Don’t do SECURITY. Do business SECURELY.

US bank computer-security incident notification rule compliance begins

US banks must now notify their regulator within 36 hours of a significant computer-security incident, and service providers must notify their bank customers.

Compliance with the Computer-Security Incident Notification Rule, issued jointly by the US federal banking agencies, is required from today.

Key points

  • Banking organisations must notify their primary federal regulator within 36 hours of determining that a “notification incident” has occurred.
  • Notification incidents are those that materially disrupt, or are reasonably likely to disrupt, operations, services or financial stability.
  • Bank service providers must notify affected bank customers as soon as possible after an incident causing material disruption for four hours or more.
  • The rule complements existing GLBA security standards.

UK technology and service providers to US banks should check that their contracts, monitoring and incident response procedures support rapid notification to their customers.

Source: Computer-Security Incident Notification Requirements final rule (Federal Register)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights