ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Proposed rule to require reporting of cyberattacks, ransomware payments

March 28, 2024
Reading Time: 2 mins read
Cybersecurity: What threat-ready really means for banks

The Cybersecurity and Infrastructure Security Agency—part of the Department of Homeland Security—today announced a notice of proposed rulemaking to implement a 2022 law requiring financial institutions and other “critical infrastructure” businesses to report cyber incidents and ransomware payments to the department and agency.

Under the proposal, regulated financial institutions and other critical infrastructure sectors would be required to report to DHS or CISA significant cyber incidents within 72 hours as well as any ransomware payments within 24 hours. They would also be required to “promptly” fill supplemental reports if “substantial new or different information” becomes available about the incident. The reporting requirements are in addition to existing computer security incident notifications that are required to be made to financial regulators within 36 hours and a new Securities and Exchange Commission requirement for publicly traded companies to report significant cyber incidents to the public within four business days.

The proposed 450-page rulemaking by CISA would implement the Cyber Incident Reporting for Critical Infrastructure Act, or CIRCIA, of 2022, which establishes reporting requirements for several sectors of the economy, including financial services. Covered entities would be required submit CIRCIA reports through the CIRCIA Incident Reporting Form available on CISA’s website or in any other manner approved by CISA’s director.

Cyber incidents that must be reported include denial-of-service attacks that render a cover entity’s services unavailable to customers for an extended period of time, cyberattacks that encrypt one of the entity’s core business systems or information systems, unauthorized access to an entity’s business systems caused by tampered software or compromised credentials, and ransomware attacks that lock an entity out of its industrial control systems. Reports must include contact information for the entity, a description of the affected systems, the effects on the entity’s operations, and more. Ransomware payment reports must include the data and amount of the payment, among other things.

Tags: RansomwareReporting
ShareTweetPin

Related Posts

ABA unveils key policy priorities for 2025

Senate Banking Committee postpones vote on crypto market structure bill

Newsbytes
January 14, 2026

Senate Banking Committee Chairman Tim Scott (R-S.C.) delayed a scheduled committee vote on cryptocurrency market structure legislation. More than 10,000 bankers have sent letters to Senate offices in recent days calling on Congress to use the bill to...

FHFA to create affordable housing advisory committee

HUD proposes to remove disparate impact from Fair Housing Act rule

Compliance and Risk
January 14, 2026

The Department of Housing and Urban Development is proposing to rescind three rules allowing the use of disparate impact in determining Fair Housing Act violations.

Business inventories rise in February

Business inventories rose in October

Economy
January 14, 2026

Business inventories in October 2025 came in at $2.68 trillion, up 0.3% from the month prior and up 1.1% from a year ago, the Commerce Department said.

Producer price index increased 0.5% in April

Producer prices rose in November

Economy
January 14, 2026

The Producer Price Index for final demand increased 0.2% in November, seasonally adjusted, the U.S. Bureau of Labor Statistics reported. Final demand prices edged up 0.1% in October and advanced 0.6% in September. On an unadjusted basis, the...

Poll: Small businesses remain optimistic amid economic uncertainty

NFIB: Small business optimism rose in December

Economy
January 14, 2026

The NFIB Small Business Optimism Index rose 0.5 points in December to 99.5 and remained above its 52-year average of 98, according to the National Federation of Independent Business. The Uncertainty Index fell seven points from November to...

Financial Stability Board releases 2025 G-SIB list

Beige Book: Economic activity inched up at end of 2025

Economy
January 14, 2026

Overall economic activity increased at a slight to modest pace in eight of the twelve Federal Reserve Districts in the final months of 2025, with banking conditions reported as stable or improving, the Fed said in its first...

NEWSBYTES

Senate Banking Committee postpones vote on crypto market structure bill

January 14, 2026

HUD proposes to remove disparate impact from Fair Housing Act rule

January 14, 2026

Business inventories rose in October

January 14, 2026

SPONSORED CONTENT

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

November 1, 2025
5 FedNow®  Service Developments You May Have Missed

5 FedNow® Service Developments You May Have Missed

October 31, 2025

Cash, Security, and Resilience in a Digital-First Economy

October 20, 2025
Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

October 1, 2025

PODCASTS

Podcast: The incredible shrinking penny (circulation)

January 8, 2026

Podcast: Cybersecurity in a mobile-first banking landscape

December 18, 2025

Podcast: The 2026 outlook for bank M&A

December 11, 2025

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.