ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Proposed rule to require reporting of cyberattacks, ransomware payments

March 28, 2024
Reading Time: 2 mins read
Cybersecurity: What threat-ready really means for banks

The Cybersecurity and Infrastructure Security Agency—part of the Department of Homeland Security—today announced a notice of proposed rulemaking to implement a 2022 law requiring financial institutions and other “critical infrastructure” businesses to report cyber incidents and ransomware payments to the department and agency.

Under the proposal, regulated financial institutions and other critical infrastructure sectors would be required to report to DHS or CISA significant cyber incidents within 72 hours as well as any ransomware payments within 24 hours. They would also be required to “promptly” fill supplemental reports if “substantial new or different information” becomes available about the incident. The reporting requirements are in addition to existing computer security incident notifications that are required to be made to financial regulators within 36 hours and a new Securities and Exchange Commission requirement for publicly traded companies to report significant cyber incidents to the public within four business days.

The proposed 450-page rulemaking by CISA would implement the Cyber Incident Reporting for Critical Infrastructure Act, or CIRCIA, of 2022, which establishes reporting requirements for several sectors of the economy, including financial services. Covered entities would be required submit CIRCIA reports through the CIRCIA Incident Reporting Form available on CISA’s website or in any other manner approved by CISA’s director.

Cyber incidents that must be reported include denial-of-service attacks that render a cover entity’s services unavailable to customers for an extended period of time, cyberattacks that encrypt one of the entity’s core business systems or information systems, unauthorized access to an entity’s business systems caused by tampered software or compromised credentials, and ransomware attacks that lock an entity out of its industrial control systems. Reports must include contact information for the entity, a description of the affected systems, the effects on the entity’s operations, and more. Ransomware payment reports must include the data and amount of the payment, among other things.

Tags: RansomwareReporting
ShareTweetPin

Related Posts

CFPB claims ‘complex’ pricing drives up cost of financial products

Trump nominates Johnson to lead CFPB

Compliance and Risk
June 10, 2026

President Trump nominated bank executive Brian Johnson to lead the CFPB, which has been without a full-time leader since the firing of Rohit Chopra last year.

ABA, BPI urge cross-regulator ‘no-action’ letters for AML/BSA innovations

ABA backs proposed overhaul of BSA program rule

Compliance and Risk
June 10, 2026

ABA said it strongly supports the shift toward risk-based compliance in a proposed overhaul of the Bank Secrecy Act program rule.

Survey: Banks boosting cybersecurity due to AI while also investing in technology

Financial Stability Board releases ‘sound practices’ for AI adoption

Compliance and Risk
June 10, 2026

The Financial Stability Board has released a draft list of 12 sound practices to guide the adoption of artificial intelligence by banks and other financial institutions.

FATF updates list of jurisdictions with anti-money laundering deficiencies

ABA urges regulators to uphold AML/CFT, sanctions requirements for all stablecoin issuers

Compliance and Risk
June 10, 2026

As federal regulators draft anti-money laundering and sanctions regulations for payment stablecoin issuers, they need to address the financial crime risks posed by secondary market payment stablecoin activities, ABA said.

OCC’s Hsu suggests requiring banks, AI companies to reimburse customers for fraud

ABA Fraudcast: The challenge of synthetic identity

Compliance and Risk
June 10, 2026

A longtime leader in the fight against fraud describes one effective addition to the banking industry’s commitment to innovation: partnership.

ABA raises concerns with draft tax form

ABA seeks further revisions to draft W-9 tax form

Newsbytes
June 9, 2026

ABA said that while it appreciates the IRS incorporating its recommendations into the proposed revisions to W-9 tax forms, the association still has significant concerns about some of the instructions for completing the form.

NEWSBYTES

Trump nominates Johnson to lead CFPB

June 10, 2026

ABA backs proposed overhaul of BSA program rule

June 10, 2026

Financial Stability Board releases ‘sound practices’ for AI adoption

June 10, 2026

SPONSORED CONTENT

Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

June 1, 2026
A Modern Blueprint for Serving High-Net-Worth Families

A Modern Blueprint for Serving High-Net-Worth Families

May 28, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

AI Is in Your Bank. Is Your Cloud Contract Governing It?

May 20, 2026
Credit Memos at the Convergence Point

Credit Memos at the Convergence Point

May 1, 2026

PODCASTS

Podcast: Creating a feeling of welcome, for customers and new bankers

May 28, 2026

Podcast: How consumer deposits drive full relationship banking

May 14, 2026

Podcast: How an Ohio banker talks with policymakers about stablecoin issues

May 6, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.