Skip to main content

NCUA Board Meeting Coverage: NCUA Approves New Cyber Incident Reporting Rule

02/16/2023 CUToday

ALEXANDRIA, Va.–By a 3-0 vote, the NCUA board has approved a final rule on cyber incident reporting for federally insured credit unions.

The rule requires credit unions to inform NCUA of any “reportable” incident within 72 hours. Such incidents are those where the credit union “reasonably believes” a cyber incident has occurred, with such events defined as those in which the integrity, confidentiality or availability of information has been compromised.

The rule is to go into effect on Sept. 1, 2023.

thumbnail_NCUA Harper at Meeting

Todd Harper

The NCUA board was updated on the rule by Kelly Lay, director of the Office of Examination and Insurance, and Christina Saari, information systems officer in the same office. Both said credit unions had been strongly supportive of such rulemaking in their comment letters.

Harper: Issue ‘Keeps Me Up at Night’

NCUA Chairman Todd Harper, who said cybersecurity “is an issue that often keeps me up at night,” noted the final rule is largely unchanged from the proposed rule approved last July.

“Through these high-level early warning notifications, the NCUA will be able to work with other agencies and the private sector to respond to cyber threats before they become systemic and threaten the broader financial services sector,” said Harper. “This final rule will also align the NCUA’s reporting requirements with those of the federal banking agencies and the Cyber Incident Reporting for Critical Infrastructure Act.”

Harper, who credited Vice Chairman Kyle Hauptman for his suggestion the final rule include language noting NCUA will coordinate with the Cybersecurity and Infrastructure Security Agency on any future credit union cyber incident reporting requirements to avoid duplicative reporting to both agencies, said everyone in the financial system has an obligation to protect the nation’s economic and financial infrastructure. “And, credit unions must be included in conversations about critical infrastructure, as a whole. This final rule will facilitate such dialogue.”

Harper said the final rule is one of several actions NCUA has recently taken to improve the system’s cyber resiliency, including its earlier launch of the Information Security Examination program (ISE).

‘Fix This Blind Spot’

“While the cyber incident notification final rule and ISE will help in the fight against cyberattacks, we still must confront the regulatory blind spot that continues to exist because the NCUA lacks authority — the same authority that banking regulators have — to exercise a risk- based approach to supervise third-party vendors,” said Harper.

thumbnail_NCUA Hauptman at Meeting

Kyle Hauptman

NCUA has lost several bids in Congress to obtain that supervision authority.

“Unfortunately, cyber risk in the credit union system often lurks in the ether — beyond the NCUA’s purview — within credit union service organizations and third-party service providers that do not have the same level of oversight as bank vendors,” Harper continued. “As a result, thousands of credit unions, tens of millions of consumers who use credit unions, and roughly $2 trillion in assets are exposed to potentially devastating risks. The Government Accountability Office, the Financial Stability Oversight Council, and the NCUA’s Inspector General have all recommended congressional action to fix this blind spot.”

In response to a question from Harper on the guidance and training that will be made available, agency staff said both will be provided, including scenarios for when a notification is needed and when it is not.

Hauptman: Plan is to Coordinate With CISA

Like Harper, Hauptman called cyber security and incident reporting “critically important,” and said the sooner the agency is aware of an incident, the sooner it can determine whether it is isolated or widespread.

“Today’s rule is about reporting to NCUA only. NCUA is issuing its rule now, rather than waiting until 2025 when the Cybersecurity and Infrastructure Security Agency (CISA) will release its final rule,” said Hauptman. “The board believes it is in the best interest of the credit union system to align the NCUA’s rule with the Cyber Incident Reporting Act to provide uniform and timely cyber incident reporting. It is our intention to coordinate with CISA on any future credit union cyber incident reporting to avoid duplicate reporting to both the NCUA and CISA.”

thumbnail_NCUA Meeting Hood

Rodney Hood

In his remarks, Hauptman also noted:

  • Requirements on notifying credit union members and the public are unchanged
  • Credit unions are being asked to report as soon as possible and not later than 72 hours after the credit union reasonably believes an incident has occurred. The timeframe of 72 hours is consistent with what CISA will require in 2025
  • Credit unions are not required to provide a detailed incident assessment to the NCUA within the 72-hour time frame
  • NCUA will not publicize the name of credit unions that report cyber incidents.

Hood: ‘The Risk is a Moving Target’

Noting the time the agency has invested focusing on cybersecurity, NCUA Board Member Rodney Hood added, “I wish we could say that after having focused on this threat for such a long time, we are making progress toward a real sustainable solution, but unfortunately that's simply not the case given the velocity and evolution of cybersecurity threats.  As such, we have to accept that cybersecurity threats are an ongoing risk both to financial institutions’ operations and to their reputations.  Moreover, we have to accept that the risk is a moving target.”

