Skip to main content

NCUA Board Meeting Coverage: NCUA Approves New Cyber Incident Reporting Rule

02/16/2023 CUToday

ALEXANDRIA, Va.–By a 3-0 vote, the NCUA board has approved a final rule on cyber incident reporting for federally insured credit unions.

The rule requires credit unions to inform NCUA of any “reportable” incident within 72 hours. Such incidents are those where the credit union “reasonably believes” a cyber incident has occurred, with such events defined as those in which the integrity, confidentiality or availability of information has been compromised.

The rule is to go into effect on Sept. 1, 2023.

thumbnail_NCUA Harper at Meeting

Todd Harper

The NCUA board was updated on the rule by Kelly Lay, director of the Office of Examination and Insurance, and Christina Saari, information systems officer in the same office. Both said credit unions had been strongly supportive of such rulemaking in their comment letters.

Harper: Issue ‘Keeps Me Up at Night’

NCUA Chairman Todd Harper, who said cybersecurity “is an issue that often keeps me up at night,” noted the final rule is largely unchanged from the proposed rule approved last July.

“Through these high-level early warning notifications, the NCUA will be able to work with other agencies and the private sector to respond to cyber threats before they become systemic and threaten the broader financial services sector,” said Harper. “This final rule will also align the NCUA’s reporting requirements with those of the federal banking agencies and the Cyber Incident Reporting for Critical Infrastructure Act.”

Harper, who credited Vice Chairman Kyle Hauptman for his suggestion the final rule include language noting NCUA will coordinate with the Cybersecurity and Infrastructure Security Agency on any future credit union cyber incident reporting requirements to avoid duplicative reporting to both agencies, said everyone in the financial system has an obligation to protect the nation’s economic and financial infrastructure. “And, credit unions must be included in conversations about critical infrastructure, as a whole. This final rule will facilitate such dialogue.”

Harper said the final rule is one of several actions NCUA has recently taken to improve the system’s cyber resiliency, including its earlier launch of the Information Security Examination program (ISE).

‘Fix This Blind Spot’

“While the cyber incident notification final rule and ISE will help in the fight against cyberattacks, we still must confront the regulatory blind spot that continues to exist because the NCUA lacks authority — the same authority that banking regulators have — to exercise a risk- based approach to supervise third-party vendors,” said Harper.

thumbnail_NCUA Hauptman at Meeting

Kyle Hauptman

NCUA has lost several bids in Congress to obtain that supervision authority.

“Unfortunately, cyber risk in the credit union system often lurks in the ether — beyond the NCUA’s purview — within credit union service organizations and third-party service providers that do not have the same level of oversight as bank vendors,” Harper continued. “As a result, thousands of credit unions, tens of millions of consumers who use credit unions, and roughly $2 trillion in assets are exposed to potentially devastating risks. The Government Accountability Office, the Financial Stability Oversight Council, and the NCUA’s Inspector General have all recommended congressional action to fix this blind spot.”

In response to a question from Harper on the guidance and training that will be made available, agency staff said both will be provided, including scenarios for when a notification is needed and when it is not.

Hauptman: Plan is to Coordinate With CISA

Like Harper, Hauptman called cyber security and incident reporting “critically important,” and said the sooner the agency is aware of an incident, the sooner it can determine whether it is isolated or widespread.

“Today’s rule is about reporting to NCUA only. NCUA is issuing its rule now, rather than waiting until 2025 when the Cybersecurity and Infrastructure Security Agency (CISA) will release its final rule,” said Hauptman. “The board believes it is in the best interest of the credit union system to align the NCUA’s rule with the Cyber Incident Reporting Act to provide uniform and timely cyber incident reporting. It is our intention to coordinate with CISA on any future credit union cyber incident reporting to avoid duplicate reporting to both the NCUA and CISA.”

thumbnail_NCUA Meeting Hood

Rodney Hood

In his remarks, Hauptman also noted:

  • Requirements on notifying credit union members and the public are unchanged
  • Credit unions are being asked to report as soon as possible and not later than 72 hours after the credit union reasonably believes an incident has occurred. The timeframe of 72 hours is consistent with what CISA will require in 2025
  • Credit unions are not required to provide a detailed incident assessment to the NCUA within the 72-hour time frame
  • NCUA will not publicize the name of credit unions that report cyber incidents.

