ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

What Banks Need to Know About New Data Breach Notification Requirements

February 4, 2022
Reading Time: 4 mins read
What Banks Need to Know About New Data Breach Notification Requirements

By David J. Oberly

Given the omnipresent concern about cyber attacks targeting the banking industry, the FDIC, OCC and Federal Reserve recently published a new joint final rule establishing enhanced security incident notification requirements for banking organizations and their service providers.

The final rule is designed to improve the sharing of information about cyber incidents that may impact the nation’s banking system and requires banks to notify their primary federal regulator within 36 hours of determining that a “significant” computer-security incident has occurred. Similarly, bank service providers are now required to notify impacted bank customers as soon as possible of any incident that could materially impact their operations for four hours or more.

The deadline for compliance with the new notification requirements is May 1. Here is a breakdown of these new notification requirements:

Financial institutions

Notification events. For covered banking organizations, the new notification requirements are triggered in the event a bank experiences a “notification incident,” defined as a security event resulting in actual harm to the confidentiality, integrity or availability of the bank’s information system or the information that the system processes, stores or transmits and which has—or is reasonably likely to—disrupt or degrade its: ability to carry out banking operations or deliver banking products or services to a material portion of its customers; business lines which, upon failure, would result in a material loss of revenue or franchise value; or operations which, upon failure or discontinuance, would pose a threat to the financial stability of the nation.

Notification obligations. In the event of a notification incident, banking organizations are required to notify the appropriate agency or agency-designated point of contact of the incident, which can be accomplished through email, telephone or similar methods prescribed by the agencies. The bank must provide its notice no later than 36 hours after a determination has been made that a notification incident has occurred.

Service providers

Notification events. For service providers, the new notification requirements are triggered when a service provider experiences an incident resulting in actual harm to the confidentiality, integrity or availability of the service provider’s information system or the information that the system processes, stores or transmits and which has—or is reasonably likely to—disrupt or degrade the services it provides for a period of four or more hours.

Notification obligations. In the event of a triggering security incident, service providers are required to provide notice of the incident to at least one bank-designated point of contact at each affected bank customer. In the event no bank-designated point of contact has been supplied to the service provider, notification must be made to the bank’s CEO and CIO or two individuals of comparable responsibility and can be accomplished “through any reasonable means.”

In terms of timing, service providers are only required to supply the requisite notice “as soon as possible” after a determination has been made that a triggering security incident has occurred. The 36-hour time limitation imposed on banks does not, however, extend to service providers.

Practical compliance tips

Security incident notification is not a new concept, especially for the already heavily regulated banking sector. With that said, the more aggressive notification requirements set forth in the final rule may require banks and their service providers to make certain modifications to their current security incident policies, procedures and protocols to align them with these new, unique notice requirements. In particular, banks and their service providers should consider taking the following actions well in advance of the May 1, 2022, compliance deadline:

Security incident detection. Ensure that the appropriate practices and protocols are in place to effectively detect any potential security incidents. These practices should also provide the capability to rapidly determine whether any such incident rises to the level of triggering notice under the final rule.

Incident response notification. Update all security incident response plans to ensure the ability to provide notification to any applicable regulatory agencies (in the case of banks) or banking customers (in the case of service providers) within the time limitations prescribed by the final rule. This should include the implementation of clear, easy-to-understand protocols to facilitate notification in a timely manner, as well as up-to-date contact information for all designated points of contact that must receive notice in the event of a triggering security incident.

Service provider contacts. Review all service provider contracts to ensure they address security incident notification requirements in a manner that is consistent with the final rule. Incorporating these new obligations is especially important in light of the obligation imposed on service providers to escalate security incidents to a bank customer’s CEO and CIO in the event that no bank-designated contacts have been given to the service provider. At the same time, service providers must also remember that compliance with the final rule is required even where their contractual obligations conflict with the new notification mandates.

Other intersecting breach notice obligations. Lastly, keep in mind that the notification requirements under the final rule likely diverge from banks’ and service providers’ other existing breach notification obligations. This is because the final rule focuses on security incidents themselves that may impair or otherwise harm operations (that is, the operational impact of security incidents), while other breach notice regimes focus on unauthorized access to personal information (that is, the compromise of personal information associated with a security incident).

David J. Oberly is an attorney in the Cincinnati office of Blank Rome LLP and is a member of the firm’s privacy, security and data protection, biometric privacy and privacy class action litigation groups. He can be reached at [email protected].

Tags: Data breachesData privacyData securityThird-party riskVendor relations
ShareTweetPin

Related Posts

ABA faults banking regulators for confusing CRA rule rollout

FDIC, OCC release Q3, Q4 CRA exam schedules

Community Banking
May 29, 2026

The FDIC has released the schedules for Community Reinvestment Act examinations to be conducted in the third and fourth quarters of the year, while the OCC released its schedule of CRA evaluations for Q3.

FinCEN seeks feedback on real estate reporting form

Court vacates FinCEN residential real estate reporting rule

Compliance and Risk
May 28, 2026

A federal court has vacated FinCEN’s new anti-money laundering reporting requirements for residential real estate transfers. As a result, reporting requirements are suspended while the agency appeals the decision.

CFPB claims ‘complex’ pricing drives up cost of financial products

Consumer groups, vendors sue CFPB over changes to fair lending enforcement

Compliance and Risk
May 28, 2026

A coalition of consumer groups and fair lending compliance firms has filed a lawsuit to prevent the CFPB from removing disparate impact as a prohibited practice from Regulation B, which implements the Equal Credit Opportunity Act.

Trump administration proposes nondisclosure agreement for all government employees

Trump administration proposes nondisclosure agreement for all government employees

Compliance and Risk
May 26, 2026

The Trump administration is proposing the creation of a government-wide nondisclosure agreement for new and existing federal employees that agencies could elect to adopt.

Treasury Department seeks feedback on stablecoins, illicit activities

ABA, associations urge regulators to fully account for stablecoin risks in annual report

Compliance and Risk
May 26, 2026

Saying they are deeply concerned about the risk stablecoin payment issuers pose to the overall financial system, ABA and three other bankers associations submitted recommendations for what federal regulators should include in their annual report to Congress on...

FDIC approves new guidance for ‘living wills’

Banking agencies publish ‘living will’ feedback

Compliance and Risk
May 26, 2026

The FDIC and Federal Reserve recently published their feedback letters for the resolution plans submitted by the largest banks, although FDIC board member and Comptroller of the Currency Jonathan Gould abstained from voting for the letters’ release, as...

NEWSBYTES

ABA, associations reaffirm support for federal preemption of Illinois interchange law

May 29, 2026

ABA DataBank: Streamflation takes off

May 29, 2026

FDIC, OCC release Q3, Q4 CRA exam schedules

May 29, 2026

SPONSORED CONTENT

A Modern Blueprint for Serving High-Net-Worth Families

A Modern Blueprint for Serving High-Net-Worth Families

May 28, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

AI Is in Your Bank. Is Your Cloud Contract Governing It?

May 20, 2026
Credit Memos at the Convergence Point

Credit Memos at the Convergence Point

May 1, 2026
Digital Account Opening: Think Outside the Box for Maximum Business Impact

Digital Account Opening: Think Outside the Box for Maximum Business Impact

April 29, 2026

PODCASTS

Podcast: Creating a feeling of welcome, for customers and new bankers

May 28, 2026

Podcast: How consumer deposits drive full relationship banking

May 14, 2026

Podcast: How an Ohio banker talks with policymakers about stablecoin issues

May 6, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.