Skip to main content

NCUA Board Meeting Coverage: NCUA Approves New Cyber Incident Reporting Rule

02/16/2023 CUToday

ALEXANDRIA, Va.–By a 3-0 vote, the NCUA board has approved a final rule on cyber incident reporting for federally insured credit unions.

The rule requires credit unions to inform NCUA of any “reportable” incident within 72 hours. Such incidents are those where the credit union “reasonably believes” a cyber incident has occurred, with such events defined as those in which the integrity, confidentiality or availability of information has been compromised.

The rule is to go into effect on Sept. 1, 2023.

thumbnail_NCUA Harper at Meeting

Todd Harper

The NCUA board was updated on the rule by Kelly Lay, director of the Office of Examination and Insurance, and Christina Saari, information systems officer in the same office. Both said credit unions had been strongly supportive of such rulemaking in their comment letters.

Harper: Issue ‘Keeps Me Up at Night’

NCUA Chairman Todd Harper, who said cybersecurity “is an issue that often keeps me up at night,” noted the final rule is largely unchanged from the proposed rule approved last July.

“Through these high-level early warning notifications, the NCUA will be able to work with other agencies and the private sector to respond to cyber threats before they become systemic and threaten the broader financial services sector,” said Harper. “This final rule will also align the NCUA’s reporting requirements with those of the federal banking agencies and the Cyber Incident Reporting for Critical Infrastructure Act.”

Harper, who credited Vice Chairman Kyle Hauptman for his suggestion the final rule include language noting NCUA will coordinate with the Cybersecurity and Infrastructure Security Agency on any future credit union cyber incident reporting requirements to avoid duplicative reporting to both agencies, said everyone in the financial system has an obligation to protect the nation’s economic and financial infrastructure. “And, credit unions must be included in conversations about critical infrastructure, as a whole. This final rule will facilitate such dialogue.”

Harper said the final rule is one of several actions NCUA has recently taken to improve the system’s cyber resiliency, including its earlier launch of the Information Security Examination program (ISE).

‘Fix This Blind Spot’

“While the cyber incident notification final rule and ISE will help in the fight against cyberattacks, we still must confront the regulatory blind spot that continues to exist because the NCUA lacks authority — the same authority that banking regulators have — to exercise a risk- based approach to supervise third-party vendors,” said Harper.

thumbnail_NCUA Hauptman at Meeting

Kyle Hauptman

NCUA has lost several bids in Congress to obtain that supervision authority.

“Unfortunately, cyber risk in the credit union system often lurks in the ether — beyond the NCUA’s purview — within credit union service organizations and third-party service providers that do not have the same level of oversight as bank vendors,” Harper continued. “As a result, thousands of credit unions, tens of millions of consumers who use credit unions, and roughly $2 trillion in assets are exposed to potentially devastating risks. The Government Accountability Office, the Financial Stability Oversight Council, and the NCUA’s Inspector General have all recommended congressional action to fix this blind spot.”

In response to a question from Harper on the guidance and training that will be made available, agency staff said both will be provided, including scenarios for when a notification is needed and when it is not.

Hauptman: Plan is to Coordinate With CISA

Like Harper, Hauptman called cyber security and incident reporting “critically important,” and said the sooner the agency is aware of an incident, the sooner it can determine whether it is isolated or widespread.

“Today’s rule is about reporting to NCUA only. NCUA is issuing its rule now, rather than waiting until 2025 when the Cybersecurity and Infrastructure Security Agency (CISA) will release its final rule,” said Hauptman. “The board believes it is in the best interest of the credit union system to align the NCUA’s rule with the Cyber Incident Reporting Act to provide uniform and timely cyber incident reporting. It is our intention to coordinate with CISA on any future credit union cyber incident reporting to avoid duplicate reporting to both the NCUA and CISA.”

thumbnail_NCUA Meeting Hood

Rodney Hood

In his remarks, Hauptman also noted:

  • Requirements on notifying credit union members and the public are unchanged
  • Credit unions are being asked to report as soon as possible and not later than 72 hours after the credit union reasonably believes an incident has occurred. The timeframe of 72 hours is consistent with what CISA will require in 2025
  • Credit unions are not required to provide a detailed incident assessment to the NCUA within the 72-hour time frame
  • NCUA will not publicize the name of credit unions that report cyber incidents.

Hood: ‘The Risk is a Moving Target’

Noting the time the agency has invested focusing on cybersecurity, NCUA Board Member Rodney Hood added, “I wish we could say that after having focused on this threat for such a long time, we are making progress toward a real sustainable solution, but unfortunately that's simply not the case given the velocity and evolution of cybersecurity threats.  As such, we have to accept that cybersecurity threats are an ongoing risk both to financial institutions’ operations and to their reputations.  Moreover, we have to accept that the risk is a moving target.”