Hood said every CU must recognize that their institution is “just one wrong email or malicious link away from being on the front pages. Given those realities, even those of us who favor a more balanced approach to regulatory matters, we must recognize that the agency's cybersecurity review and supervision capabilities need to be more robust.”

A Patch is No Patch

He further said credit unions can no longer count on vendors to provide a “patch” to address vulnerabilities and then move on, and must instead “rethink” their defenses.

In response to a question from Hood over what responsibilities CUs have related to cyber-incidents ahead of the Sept. 1 implementation of the new rule, staff said rules are in place requiring such reporting.

Comments

Popular posts from this blog

The Most Overlooked Growth Opportunity in First Responder Credit Unions

Credit unions spend enormous amounts of time, energy, and marketing dollars trying to acquire new members. But many institutions — especially sponsor-based first responder credit unions — are sitting on one of the most valuable growth opportunities already inside their existing membership base. The joint owner population. Every day, firefighters, police officers, EMTs, dispatchers, and other first responders join credit unions through sponsor relationships. During account opening, spouses or partners are often added as joint owners for convenience. They help manage the household finances. They use the debit card. They log into online banking. They interact with the credit union regularly. Yet in many cases, they never actually become full member-owners of the cooperative. They are connected to the institution — but not fully part of it. And that creates a major strategic opportunity. Why Joint Owner Conversion Matters For sponsor-based credit unions, converting joint owners into full m...

ACU Calls For Full Political Engagement As Election Cycle Heats Up, Warns Of Well-Funded Opposition

  WASHINGTON--Credit unions need every advocacy resource at their disposal, and in an election year, that means supporting credit union champions, America’s Credit Unions emphasized. ACU President/CEO Scott Simpson and Head of Political Affairs Trey Hawkins outlined credit unions’ role in supporting those champions in the 120th Congress as the 2026 election cycle resumes with primaries next week. Scott Simpson “It’s important that we defend those who defend us, that we help those who help us,” Simpson said, referring to policymakers who have supported the credit union tax status and regulatory relief, while opposing new interchange mandates, to name a few issues. “This is an opportunity for us to lean in, to marshal all the available resources that we can. Our counterparts in the for-profit financial space, those who are devoted to harming us, can vastly out-resource us.” Hawkins shared potential outcomes for control of chambers of Congress, but noted credit unions have support reg...

Discussions Reportedly Underway Over Allowing Donations of Co. Stock to Trump Accounts for Kids

WASHINGTON — White House and Treasury Department officials are discussing whether to expand the Trump administration’s new investment accounts for American children to allow donations of individual company stock. The accounts, formally known as Section 530A accounts and referred to by supporters as “Trump accounts,” are scheduled to begin accepting contributions on July 4, The New York Times reported. The program has already received billions of dollars in philanthropic commitments. Under current rules, the accounts are limited to cash investments placed into diversified index funds. According to The New York Times, administration officials are now considering whether wealthy individuals could instead donate shares of their companies directly into the accounts. The proposal has reportedly been championed by venture capitalist Brad Gerstner, founder of Altimeter Capital, who helped develop the 530A account initiative. Gerstner has discussed the idea with administration officials, The Ne...

Senate Banking To Vote Thursday On Landmark Digital Assets Bill

“NCOFCU appreciates the Senate Banking Committee’s continued work during next week’s markup hearing to establish a clear and responsible regulatory framework for digital assets,” said the National Council of Fire Fighter Credit Unions (NCOFCU) leadership. “As lawmakers consider this legislation, it is essential that first responder credit unions are recognized as a vital part of the financial services ecosystem and are not overlooked in the evolving digital asset landscape. Credit unions serving police, fire, EMS, and other emergency personnel must have equitable access to innovation, regulatory clarity, and the tools necessary to continue supporting the financial readiness and resilience of America’s first responders.” Grant Sheehan CEO WASHINGTON—The Senate Banking Committee will vote on the long-awaited CLARITY Act this Thursday, Committee Chairman Tim Scott (R-SC) announced Friday. Tim Scott The announcement marks a potentially major step forward for legislation that would establis...

