Home / Blog / Cybersecurity
April 1, 2022 by Christopher Salone
In the final quarter of 2021, the Federal Deposit Insurance Corporation (FDIC), the Board of Governors of the Federal Reserve System, and the Office of the Comptroller of the Currency (the agencies), issued a rule requiring any FDIC insured financial institution to notify its primary Federal regulator of any ‘‘computer-security incident’’ that rises to the level of a ‘‘notification incident.’’ The Federal regulator must be notified as soon as possible and no later than 36 hours after the banking organization determines that a notification incident has occurred. The final rule also requires a bank service provider to inform each affected banking organization customer as soon as possible when the bank service provider determines that it has experienced a computer-security incident that has caused, or is reasonably likely to cause, a material service disruption or degradation for four or more hours. Banks and their service providers must comply with the Final Rule starting May 1, 2022.
In the rule, the agencies define a “computer-security incident” as
When a computer-security incident has occurred and has risen to the level of a “notification incident,” formal communication to the Bank’s primary Federal regulator must occur. In the rule, a “notification incident” is defined as
In the final rule, the agencies provide several examples of “notification incidents,” some of which include:
FDIC-supervised banks can comply with the rule by reporting an incident to their “case manager,” who serves as the primary FDIC contact for all supervisory-related matters, or to any member of an FDIC examination team if the event occurs during an examination. If a bank is unable to access its supervisory team contacts, the bank may notify the FDIC by email at: incident@fdic.gov.
FDIC Insured Banks should, as soon as practical, review the rule (embedded below) and assess the needed changes to the following:
FoxPointe Solutions, a division of The Bonadio Group, is equipped and prepared to help your organization prepare for these requirements. We would be happy to answer any questions you may have or provide you with additional information. Reach out today.