Justice Department seizes millions of dollars linked to alleged crypto investment scams

Compliance and Risk
June 20, 2025

The Department of Justice announced it has seized $225.3 million in funds linked to cryptocurrency investment scams. The action marks the largest cryptocurrency seizure in Secret Service history.

ABA urges FinCEN to reevaluate BOI collection burden on banks

FinCEN releases figures on BSA filings

Compliance and Risk
June 20, 2025

Financial institutions filed 4.7 million suspicious activity reports in fiscal year 2024. They filed 20.5 million currency transaction reports during the same time frame.

FinCEN to propose new rules on money laundering, whistleblower program

Treasury official outlines principles for Bank Secrecy Act modernization

Compliance and Risk
June 18, 2025

The Treasury Department is exploring ways to streamline the filing process for suspicious activity reports and currency transaction reports as part of a broader effort to modernize BSA enforcement, Deputy Secretary of the Treasury Michael Faulkender said.

NEWSBYTES

House passes ABA-backed ‘trigger leads’ bill

June 23, 2025

Fed removes reputational risk from bank exams

June 23, 2025

OCC: Bank trading revenue $15B in Q1 2025

June 23, 2025

SPONSORED CONTENT

AI Compliance and Regulation: What Financial Institutions Need to Know

Unlocking Deposit Growth: How Financial Institutions Can Activate Data for Precision Cross-Sell

June 1, 2025
Choosing the Right Account Opening Platform: 10 Key Considerations for Long-Term Success

Choosing the Right Account Opening Platform: 10 Key Considerations for Long-Term Success

April 25, 2025
Outsourcing: Getting to Go/No-Go

Outsourcing: Getting to Go/No-Go

April 5, 2025
Six Payments Trends Driving the Future of Transactions

Six Payments Trends Driving the Future of Transactions

March 15, 2025

PODCASTS

Podcast: Staying close to clients amid tariff-driven volatility

June 18, 2025

Podcast: Old National’s Jim Ryan on the things that really matter

June 12, 2025

Podcast: What bankers need to know about ‘First Amendment audits’

June 5, 2025
ADVERTISEMENT

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2025 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2025 American Bankers Association. All rights reserved.