Hood said every CU must recognize that their institution is “just one wrong email or malicious link away from being on the front pages. Given those realities, even those of us who favor a more balanced approach to regulatory matters, we must recognize that the agency's cybersecurity review and supervision capabilities need to be more robust.”

A Patch is No Patch

He further said credit unions can no longer count on vendors to provide a “patch” to address vulnerabilities and then move on, and must instead “rethink” their defenses.

In response to a question from Hood over what responsibilities CUs have related to cyber-incidents ahead of the Sept. 1 implementation of the new rule, staff said rules are in place requiring such reporting.

Comments

Popular posts from this blog

NCUA Board briefed on four topics

The NCUA Board heard briefings on four topics during its meeting Thursday, including the status of the deregulation initiative, a clarification regarding existing rules applicable to brokered and reciprocal deposit arrangements, and the agency’s 2026-2030 Strategic Plan and 2026 Annual Performance Plan.   Acting Director of the Office of Examination and Insurance Amanda Parkhill provided an overview of Phase 1 of the agency’s Deregulation Project, which focuses on targeted, technical changes to remove outdated or unnecessary requirements and improve clarity. The agency made it clear that the effort will likely continue into late 2026 or early 2027, evolving over time based on policy priorities and stakeholder input.   NCUA General Counsel Frank Kressman briefed the board on brokered and reciprocal deposit arrangements and the NCUA’s FAQs on this topic. The briefing demonstrated how a brokered deposit network operates with respect to low-income designated (LID) FICUs ...

How Your Bank/Credit Union Can Fight ‘Soft Switching’ — and Even Steal a Few Accounts of Your Own

Your Members Aren't Leaving in a Huff, They're Just Fading Away. Here's How to Stop It. “Soft switching” is picking up as Americans’ financial activity continues to fragment among multiple players, according to new research from JD Power. This trend has implications both for banks and credit unions that want to retain and grow existing relationships, as well as those that would also like to expand by snapping up accounts from other institutions. Key risk:  Once someone establishes a relationship with another provider, their one-time primary financial institution risks slipping into second place — or even losing the relationship entirely. Need to Know: The average checking account customer now has three deposit accounts at different institutions, the study found. One out of five consumers moved money away from their primary financial institution in the past three months, according to the study, an increase over the 17% rate seen in the previous edition. Departures aren’t sud...

Sunday Reading - Landmine Rat Honored

  Landmine Rat Honored   Cambodia unveiled the world’s first statue honoring a landmine-detecting rat (w/photo) Friday. Magawa the rat lived to 8 years old and identified more than 100 landmines and other explosives from 2016 to 2021.  There are more than 100 African pouched rats deployed in landmine detection operations across the world. To identify mines, the rats are trained to sniff out explosive compounds like trinitrotoluene, or TNT. (The rats are not heavy enough to trigger detonation.) In Cambodia, up to 6 million landmines remain undiscovered, most planted during three decades of conflict, from the Vietnam War era through Cambodia's civil war . Since 1979, roughly 20,000 people have been killed in Cambodia, and roughly 40,000 wounded as a result of the mines. Magawa cleared more than ...

The Case for Sharing a CEO Between Credit Unions

  Embracing Collaboration: The Case for Sharing a CEO Between Credit Unions In recent years, credit unions have faced numerous challenges, from regulatory pressures to evolving member expectations. As many seasoned leaders retire, smaller credit unions often find themselves at a turning point. In this landscape, one innovative solution is gaining traction: sharing a CEO between two credit unions. This approach not only addresses financial constraints but also fosters collaboration and enhances service delivery. The Rationale Behind Sharing a CEO 1. Financial Sustainability One of the most pressing concerns for small credit unions is maintaining financial health amid rising operational costs. A shared CEO model alleviates the financial burden of hiring and compensating a full-time executive. By splitting salary and benefits, both credit unions can allocate resources more effectively, allowing for investment in member services, technology, and community initiatives. ...

The Unique Challenges, Opportunities for CUs in Attracting & Retaining Top Talent

Affinity FCU shares the details of its strategies, including a comprehensive benefits program. By Pam Cohen | September 09, 2024 at 09:00 AM Credit/AdobeStock Attracting and retaining top talent is an ongoing challenge for many organizations, but credit unions face a unique set of obstacles. Unlike larger financial institutions, credit unions often operate with resource constraints and have less brand recognition, which can make it difficult to compete for top-tier talent. Despite these challenges, credit unions have unique strengths that can be leveraged to attract individuals who value a strong sense of community and a supportive work environment. Being Innovative When Growing Talent At Affinity Federal Credit Union, we have implemented several innovative strategies to attract and retain top talent. One key approach is our comprehensive benefits program, which emphasize...

Open Banking Pushes Leading Credit Unions Ahead In Race For Member Loyalty

  https://youtu.be/pUIV8hwSDCE NEW YORK—Credit unions that embrace open banking aren’t just keeping pace with competitors—they’re pulling ahead, new data show. A new report finds that innovation in digital tools and personalized experiences is emerging as the decisive factor separating credit unions that win lasting member loyalty from those at risk of losing ground. “ The 2025 Credit Union Innovation Readiness Index: Closing Gaps, Winning Members ,” a June report produced in collaboration between  Velera  and PYMNTS Intelligence, underscores innovation as a defining factor for credit union success. iStock-Korakrich Suntornnites “Facing shifting expectations from both consumers and small to medium-sized businesses (SMBs) toward digital convenience and tailored experiences, credit unions must modernize not just to compete with traditional banks, but to remain relevant to their members. The report, based surveys of 500 credit union executives, 15,000 U.S. consumers, and nea...

With Inflation High and Rates Rising, LAFCU Introduces New Adjustable Rate Mortgage

 LANSING, Mich. — As inflation remains high and the Fed continues to push up rates, Lansing Area FCU (LAFCU) has introduced a 10/6 adjustable-rate mortgage (ARM). In announcing the new offering, the $970-million credit union noted ARMs were a hallmark of the 1980s inflationary period and the mid-2000s mortgage crisis, and the product is now making a “comeback.” The loan has a fixed rate of interest for the first 10 years of the loan, after which it adjusts once every six months over the remaining 20 years. The terms apply to both new and refinanced mortgages. The Stanton familiy in their new home. “LAFCU’s 10/6 ARM loan is a low-cost ...

Loan Growth Part 3

MADISON, Wis.–Credit union loan balances rose 1.1% in February, faster than the 0.2% reported in February 2021, even as membership growth slowed significantly during the first two months of 2022, according to data released as part of CUNA Mutual’s April Trends Report. The Report, which is based on data through February, showed overall loan growth was 9.6% during the last 12 months. What is actually happening below the surface? According to the Trends Report, consistent with the trend line the analysis shows large credit unions reported significantly faster loan growth in 2021 as compared to smaller credit unions. Credit unions with assets greater than $1 billion reported loan growth of 8.4% compared to credit unions with assets less than $20 million, reporting loan growth of 0.9%. Here's a look at how credit unions performed by category, according to the newest Trends Report” ...

Meet Spokane Firefighter Credit Union (SFCU) New President/CEO - Troy Clute

Meet SFCU's New President/CEO - Troy Clute  Troy Clute serves as the President and Chief Executive Officer of Spokane Firefighters Credit Union, bringing 29 years of experience in banking and finance. His career includes extensive leadership roles across the industry, with a strong foundation in consumer lending and member-focused financial services. Troy is a graduate of the renowned CUES CEO Institute Program, having earned the Certified Chief Executive (CCE) designation—one of the highest leadership credentials in the credit union movement. His leadership is defined by strategic vision, operational excellence, and a deep commitment to serving Spokane’s firefighter community and their families. Beyond his professional role, Troy values family above all. He and his wife, Karri, have been married for 36 years and share two grown children, Kellen and Kennadie, as well as three grandchildren—Tyus, Izze, and Major—who keep life joyful and full of adventure. When he’s not leading the c...

The impact of recent bank failures could impact credit unions.

The failures of Silicon Valley Bank (SVB) and Signature Bank, combined with the FDIC’s decision to cover all depositors could have an impact on credit unions. With over 93% of their deposits uninsured, SVB appears to be the poster child for poor strategic planning. The bank got caught short when the Fed raised rates. For credit unions, the real story is the decision to cover ALL accounts regardless of the amount in the account. Where is the threat to credit unions? Credit unions had no role in the failures of SVB and Signature Bank. The threat lies in the Treasury and FDIC’s decision to guarantee the funds in every account…no matter how much was in that account. While the Treasury Secretary and FDIC Chairman Gruenberg may have felt the need to do so to restore confidence, this action just kicks the can down the road. And the road will have no end if NCUA feels the pressure to do the same thing if a similar situation hits the credit union movement. Should there be a conservatorship or...