ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Proposed rule to require reporting of cyberattacks, ransomware payments

March 28, 2024
Reading Time: 2 mins read
Cybersecurity: What threat-ready really means for banks

The Cybersecurity and Infrastructure Security Agency—part of the Department of Homeland Security—today announced a notice of proposed rulemaking to implement a 2022 law requiring financial institutions and other “critical infrastructure” businesses to report cyber incidents and ransomware payments to the department and agency.

Under the proposal, regulated financial institutions and other critical infrastructure sectors would be required to report to DHS or CISA significant cyber incidents within 72 hours as well as any ransomware payments within 24 hours. They would also be required to “promptly” fill supplemental reports if “substantial new or different information” becomes available about the incident. The reporting requirements are in addition to existing computer security incident notifications that are required to be made to financial regulators within 36 hours and a new Securities and Exchange Commission requirement for publicly traded companies to report significant cyber incidents to the public within four business days.

The proposed 450-page rulemaking by CISA would implement the Cyber Incident Reporting for Critical Infrastructure Act, or CIRCIA, of 2022, which establishes reporting requirements for several sectors of the economy, including financial services. Covered entities would be required submit CIRCIA reports through the CIRCIA Incident Reporting Form available on CISA’s website or in any other manner approved by CISA’s director.

Cyber incidents that must be reported include denial-of-service attacks that render a cover entity’s services unavailable to customers for an extended period of time, cyberattacks that encrypt one of the entity’s core business systems or information systems, unauthorized access to an entity’s business systems caused by tampered software or compromised credentials, and ransomware attacks that lock an entity out of its industrial control systems. Reports must include contact information for the entity, a description of the affected systems, the effects on the entity’s operations, and more. Ransomware payment reports must include the data and amount of the payment, among other things.

Tags: RansomwareReporting
ShareTweetPin

Related Posts

Consumer Sentiment declined in April

Preliminary: Consumer sentiment fell in August

Economy
August 14, 2026

The University of Michigan Consumer Sentiment Index decreased 7.6% in August compared to the month prior, landing at 51, according to preliminary results for the month.

Bill would strengthen criminal penalties for ATM robberies

State attorneys general express support for ATM crime bill

Compliance and Risk
August 14, 2026

Fifteen state attorneys general urged Congress to pass legislation ensuring that robberies of off-site ATMs carry the same legal consequences as bank robberies. ABA also supports the bill.

ABA urges ‘same risk, same regulation’ for digital assets

ABA urges federal regulation of AI, level playing field for financial services

Compliance and Risk
August 14, 2026

Congress should establish a nationally harmonized, risk-based framework for regulating artificial intelligence in the financial services sector, which would preempt state laws while assuring strong consumer protection and cybersecurity outcomes, ABA told House Financial Services Committee members.

ABA: Proposed quality control rule for AVMs would overburden banks

ABA DataBank: Consumers tap home equity as housing values rise

Economy
August 14, 2026

Total home equity lines of credit (HELOC) reached $446 billion in Q1 2026, up 35.3% since hitting a trough in Q1 2022.

CFPB claims ‘complex’ pricing drives up cost of financial products

CFPB ends publication of consumer complaint narratives

Compliance and Risk
August 14, 2026

The CFPB will cease publication of unverified complaint narratives and visualizations, arguing the utility of publicizing narratives is minimal “while often causing confusion and providing misleading data.”

OCC to merge community bank, large bank supervision departments

OCC releases 2026 update to Bank Accounting Advisory Series

Compliance and Risk
August 14, 2026

The BAAS contains OCC staff responses to frequently asked questions from the banking industry and bank examiners on a variety of accounting topics.

NEWSBYTES

Preliminary: Consumer sentiment fell in August

August 14, 2026

State attorneys general express support for ATM crime bill

August 14, 2026

ABA urges federal regulation of AI, level playing field for financial services

August 14, 2026

SPONSORED CONTENT

Beyond Surveillance: Rethinking Security for Modern Financial Institutions

Beyond Surveillance: Rethinking Security for Modern Financial Institutions

August 12, 2026
Relationship Banking at Scale: Why Banks Need The Digital Sales & Service Platform

Relationship Banking at Scale: Why Banks Need The Digital Sales & Service Platform

August 1, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

Examiners Are Now Looking at Your Non-Core Systems

June 11, 2026
Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

June 1, 2026

PODCASTS

Podcast: Banking the brave new world of college athletics

August 4, 2026

Podcast: Tactics for meaningful strategic planning

July 28, 2026

Podcast: Why it might be time to revisit a key FDIC ratio

July 23, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.