New rule requires US banks to report cyber incidents within 36 hours

From May next year, US banks will be required to notify regulators within 36 hours of any significant cyber incident that could threaten national financial systems, under new rules announced by the US Federal Reserve.

The final rule requires a banking organisation to notify its primary federal regulator of any significant computer security incident as soon as possible – and no later than 36 hours – after it determines that a cyber incident has occurred.

Notification is required for incidents that have, or are reasonably likely to, materially affect the viability of a bank's operations, its ability to deliver products and services, or the stability of the financial sector.

In addition, the final rule requires a bank service provider to notify affected customers as soon as possible when the provider determines that it has experienced a cyber incident that has, or is reasonably likely to, materially affect customers for four or more hours.

    Share Story:

YOU MIGHT ALSO LIKE

BANNER

Resilience Rooted in Reality
In this podcast, CIR speaks to CLDigital’s Tejas Katwala about why organisations must move beyond checklist compliance to build living, data driven resilience. He explains how rethinking governance, risk and compliance, breaking down silos and focusing on value streams can create sustainable, real time resilience that is rooted in the way businesses actually operate today.

Building cyber resilience in a complex threat landscape
Cyber threats are evolving faster than ever. This episode explores how organisations can strengthen defences, embed resilience, and navigate regulatory and human challenges in an increasingly complex digital environment.