Skip to main content

What CUs Need to Know About the New Cyber Incident Reporting Requirements

The NCUA’s final rule goes into effect on Sept. 1.

reported data breach Image: Shutterstock

The NCUA has approved new cyber incident reporting requirements for credit unions. Under the final rule, federally insured credit unions will be required to notify the NCUA of a “reportable cyber incident” within 72 hours of such an event. The NCUA’s final rule follows the 36-hour notification requirement implemented for banking organizations last year. While the final rule doubles the reporting time for credit unions, it also could require credit unions to notify the NCUA of a significantly broader set of incidents than required for banking organizations. The final rule continues the trend of regulators increasing their focus on the cybersecurity safeguards among financial institutions and, in particular, of requiring faster notifications when incidents occur.

The final rule will go into effect on Sept. 1, 2023. Here, we’ll provide a primer about the rule and proactive steps credit unions should be taking in anticipation of these new reporting requirements.

What Is a Reportable Cyber Incident?

The rule requires credit unions to notify the NCUA no later than 72 hours after it reasonably believes a reportable cyber incident has occurred. A reportable cyber incident is defined as any substantial cyber incident that leads to:

  • A substantial loss of confidentiality, integrity or availability of a network or member information system that results from the unauthorized access to or exposure of sensitive data, disrupts vital member services, or has a serious impact on the safety and resiliency of operational systems and processes;
  • A disruption of business operations, vital member services, or a member information system resulting from a cyberattack or exploitation of vulnerabilities; and/or
  • A disruption of business operations or unauthorized access to sensitive data facilitated through, or caused by, a compromise of a CUSO, cloud service provider, managed service provider, or other third-party data hosting provider or a supply chain compromise.

Examples of Reportable Incidents

The NCUA’s final rule contained some examples of what may constitute a reportable cyber incident, including, without limitation:

  • If a member information system has been unlawfully modified and/or sensitive data has been left exposed to an unauthorized person, process or device;
  • A failed system upgrade or change that results in unplanned widespread user outages for credit union members and employees; or
  • A distributed denial of service (DDoS) attack that disrupts member account access.

The rule does state that incidents such as unsuccessful malware attacks or failed attempts to gain access to systems do not have to be reported. In addition, third-party incidents that are unknown to a credit union and hold information about individuals who happen to be credit union members or employees do not impose a notification requirement.

How Should Incidents Be Reported?

According to the final rule, incidents may be reported to the NCUA “via email, telephone or other similar methods that the NCUA may prescribe.” The reporting methods are designed to give credit unions flexibility based upon the impact of a potential cyber incident. The NCUA has also stressed that an initial report does not have to include a full assessment of the incident.

Next Steps for Credit Unions

The NCUA will be providing additional guidance, including examples of reportable and non-reportable incidents, before the final rule becomes effective in September. In the meantime, credit unions should be reviewing and updating their incident response plans and vendor management programs to ensure that they are prepared to comply with these enhanced requirements.

Comments

Popular posts from this blog

Trump Administration Declares CFPB Funding Illegal, Bureau’s Cash To Run Out By Early 2026

WASHINGTON—Credit-unions face a potential regulatory vacuum as the Trump Administration formally has determined the CFPB’s current self-funding mechanism unlawful—a move that could put the agency on a path to closure in early 2026 unless Congress steps in. For credit-union leaders, who rely on the Bureau’s oversight of consumer-finance markets and enforcement of unfair practices, the decision signals a major disruption to the regulatory environment CUs navigate daily. In a court filing released late Monday, the Administration declared that the CFPB is now legally barred from seeking additional funds from the Federal Reserve System—the agency’s usual funding source under the Dodd‑Frank Wall Street Reform and Consumer Protection Act, POLITICO reported. That means the Bureau’s remaining resources will likely carry it only through the end of the year, after which it “anticipates exhausting its currently available funds in early 2026.” CUToday.info has tracked this story, noting in  Oct...

Sheehans Consulting LLC - "We only have one goal in mind!"

We have one goal in mind: “What is best for you? We achieve strategic initiatives, develop products, optimize profitability and productivity through best practices, and make our firm a strong asset for professional services.  With over 30 years of experience in public administration, credit union, and association management, I have developed a solid track record in leadership and development.  Please visit us at https://www.sheehansconsultingllc.com/ to learn more about what we can do for you.   _________________________________________ Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

Now Available - "Financial Literacy" From NCOFCU

https://www.ncofcu.org/financial-literacy The National Council of Firefighter Credit Unions (NCOFCU) is dedicated to enhancing financial literacy among our members, members, particularly targeting the Millennial and Gen Z demographics. We are excited to share our engaging financial education video series, designed to address their key concerns regarding earning, saving, and spending money wisely. Here are several critical financial lessons that can significantly impact your personal finance management and long-term financial health. Discover how staying informed and educated about financial products and market trends can empower you to make smarter financial decisions. https://www.youtube.com/playlist?list=PLT3lzRTXnHw4LjHuOIk31eTDxaQ7J7B0f   _________________________________________ Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

