Skip to main content

What CUs Need to Know About the New Cyber Incident Reporting Requirements

The NCUA’s final rule goes into effect on Sept. 1.

reported data breach Image: Shutterstock

The NCUA has approved new cyber incident reporting requirements for credit unions. Under the final rule, federally insured credit unions will be required to notify the NCUA of a “reportable cyber incident” within 72 hours of such an event. The NCUA’s final rule follows the 36-hour notification requirement implemented for banking organizations last year. While the final rule doubles the reporting time for credit unions, it also could require credit unions to notify the NCUA of a significantly broader set of incidents than required for banking organizations. The final rule continues the trend of regulators increasing their focus on the cybersecurity safeguards among financial institutions and, in particular, of requiring faster notifications when incidents occur.

The final rule will go into effect on Sept. 1, 2023. Here, we’ll provide a primer about the rule and proactive steps credit unions should be taking in anticipation of these new reporting requirements.

What Is a Reportable Cyber Incident?

The rule requires credit unions to notify the NCUA no later than 72 hours after it reasonably believes a reportable cyber incident has occurred. A reportable cyber incident is defined as any substantial cyber incident that leads to:

  • A substantial loss of confidentiality, integrity or availability of a network or member information system that results from the unauthorized access to or exposure of sensitive data, disrupts vital member services, or has a serious impact on the safety and resiliency of operational systems and processes;
  • A disruption of business operations, vital member services, or a member information system resulting from a cyberattack or exploitation of vulnerabilities; and/or
  • A disruption of business operations or unauthorized access to sensitive data facilitated through, or caused by, a compromise of a CUSO, cloud service provider, managed service provider, or other third-party data hosting provider or a supply chain compromise.

Examples of Reportable Incidents

The NCUA’s final rule contained some examples of what may constitute a reportable cyber incident, including, without limitation:

  • If a member information system has been unlawfully modified and/or sensitive data has been left exposed to an unauthorized person, process or device;
  • A failed system upgrade or change that results in unplanned widespread user outages for credit union members and employees; or
  • A distributed denial of service (DDoS) attack that disrupts member account access.

The rule does state that incidents such as unsuccessful malware attacks or failed attempts to gain access to systems do not have to be reported. In addition, third-party incidents that are unknown to a credit union and hold information about individuals who happen to be credit union members or employees do not impose a notification requirement.

How Should Incidents Be Reported?

According to the final rule, incidents may be reported to the NCUA “via email, telephone or other similar methods that the NCUA may prescribe.” The reporting methods are designed to give credit unions flexibility based upon the impact of a potential cyber incident. The NCUA has also stressed that an initial report does not have to include a full assessment of the incident.

Next Steps for Credit Unions

The NCUA will be providing additional guidance, including examples of reportable and non-reportable incidents, before the final rule becomes effective in September. In the meantime, credit unions should be reviewing and updating their incident response plans and vendor management programs to ensure that they are prepared to comply with these enhanced requirements.

Comments

Popular posts from this blog

Syracuse Fire Department Credit Union

Remember, you're not alone with  NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

Happy Holidays To All Who Serve

  Happy Holidays To All Who Serve 12/22/2025 10:28 am   By Grant Sheehan and Anthony Hernandez Every year, many Americans celebrate the joy of family and relief from work the holidays bring. Apart from the hustle and bustle, the holiday season is a special time to be with loved ones, engaging in family traditions and rituals, and making memories that will last a lifetime. However, not everyone gets to partake in the holiday gatherings.   There are over a hundred thousand military members serving in harm’s way or in 24-hour command center...

Is another housing bubble brewing?

While there have been fears expressed by some of a repeat of the housing bubble that led to the housing crisis just over a decade ago, numerous real estate analysts say they believe the market fundamentals are much stronger now and that the sharp increase in home prices reflects low rates, a lack of inventory, and demographics. To be sure, the market is hot in many markets, with home sellers receiving multiple cash offers, often over the listed price, on homes. Some analysts, including those at Swiss banking giant UBS, have published charts showing how home prices are outstripping both wages and rents, reported USA Today. Home prices have appreciated more than 60% since November 2012, incomes have only appreciated by 20% and rents by 30% over the same time period, the report added. “But unlike the real estate boom that led to the Great Recession, this nationwide price spike is not being fueled by a wholesale collapse in lender ethics,” USA Today reported “There aren't any low-doc o...

Sunday Reading - The gold standard, explained

  Gold Standard       The gold standard, explained A gold standard is a system where a country’s currency is pegged to, and can be converted into, a fixed amount of gold. It’s typically meant to create a sense of security in the country’s currency: When a government uses a gold standard , its currency can be exchanged for an equivalent amount of gold—although regulations around redemption vary by country.   After the Civil War, in 1873, America adopted the gold standard for the first time. At the time, if gold was priced at $100 an ounce, each dollar  rep...