Hood: ‘The Risk is a Moving Target’

Noting the time the agency has invested focusing on cybersecurity, NCUA Board Member Rodney Hood added, “I wish we could say that after having focused on this threat for such a long time, we are making progress toward a real sustainable solution, but unfortunately that's simply not the case given the velocity and evolution of cybersecurity threats.  As such, we have to accept that cybersecurity threats are an ongoing risk both to financial institutions’ operations and to their reputations.  Moreover, we have to accept that the risk is a moving target.”

Hood said every CU must recognize that their institution is “just one wrong email or malicious link away from being on the front pages. Given those realities, even those of us who favor a more balanced approach to regulatory matters, we must recognize that the agency's cybersecurity review and supervision capabilities need to be more robust.”

A Patch is No Patch

He further said credit unions can no longer count on vendors to provide a “patch” to address vulnerabilities and then move on, and must instead “rethink” their defenses.

In response to a question from Hood over what responsibilities CUs have related to cyber-incidents ahead of the Sept. 1 implementation of the new rule, staff said rules are in place requiring such reporting.

Comments

Popular posts from this blog

Hauptman Tells Congress CU Health is Strong; Responds to Questions from Committee

WASHINGTON — National Credit Union Administration Chairman Kyle Hauptman told members of the House Financial Services Committee on Thursday that the nation’s credit union system remains financially strong, while warning that rising delinquencies and consumer financial stress continue to warrant close monitoring. Hauptman also responded to a handful of questions from members of Congress, as well. Hauptman appeared as part of the regular hearings on Oversight of Prudential Regulators. Also appearing as witnesses were Michelle Bowman, vice chair for supervision with the Federal Reserve; Travis Hill, FDIC chairman, and Jonathan Gould, the acting Comptroller of the Currency. Kyle Hauptman In his prepared statement, Hauptman said federally insured credit unions remain well-capitalized and continue to meet members’ borrowing needs despite economic headwinds. He said the NCUA is focused on maintaining safety and soundness, protecting the National Credit Union Share Insurance Fund and creating...

Reuters: Trump Regulators Launch Biggest Bank Oversight Overhaul Since 2008

Is NCUA next? WASHINGTON—Federal banking regulators under President Trump are undertaking what Reuters described as the most significant overhaul of bank supervision since the 2008 financial crisis, shifting examiner focus away from process and compliance issues and toward what agencies consider “material” financial risks. According to Reuters, the Federal Reserve, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corp. have directed examiners to concentrate on risks that pose direct threats to a bank’s safety and soundness, rather than on paperwork deficiencies, governance concerns or procedural issues that do not immediately affect financial stability. Reuters reported that regulators have also moved away from evaluating banks based on “reputational risk,” a supervisory concept long criticized by banks as overly subjective. The change follows complaints from President Trump and others that financial institutions have used reputational-risk considerations...

Sunday Reading - Changing the Map

  Changing the Map     Redistricting, explained Congressional redistricting is the process by which states redraw electoral district boundaries   that determine representation in the US House of Representatives. The Constitution, federal law, and court rulings require districts to have roughly equal populations, avoid discrimination against racial or language minorities, and, in most states, be geographically contiguous. For most of American history, redistricting has followed a predictable cycle, occurring every 10 years after the census.   Gerrymandering is the deliberate manipulation of district boundaries to advantage one political party. Common tactics  by both major American political parties include packing opposition voters i...

Proposed FOM changes would streamline ability to reach underserved

February 16, 2023 The NCUA Board proposed chartering and field-of-membership changes and issued its final cyber incident reporting rule at its Thursday meeting. The board also heard a quarterly update on the share insurance fund, which noted an increase in the fund's equity ratio to 1.30%." The proposal would amend the chartering and FOM rules through nine changes to enhance consumer access to financial services, especially in low- and moderate-income communities while reducing duplicative or unnecessary paperwork and administrative requirements. “Getting credit union services to more communities across the country is important to CUNA, state leagues and the credit unions we serve, and making that easier to achieve has a big impact on access,” said CUNA Deputy Chief Advocacy Officer Jason Stverak. “While we need to review the proposal in detail, we thank the NCUA board for working to streamline the ability of credit un...

NCUA Board Approves Final Rule on Dependent Care and Board Member Reimbursement

Alexandria, VA (June 8, 2026) ― The National Credit Union Administration today issued a final rule for Dependent Care and Board Member Reimbursement. The NCUA Board amended its regulations concerning the reimbursement of reasonable expenses for federal credit union officials to remove potential barriers to volunteer service. This final rule provides flexibility for a federal credit union’s board to adopt more family-friendly policies tailored to its size, region, and operations. Previously, dependent care costs had not been considered reasonable expenses under NCUA regulation 12 C.F.R. 701.33.  The final rule applies to all federal credit unions, including corporate federal credit unions. It will not apply to federally insured, state-chartered credit unions, which remain subject to state law. The final rule is effective 30 days from the date of publication in the Federal Register and takes into consideration public comments received from the proposed rule that was issued on Januar...

Trump Accounts Program For Children Moves Forward With New Mobile App Launch

  WASHINGTON—The Treasury Department on Thursday announced the launch of the new Trump Accounts mobile app, marking the next phase of the Administration’s rollout of its new federally backed investment savings program for children ahead of the program’s official July 4 launch date. Donald Trump The app, now available through major mobile app stores, will serve as the primary platform for families to manage and activate Trump Accounts. Treasury Secretary Scott Bessent said the app is intended to give parents and guardians a “simple, secure way” to participate in the program, which was created under the 2025 Republican tax-and-spending package. Families that already submitted IRS Form 4547 to enroll children in the program will begin receiving phased activation emails between now and July 4, according to Treasury. Under the program, eligible children born between Jan. 1, 2025, and Dec. 31, 2028, can receive a one-time $1,000 federal seed contribution into a tax-deferred investment ac...

Cheer Up and Change: "Wait and see is not a plan."

I posted this a year ago and thought I would bring it back to see if any of his predictions came true. Take a look and tell us what you think. Grant Sheehan CEO Cheer Up and Change: The Demographic Mandate At a conference I recently attended Monday morning started off with a great session by demographer and futurist Ken Gronbach, who laid out his predictions on where we’re going and what we can expect as demographics change. I was pleasantly surprised that the future isn’t sounding as bleak as the news might have you believe. Gronbach offered lots of predictions for where our society and our world is headed. His predictions were given with a purpose: To help associations build their vision and plan for the future. As Gronbach stressed,  "Wait and see is not a plan." I’ve decided to arrange this recap into a list of my takeaways rather than a narrative recap. I hope you get as much out of this information as I did! Things to Expect: Big Changes in Retail : Gronbach ...

And The Forecast For 2017 Is?

Steven Rick who will be speaking to us in Charlotte, has made the following predictions for 2017. MADISON, Wis. – Increases in housing construction and rising oil prices will drive higher economic growth higher next year, while auto sales should remain robust, according to CUNA Mutual’s chief economist. Steven Rick said credit unions next year can expect a “slight acceleration” in the economy with no signs of a recession until late 2018—good news for CUs looking to expand their reach and services, he said. Rick is further predicting the Fed will boost rates once this year and three times in 2017. “We’re forecasting a modest acceleration in economic growth to 2.4% in 2017 from this year’s very slow 1.6%,” Rick told attendees of CUNA Mutual Group’s seventh annual Discovery Conference. “An inventory correction, reduced energy sector investment due to falling oil prices, and the negative impact of the rising dollar on our exports all contributed to the U.S. economy’s slower gro...

Mortgage Rates Decline to Their Lowest Levels Since April

WASHINGTON–Mortgage rates fell last week to their lowest level since early April. According to Freddie Mac, the standard 30-year fixed-rate mortgage averaged 6.87% in the week ending June 20, which was down from the prior week’s 6.95% average and marks the third consecutive weekly decline. Rates are down from a 2024 peak of 7.22%. “Mortgage rates fell for the third straight week following signs of cooling inflation and market expectations of a future Federal Reserve rate cut,” Sam Khater, Freddie Mac’s chief economist, said in a statement. “These lower mortgage rates coupled with the gradually improving housing supply bodes well for the housing market.” Most economists and forecasters expect rates ...

IRS Reporting Requirement Has Turned Into Uphill Battle for CUs

  It’s in. It’s out. It’s in again. On Thursday, NAFCU, CUNA and more than 100 associations sent a letter to all members of the U.S. House of Representatives and Senate asking them to reject a proposed IRS reporting requirement that credit union trades have been pushing back against since July . The proposed IRS reporting requirement would require financial institutions, including credit unions, to report the inflows and outflows of personal and business accounts, as well as transfers between accounts of the same owner, if it is more than $600 per year. The proposal found new life inside the House version of the budget reconciliation bill after it was rejected in the version approved by the House Ways and Means Committee last month. On Tuesday, Speaker of the House Nancy Pelosi (D-Calif.) said the IRS reporting requirement would be included in the House version of the bill. CUNA, NAFCU and other organizations voiced their objections to the proposal in a joint letter. While the l...