Cutting Through The Stablecoin Noise—What Credit Unions Actually Need To Know Now

By Ray Birch DOVER, Del.—By any measure, stablecoins have quickly become one of the most talked-about—and least understood—topics in credit union boardrooms. The pressure to “do something” is building, fueled by headlines, fintech momentum and a growing fear of being left behind. But according to InvestiFi CEO Kian Sarreshteh, that urgency may be misplaced. “There’s a lot of FOMO right now,” Sarreshteh said. “If I don’t adopt a stablecoin solution this year, I’m going to be left behind. I would argue pretty strongly that’s very far from the truth.” Instead of rushing to sign up for a Stablecoin pilot, Sarreshteh said credit unions should begin with a more fundamental question: what problem are you actually trying to solve? While stablecoins are often discussed as a potential challenger to traditional payment rails dominated by Visa and Mastercard, he believes that kind of mass-market disruption remains years away—especially in the U.S., where consumers already have fast, convenient opt...

Fire Family Foundation Establishes Erksine Fire: Rebuilding Lives and Community Fund

Fund Will Assist Fire Victims and Firefighters in Kern County July    8, Los Angeles, CA:   Responding to the emergency of deadly wildfires that are currently blazing through communities in Kern County, Fire Family Foundation, the charitable hand of Firefighters First Credit Union, has created the Erskine Fire: Rebuilding Lives and Community Fund. California’s largest wildfire so far this year, the Erskine fire erupted Thursday afternoon and continues to burn; two people have died, thousands have left their homes, 200 homes were destroyed with many others severely damaged. Four firefighters who were working on the blaze learned the sad news that their own homes were completely destroyed by the fire. The Erskine Fire Fund will dedicate 100% of the funds raised to be distributed to firefighters and fire victims; funds will be used for short-term assistance to pay expenses for essential and immediate needs from food to mortgages/rent "Our firefighters are battli...

NCUA Identifies Supervisory Priorities for 2024

ALEXANDRIA, Va.–In a new  Letter to Credit Unions , NCUA has outlined its supervisory priorities and other updates for its 2024 examination program. The agency said the areas identified are those with the highest risk to credit union members and the insurance fund. As CUToday.info has previously reported, growing financial strains and liquidity risks are cited by the agency, as well as the growth in the number of composite CAMELS code 3, 4, and 5 credit unions.  The agency further noted: Its exam flexibility initiative will continue in 2024, extending the exam cycle for certain credit unions. It will continue its Small Credit Union Exam Program in most federal credit unions with assets of $50 million or less. Supervisory Priorities f...

NAFCU - Vehicle Sales Decline During 2017

ARLINGTON, Va.—Vehicle sales in 2017 totaled 17.23 million units, non-seasonally adjusted, marking the first year-over-year sales decline since 2009. Total vehicle sales increased in December to 17.85 million seasonally adjusted, annualized units but were down 1.7% from a year ago. "Looking ahead, sales are expected to trend down further in 2018 as pent-up demand from earlier years diminishes," observed NAFCU Research Assistant Yun Cohen in a Macro Data Flash report. "In addition, banks are tightening standards on auto loans according to a recent survey by the Federal Reserve, which could lead to credit constraints. Despite the slowdown, vehicle sales are expected to remain strong in light of a strong labor market and growing economy." According to data by Autodata Corp., car sales decreased from 6.3 million to 6.1 million annualized units during the month. However, sales of light trucks increased from 11.2 million to 11.8 million annualized units, Cohen no...

'Victory is Elusive': CU Economist Agrees Fed Rate Cuts Questionable Following New CPI Report

04/10/2024 11:01 am WASHINGTON–A credit union economist has joined with other economists and analysts in forecasting a delay in any rate cuts by the Fed in 2024 following today’s inflation report. The newly released Consumer Price Index climbed 3.8% on an annual basis after stripping out food and fuel prices. That “core” index was stronger than the 3.7% increase economists expected, and unchanged from 3.8% in February.  Counting in food and fuel, the inflation measure climbed 3.5% in March from a year earlier, up from 3.2% in February and faster than what many had forecast.  "Victory in the Federal Reserve's inflation fight remains elusive with a stubbornly high headline consumer price index increase of 0.4% in March, matching February's disappointing result,” said America's Credit Unions VP-data and research, chief econom...

Ten-Year Treasury Hits a 15-Year High

WASHINGTON–The yield on the 10-year U.S. Treasury note has hit a 15-year high, which could lead to higher costs for many borrowers. The increase in yields is also “raising concern” on Wall Street about the potential fallout in the stock, bond and housing markets, the Wall Street Journal added. A key benchmark for interest rates across the economy, the 10-year yield settled at 4.258%, according to Tradeweb, up from 4.220% earlier this week, marking its highest close since June 2008, months before the collapse of Lehman Brothers and expansive Federal Reserve policy “ushered in more than a decade of historically low bond yields,” the Journal added. ‘Nervous’ Investors “The rise in yields is making investors nervous, because past surges have at...