NAFCU Economist: U.S. Might Dodge Recession

Curt Long said a strong jobs report shows resilience despite the Fed’s escalation in interest rates. By Jim DuPlessis | January 06, 2023 CUTimes Source: Shutterstock. NAFCU Chief Economist Curt Long said Friday the continued strength in the job market has increased the odds the nation will dodge a recession this year. The U.S. Bureau of Labor Statistics reported Friday there were 153.7 million seasonally adjusted jobs in December, an increase of 223,000, or 0.1%, from November and up 3% from a year earlier. The unemployment rate was 3.5% in December, down from 3.6% in November and 3.9% in December 2021. Long said December’s rate was the lowest in more than 50 years, while the labor force participation rate rose slightly. Seasonally adjusted average hourly earnings were $32.82 in December, up 0.3% from November and up 4.6% from a year ago, a slightly lower rate of increase from previous months. Curt Long “This is an unambiguously positiv...

NCOFCU is working hard for you! Coalition of CU Groups Sends Letter to Congress on Tax Exemption

Take Action Coalition of CU Groups Sends Letter to Congress on Tax Exemption May 1, 2025 10:15 am No Comments WASHINGTON–A coalition of credit union organizations has sent a joint letter to Congress in support of the credit union tax exemption. As the CU Daily has been regularly reporting, credit unions are especially  concerned this year that Congress might revoke the tax exemption as it seeks ways to pay for expiring provisions of the 2017 tax cuts, which President Trump wants to see renewed. Sending the letter to Congress were the Defense Credit Union Council (DCUC), America’s Credit Unions (ACU), Credit Union Executive Society (CUES), National Association of Credit Union Chairs (NACUC), National Credit Union Management Association (NCUMA), Inclusiv, TruStage, Earnest Consulting Group (ECG), Callahan and Associates, National Council of Firefighter Credit Unions (NCOFCU), Metropolitan Area Credit Union Management Association (MACUMA), Association of Credit Union Audit and Ri...

Dolphin Debit & Customized Service Concepts Partner to Expand ATM Options

HOUSTON– Dolphin Debit , a provider of ATM management services, said it is partnering with Customized Service Concepts (CSC), an ATM sales and service provider in New England, to offer financial institutions in the region a complete range of ATM options. Gary Walston The two companies said the advantages the partnership bring to clients are numerous, including the ability to meet any ATM need. Dolphin Debit can provide its ATM outsourcing solutions for CSC clients, allowing credit unions to break free of the burdens of ATM fleet management and maintenance, while CSC expert technicians will provide the service for the joint Dolphin-CSC clients, the organizations said. Customized Service Concepts, LLC, with offices in Durham, Conn., and Goffstown, N.H., has served financial institutions in New England for more than 30 years. CSC provides ATM/ITM solutions as well as a broad product range that inclu...

Email and Text Message Etiquette

As we navigate our everyday communications, I want to emphasize the importance of practicing good email and text message etiquette. This enhances clarity and ensures that everyone feels respected and valued in our interactions. Email Etiquette: 1. Use a Clear Subject Line: A subject line that accurately reflects the content of your email will help recipients know what to expect. 2. Greet Appropriately: Start with an appropriate greeting, such as "Dear [Name]", "Hello [Name]," or "Hi [Name], which sets a positive tone. 3. Acknowledge Receipt: If you receive an email that requires a response, action, or information, please acknowledge its receipt. A simple reply confirming that you have received the email helps the sender know their message was received and provides an opportunity to clarify expectations. 4. Be Concise: Keep your emails clear and to the point. Avoid excessive details unless necessary. 5. Professional Language: Use respectful and professional l...

Mortgage Rates Decline to Their Lowest Levels Since April

WASHINGTON–Mortgage rates fell last week to their lowest level since early April. According to Freddie Mac, the standard 30-year fixed-rate mortgage averaged 6.87% in the week ending June 20, which was down from the prior week’s 6.95% average and marks the third consecutive weekly decline. Rates are down from a 2024 peak of 7.22%. “Mortgage rates fell for the third straight week following signs of cooling inflation and market expectations of a future Federal Reserve rate cut,” Sam Khater, Freddie Mac’s chief economist, said in a statement. “These lower mortgage rates coupled with the gradually improving housing supply bodes well for the housing market.” Most economists and forecasters expect rates ...

Is Your Board Packet Online?

  Is Your Board Packet Online? Let us show you just how easy it is to get your board packets online. MyBoardPacket is known as the “easiest to use” and most affordable secure solution on the market. Contact us today to schedule a demo or request pricing information. To receive your special NCOFCU member discount, let them know who referred you! “NCOFCU” Contact Them Now →