Best Places to Retire

  List: Best Places to Retire Midland, Michigan , was ranked the best place to retire , according to a ranking of 850 cities by U.S. News . The top locations had the best mix of affordability, quality of life, health care access, and other benefits. The top five were rounded out by Weirton, West Virginia , Homosassa Springs, Florida , The Woodlands, Texas , and Spring, Texas . Midland scored top marks on walkability , culture , retail establishments , and restaurants . The town is just a short drive from beaches at the edge of Lake Huron . The top 25 included nine cities in Florida and six in Texas. See the full list here . _________________________________________ Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

NCUA Reports Continued Credit Union Loan Growth in First Quarter of 2016

"ALEXANDRIA, Va. (June 3, 2016) – Credit unions continued to increase their lending, with loans outstanding increasing 10.7 percent in the year ending in the first quarter of 2016, the National Credit Union Administration reported today.  “The credit union system again experienced solid performance during the first quarter of 2016,” NCUA Board Chairman Rick Metsger said. “Overall, new and used auto lending was especially strong, and the system gained one million members. With an influx of deposits, federally insured shares at credit unions also neared the $1 trillion mark coming in at $991.7 billion.  “As credit union lending has increased, long-term investments have declined and reduced the system’s interest rate risk. However, delinquency and charge-off rates are slightly higher than a year ago, and member-business loan delinquencies are rising even more. Credit unions making such loans should take note and ensure that they perform proper due diligence to mitigate the r...

House Vote Ends Longest Shutdown In U.S. History

WASHINGTON—The House late Wednesday approved a sweeping funding measure to end the longest federal government shutdown in U.S. history, clearing the way for federal agencies to reopen within hours and for hundreds of thousands of workers and service members to receive long-delayed pay. The vote was 222-209, with just six Democrats breaking with their leadership, POLITOCO said. President Trump is expected to sign the measure before night’s end, allowing federal operations to resume Thursday morning. The chamber’s vote—coming after days of intense negotiations and following the Senate’s 60–40 passage—sent the bipartisan agreement to President Donald Trump for his signature, effectively ending a shutdown that stretched well past six weeks and rattled everything from military readiness to basic government services. The package includes a continuing resolution funding the government through Jan. 30. The measure also includes a three-bill “minibus” of full-year funding for the Department...

Fed Governor Warns ‘Global Stablecoin Glut’ Could Reshape Monetary Policy

  NEW YORK—Federal Reserve Governor Stephen Miran believes the rapid rise of stablecoins could become a major force shaping U.S. monetary policy. Once seen as a niche digital tool for crypto traders, stablecoins have evolved into a global conduit for dollar-denominated transactions, enabling users worldwide to store value and move capital more efficiently. Their growing prominence, Miran noted during his speech at the BCVC Summit 2025 at the Harvard Club, reflects continued demand for dollars—and with the GENIUS Act now providing a clear regulatory framework for U.S.-issued stablecoins, the sector is poised for broader adoption across payment systems. Stephen Miran Stablecoins’ link to the U.S. dollar is reinforcing the currency’s global dominance while simultaneously creating new implications for monetary policy. Miran argued that stablecoins are already increasing demand for U.S. Treasury bills and other dollar-based assets, especially from investors outside the United States. Th...

NCUA Letter to Credit Unions: Interagency Statement on LIBOR Transition

Dear Boards of Directors and Chief Executive Officers: As a follow-up to Letter to Credit Unions 21-CU-03, LIBOR Transition , this letter provides additional reminders related to LIBOR’s discontinuance. Five federal financial institution regulatory agencies, in conjunction with the state bank and state credit union regulators, are jointly issuing the enclosed statement to emphasize the expectation that supervised institutions with LIBOR exposure will continue to progress toward an orderly transition away from LIBOR. [1] The NCUA encourages all federally insured credit unions to transition away from using U.S. dollar LIBOR as a reference rate as soon as possible, but no later than December 31, 2021, and to ensure existing contracts have robust fallback language that includes a clearly defined alternative reference rate. Please contact your NCUA Regional Office or state supervisory authority if you have any questions about this important topic. Read the Letter to Credit Unions   Sav...

Sunday Reading - Individual Retirement Accounts

  Individual Retirement Accounts     Inside IRAs Individual retirement accounts, or IRAs, are tax-advantaged   investment accounts that help individuals save for retirement. The money you put into an IRA is used to invest in stocks, bonds, and other assets. Anyone who earns an income—regardless of whether they are a full-timer, a part-timer, or a contractor—can open and invest in an IRA. IRAs are often good solutions for people who don’t have the option to invest in a 401(k) ( 1440 Topics )—or for those who want to put even more money aside for retirement.   Depending on the type of IRA someone gets, they will have access to either a tax-deferred or...

Are You Ready for the Next Wave of Mergers & Acquisitions?

Remember you are not alone with NCOFCU!  If you are consedering a merger reach out to us to see if we can't keep you within the first responder credit union network. ceo@ncofcu.org - 305.951.3306 ALM First shares key lessons and advice from credit unions with merger and community bank acquisition experience. By David Ritter & By Brandon Pelletier | April 10, 2024 at 09:00 AM Credit/Shutterstock With the pace of industry mergers already ramping up in 2024 and projected to increase, it's more important than ever for credit unions to have a predefined M&A strategy and be ready for the inevitable calls from prospective partner organizations. Here, we'll share key lessons and advice from cooperatives that have merger experience with other credit unions and acquisition experience with community banks to help your team prepare. Define Your Vision and Evaluation Criteria ...