Home / Blog / Cybersecurity
July 29, 2022 by Christopher Salone
The NCUA has proposed a new Cyber Incident Reporting Rule. This proposal comes on the heels of the Federal Banking Agencies Incident Reporting Rule that went into effect earlier this year.
The proposed NCUA regulation would require federally charted credit unions (also applies to state-chartered, federally insured credit unions) to report within 72 hours any incident that leads to the “substantial loss” of confidentiality, integrity or availability of member information. A cyberattack causing a disruption of business operations would also come under the umbrella of reportable events. So would the compromise of sensitive data or business operations resulting from an incident experienced by a third-party service provider.
According to the proposal, some examples of a “reportable cyber incident” include:
While the proposal calls for a 72-hour window for incident reporting, the NCUA is asking for industry comment, specifically on if the reporting requirement should be shortened to the current banking standard of 36 hours.
FoxPointe will continue to monitor the proposed rule and send updates with any changes. If you have any questions, we would be happy to have a discussion on this new proposal or any other cybersecurity related topics.