HomeSecurityUSA: Banks must report security incidents within 36...

US: Banks must report security incidents within 36 hours

The US Federal Reserve has approved a new rule that requires banks to report significant security incidents (cyberattacks) within 36 hours .

See also: SharkBot: The new Android banking trojan targeting banks in Europe

banks security incidents
US: Banks must report security incidents within 36 hours

Banks are required to report significant cyberattacks only if their operations, ability to provide banking products and services, or the stability of the U.S. financial sector have been or may be affected.

Banking service providers will also have to notify customers “as soon as possible” if a cyberattack has materially affected or is likely to affect customers for four or more hours.

Examples of incidents that banks must report include: large distributed denial of service attacks that prevent access to banking services or hacking incidents that affect banking operations for long periods of time.

See also: 9 people were arrested for impersonating bank employees

Security incidents can result from malicious software (cyberattacks), as well as non-malicious hardware and software failure, personnel errors, and other causes,” explains the Computer-Security Incident Notification Final Rule (PDF).

cyberattacks
US: Banks must report security incidents within 36 hours

Cyberattacks targeting the financial services industry have increased in frequency and severity in recent years. These cyberattacks can negatively impact banking organizations’ networks, data, and systems, and ultimately their ability to continue operating as normal.“.

Banks must report security incidents from May 2022

The final rule issued by the Federal Deposit Insurance Corporation (FDIC), the Board of Governors of the Federal Reserve System (Board), and the Office of the Comptroller of the Currency (OCC) will take effect on April 1, 2022. Banks will be required to comply and report cyberattacks and other security incidents starting May 1, 2022.

See also: Ransomware: It's a black hole that sucks in other cyber threats

The new cyberattack reporting law is designed to raise awareness among banking regulators about emerging threats to banking organizations and the broader U.S. financial system.

This in turn will allow regulators to react to these attacks before they spread further.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS