Skip to main content

NCUA Board Meeting Coverage: NCUA Approves New Cyber Incident Reporting Rule

02/16/2023 CUToday

ALEXANDRIA, Va.–By a 3-0 vote, the NCUA board has approved a final rule on cyber incident reporting for federally insured credit unions.

The rule requires credit unions to inform NCUA of any “reportable” incident within 72 hours. Such incidents are those where the credit union “reasonably believes” a cyber incident has occurred, with such events defined as those in which the integrity, confidentiality or availability of information has been compromised.

The rule is to go into effect on Sept. 1, 2023.

thumbnail_NCUA Harper at Meeting

Todd Harper

The NCUA board was updated on the rule by Kelly Lay, director of the Office of Examination and Insurance, and Christina Saari, information systems officer in the same office. Both said credit unions had been strongly supportive of such rulemaking in their comment letters.

Harper: Issue ‘Keeps Me Up at Night’

NCUA Chairman Todd Harper, who said cybersecurity “is an issue that often keeps me up at night,” noted the final rule is largely unchanged from the proposed rule approved last July.

“Through these high-level early warning notifications, the NCUA will be able to work with other agencies and the private sector to respond to cyber threats before they become systemic and threaten the broader financial services sector,” said Harper. “This final rule will also align the NCUA’s reporting requirements with those of the federal banking agencies and the Cyber Incident Reporting for Critical Infrastructure Act.”

Harper, who credited Vice Chairman Kyle Hauptman for his suggestion the final rule include language noting NCUA will coordinate with the Cybersecurity and Infrastructure Security Agency on any future credit union cyber incident reporting requirements to avoid duplicative reporting to both agencies, said everyone in the financial system has an obligation to protect the nation’s economic and financial infrastructure. “And, credit unions must be included in conversations about critical infrastructure, as a whole. This final rule will facilitate such dialogue.”

Harper said the final rule is one of several actions NCUA has recently taken to improve the system’s cyber resiliency, including its earlier launch of the Information Security Examination program (ISE).

‘Fix This Blind Spot’

“While the cyber incident notification final rule and ISE will help in the fight against cyberattacks, we still must confront the regulatory blind spot that continues to exist because the NCUA lacks authority — the same authority that banking regulators have — to exercise a risk- based approach to supervise third-party vendors,” said Harper.

thumbnail_NCUA Hauptman at Meeting

Kyle Hauptman

NCUA has lost several bids in Congress to obtain that supervision authority.

“Unfortunately, cyber risk in the credit union system often lurks in the ether — beyond the NCUA’s purview — within credit union service organizations and third-party service providers that do not have the same level of oversight as bank vendors,” Harper continued. “As a result, thousands of credit unions, tens of millions of consumers who use credit unions, and roughly $2 trillion in assets are exposed to potentially devastating risks. The Government Accountability Office, the Financial Stability Oversight Council, and the NCUA’s Inspector General have all recommended congressional action to fix this blind spot.”

In response to a question from Harper on the guidance and training that will be made available, agency staff said both will be provided, including scenarios for when a notification is needed and when it is not.

Hauptman: Plan is to Coordinate With CISA

Like Harper, Hauptman called cyber security and incident reporting “critically important,” and said the sooner the agency is aware of an incident, the sooner it can determine whether it is isolated or widespread.

“Today’s rule is about reporting to NCUA only. NCUA is issuing its rule now, rather than waiting until 2025 when the Cybersecurity and Infrastructure Security Agency (CISA) will release its final rule,” said Hauptman. “The board believes it is in the best interest of the credit union system to align the NCUA’s rule with the Cyber Incident Reporting Act to provide uniform and timely cyber incident reporting. It is our intention to coordinate with CISA on any future credit union cyber incident reporting to avoid duplicate reporting to both the NCUA and CISA.”

thumbnail_NCUA Meeting Hood

Rodney Hood

In his remarks, Hauptman also noted:

  • Requirements on notifying credit union members and the public are unchanged
  • Credit unions are being asked to report as soon as possible and not later than 72 hours after the credit union reasonably believes an incident has occurred. The timeframe of 72 hours is consistent with what CISA will require in 2025
  • Credit unions are not required to provide a detailed incident assessment to the NCUA within the 72-hour time frame
  • NCUA will not publicize the name of credit unions that report cyber incidents.

Hood: ‘The Risk is a Moving Target’

Noting the time the agency has invested focusing on cybersecurity, NCUA Board Member Rodney Hood added, “I wish we could say that after having focused on this threat for such a long time, we are making progress toward a real sustainable solution, but unfortunately that's simply not the case given the velocity and evolution of cybersecurity threats.  As such, we have to accept that cybersecurity threats are an ongoing risk both to financial institutions’ operations and to their reputations.  Moreover, we have to accept that the risk is a moving target.”

Hood said every CU must recognize that their institution is “just one wrong email or malicious link away from being on the front pages. Given those realities, even those of us who favor a more balanced approach to regulatory matters, we must recognize that the agency's cybersecurity review and supervision capabilities need to be more robust.”

A Patch is No Patch

He further said credit unions can no longer count on vendors to provide a “patch” to address vulnerabilities and then move on, and must instead “rethink” their defenses.

In response to a question from Hood over what responsibilities CUs have related to cyber-incidents ahead of the Sept. 1 implementation of the new rule, staff said rules are in place requiring such reporting.

Comments

Popular posts from this blog

The Federal Reserve decided to maintain the target range for the federal funds rate at 3-1/2 to 3-3/4

  Federal Reserve issues FOMC statement For release at 2:00 p.m. EDT Share The Federal Open Market Committee approved the following statement for release by a 9 – 3 vote: The Committee decided to maintain the target range for the federal funds rate at 3-1/2 to 3-3/4 percent, in support of the Federal Reserve's dual mandate. The Committee is continuing its policy of maintaining ample reserves in the banking system. Economic activity is expanding at a solid pace despite elevated uncertainty that owes, in part, to the conflict in the Middle East. Productivity growth and capital investment are strong. Job gains have kept pace with the workforce, and the unemployment rate has changed little. Inflation remains elevated relative to the Committee's 2 percent goal, in part reflecting supply shocks that have driven price increases in certain sectors, including energy. The Committee will deliver price stability.   Voting against the monetary policy action were Beth M. Hammack, Neel Kashk...

2026 Volunteer of the Year Award

  www.ncofcu.org/voy ================================================= Remember, you're not alone with NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional features: Advocacy   Annual Conference First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's

Sunday Reading - The Fab Four (Beatles)

  The Fab Four   The Beatles were a 20th-century British band credited with innovating the sound of popular music and, in the process, helping to legitimize rock 'n' roll as an art form. > How the Beatles became the most influential band on Earth. ( More , w/podcast) > Explore Abbey Road Studios, the site of the first ever stereo recordings and home to most of the Beatles' songs. ( More ) The intense fandom for the band, called Beatlemania, began in the United Kingdom in 1963 but did not initially translate into success in the United States. In fact, the band's American label rejected the band's first two singles. Eventually, the band gained tra...

Making the Most of the Final Five Years Before Retirement

  NATIONAL COUNCIL OF FIRST RESPONDER CREDIT UNIONS RETIREMENT READINESS Making the Most of the Final Five Years Before Retirement A practical planning guide for first responders, credit union volunteers, employees, and their families Five years before retirement is an important checkpoint. It is the time to confirm what you have saved, understand the income you can expect, and decide whether your retirement plans match the life you want to lead.   1. Review Your Retirement Savings Start by taking a fresh look at your retirement accounts, personal savings, investments, and other assets. A retirement calculator can help estimate whether you are on track and show how additional saving during the next five years may strengthen your plan.   2. Identify Every Source of Retirement Income List the income you may receive in retirement, including pensions, Social Security, retirement-plan withdrawals, invest...

Insurance Companies turn to private firefighters to cover their policy holders.

By Lyle Adriano Business Insurance Some insurers, like Chubb, are going the extra mile for select policyholders by sending in private firefighters to deal with wildfire threats before they become a problem. Insurer-provided wildfire mitigation services, while nothing new, has been making waves lately following the recent California fires. The extra service is getting so popular, that homeowners who had witnessed their neighbors’ homes being protected by private firefighters were inspired to purchase their own policies to enjoy the same benefits, some insurers said. “The enrolment has taken off dramatically over the years as people have seen us save homes,” Chubb senior executive Paul Krump told The Wall Street Journal . “It’s absolutely growing leaps and bounds.” Dick Fredericks, founding partner of Main Management Fund Advisors LLC in San Francisco and a former US ambassador to Switzerland and Liechtenstein, was one of the fortunate homeowners in Sonoma whose properties were...

Syracuse Fire Department Credit Union assists in making some happy holiday memories for needy kids.

Syracuse, N.Y. -  Firefighters were among the first to arrive on the scene when a 2-year-old girl was killed while playing with chalk on the sidewalk this summer. The girl's brother was also injured while another sibling watched it all happen. Saturday, the surviving siblings will be doing their Christmas shopping at Destiny USA with some Syracuse firefighters. "We saw them on the worst day of their lives. Now is an opportunity to make some happy memories," said Syracuse Fire Department District Chief John Kane. Nothing will erase the pain and loss the family feels. And nothing will erase the memories firefighters have of trying to save a child who was terribly injured. "It's a little something," Kane said. "Especially this time of year." The holiday shopping trips began five years ago, an idea of Syracuse Police Chief Frank Fowler. Syracuse police Officer Dennis Burlingame organized the event, and invited the fire department...

Report Probes Just How Sophisticated and Pervasive Fraud Has Become

BOSTON–Fraud threats facing credit unions are becoming more sophisticated and pervasive as digital banking expands and artificial intelligence tools enable increasingly complex attacks, according to new research and analysis from PYMNTS Intelligence .  The report said fraud has evolved from isolated incidents into a “persistent, systemwide threat” that affects every stage of the member journey, from onboarding and authentication to transactions and account servicing.  According to the report, fraudsters are increasingly using coordinated, multichannel schemes that challenge traditional fraud detection and response systems. PYMNTS Intelligence said attackers are no longer exploiting single vulnerabilities but are instead orchestrating broader campaigns involving impersonation, credential theft and unauthorized transfers.  The Findings Among the report’s findings, according to PYMNTS: One in 10 consumers encountered card fraud during the past year. Most fraud incidents occu...

White Paper from WOCCU Examines How Stablecoins are Reshaping Financial Infrastructure

WASHINGTON– World Council of Credit Unions (WOCCU) has released a new white paper that examines how stablecoins are reshaping the financial infrastructure that credit unions and other cooperative financial institutions rely on to serve their members.  According to WOCCU, the white paper, How Digital Money Is Impacting Credit Unions, Part 1: Focus on Stablecoins , is the first in a planned three-part series exploring how emerging forms of digital money are affecting the global credit union movement.  “The report begins by noting that stablecoins are no longer a niche fintech development, but part of a broader structural shift in how money is stored, moved and regulated,” WOCCU explained. “As commercial banks, payment networks, technology firms and retailers build stablecoin offerings or integrate stablecoin rails into their platforms, credit unions must consider how these changes could affect deposits, payments, member relationships and long-term institutional relevance.” For ...

National Council of Firefighter Credit Unions Partners with OMNICOMMANDER.COM for ADA Compliant Website Design and Hosting

National Council of Firefighter Credit Unions Partners with OMNICOMMANDER .COM for ADA Compliant Website Design and Hosting "OMNICOMMANDER Services" A NCOFCU Business Partner & 2018 Seattle GOLD Sponsor About OMNICOMMANDER OMNICOMMANDER is a veteran owned and operated credit union website design, social media and marketing firm. With a focus on member experience, the company ensures that every touch-point has the exact same user interface. Along with incredible design, OMNICOMMANDER creates sites with built-in mobile responsiveness, SSL encryption while observing ADA guidelines on accessibility for disabled members. For more information, visit OMNICOMMANDER on LinkedIn , Twitter , Facebook , and Instagram . Firefighter Friendly Founder...

What Credit Unions Can—And Can't—Do With New Trump Accounts

07/02/2026 09:36 am         WASHINGTON--With Trump Accounts set to officially launch July 4, America’s Credit Unions updated its frequently asked questions document to clarify the role of credit unions now and in the future. Credit unions do not have a role to play yet, as the Treasury has not announced steps to transition accounts from initial provider BNY Mellon to other authorized institutions, ACU noted. Trump Accounts are tax-deferred accounts that can be established on behalf of a child under the age of 18. Account contributions begin after July 4, with contributions up to $5,000 a year allowed. Created by H.R. 1, the law also established a pilot program to deposit a one-time $1,000 grant into accounts of children born between Jan. 1, 2025 and Dec. 31, 2028. Once the child turns 18, the account funds are available for educational expenses, home ownership, entrepreneurship, and other designated purposes. Once guidance is available from Treasury, credit unions ...