Skip to main content

What CUs Need to Know About the New Cyber Incident Reporting Requirements

The NCUA’s final rule goes into effect on Sept. 1.

reported data breach Image: Shutterstock

The NCUA has approved new cyber incident reporting requirements for credit unions. Under the final rule, federally insured credit unions will be required to notify the NCUA of a “reportable cyber incident” within 72 hours of such an event. The NCUA’s final rule follows the 36-hour notification requirement implemented for banking organizations last year. While the final rule doubles the reporting time for credit unions, it also could require credit unions to notify the NCUA of a significantly broader set of incidents than required for banking organizations. The final rule continues the trend of regulators increasing their focus on the cybersecurity safeguards among financial institutions and, in particular, of requiring faster notifications when incidents occur.

The final rule will go into effect on Sept. 1, 2023. Here, we’ll provide a primer about the rule and proactive steps credit unions should be taking in anticipation of these new reporting requirements.

What Is a Reportable Cyber Incident?

The rule requires credit unions to notify the NCUA no later than 72 hours after it reasonably believes a reportable cyber incident has occurred. A reportable cyber incident is defined as any substantial cyber incident that leads to:

  • A substantial loss of confidentiality, integrity or availability of a network or member information system that results from the unauthorized access to or exposure of sensitive data, disrupts vital member services, or has a serious impact on the safety and resiliency of operational systems and processes;
  • A disruption of business operations, vital member services, or a member information system resulting from a cyberattack or exploitation of vulnerabilities; and/or
  • A disruption of business operations or unauthorized access to sensitive data facilitated through, or caused by, a compromise of a CUSO, cloud service provider, managed service provider, or other third-party data hosting provider or a supply chain compromise.

Examples of Reportable Incidents

The NCUA’s final rule contained some examples of what may constitute a reportable cyber incident, including, without limitation:

  • If a member information system has been unlawfully modified and/or sensitive data has been left exposed to an unauthorized person, process or device;
  • A failed system upgrade or change that results in unplanned widespread user outages for credit union members and employees; or
  • A distributed denial of service (DDoS) attack that disrupts member account access.

The rule does state that incidents such as unsuccessful malware attacks or failed attempts to gain access to systems do not have to be reported. In addition, third-party incidents that are unknown to a credit union and hold information about individuals who happen to be credit union members or employees do not impose a notification requirement.

How Should Incidents Be Reported?

According to the final rule, incidents may be reported to the NCUA “via email, telephone or other similar methods that the NCUA may prescribe.” The reporting methods are designed to give credit unions flexibility based upon the impact of a potential cyber incident. The NCUA has also stressed that an initial report does not have to include a full assessment of the incident.

Next Steps for Credit Unions

The NCUA will be providing additional guidance, including examples of reportable and non-reportable incidents, before the final rule becomes effective in September. In the meantime, credit unions should be reviewing and updating their incident response plans and vendor management programs to ensure that they are prepared to comply with these enhanced requirements.

Comments

Popular posts from this blog

New Year’s Resolution: Getting Your Estate in Order

        Helping families and their businesses plan for the future     Your Most Important New Year’s Resolution: Getting Your Estate in Order   Happy New Year to all. Every January, millions of Americans resolve to lose weight, exercise more, or learn a new skill. These are admirable goals. But there’s one resolution that matters more than all of them combined—one that most people avoid because it forces them to confront their own mortality. Get your estate in order. Not next year. Not when you retire. Now. The Problem With Tomorrow Here’s what I see constantly...

Leasing Set To Surge In 2026?—Credit Unions May Miss Out If They Don’t Move

  CINCINNATI—As credit unions look to revive auto lending in 2026 after a sluggish year, one lending tool may become indispensable: vehicle leasing. With new-car prices still historically high, negative equity rising, and manufacturers fighting for market share, leasing is poised for a major rebound this year—and credit unions that remain on the sidelines risk losing out on strong, recurring loan volume. That’s the message from Scot Hall, executive vice president at  Swapalease.com , who says the economic and market dynamics heading into 2026 are aligning in ways that make leasing not only attractive, but essential. “Prices are up and they’re not coming down anytime soon,” Hall said, noting that inflation, tariffs, supply volatility, and chip-related uncertainty continue to push vehicle pricing higher. “Leasing is a great way to combat that. It’s also a great way to get somebody out of negative equity in a relatively short period of time.” Market Conditions Are Setting the Sta...

NCUA Issues 2026 Supervisory Priorities Letter to Credit Unions

Alexandria, VA (January 14, 2026)  ― The National Credit Union Administration (NCUA) today announced its 2026 Supervisory Priorities, which continue the agency’s policy of “No Regulation by Enforcement,” while prioritizing safety and soundness. This policy underscores NCUA’s commitment to providing clarity and transparency in its oversight. The letter outlines NCUA’s priorities for the year and provides information to help credit unions prepare for examinations. This year, the agency will continue to focus on risk-based supervision, tailoring the examination scope to the credit union’s unique risk profile. Key Highlights of the 2026 Supervisory Priorities: Risk-Focused Examinations:  Examiners will concentrate on areas posing the greatest risk to credit union members, the credit union system, and the Share Insurance Fund. Balance Sheet Management and Lending:  With loan performance at its weakest point in over a decade, examiners will review credit risk management practic...

A 10% Cap, A Busy Congress, And Big Stakes For Credit Unions This Week

WASHINGTON—Credit union trade groups entered the week in Washington closely monitoring developments after President Trump’s proposal for a nationwide 10% cap on credit card interest rates, even as Congress returns to work on funding, financial services reform, and digital asset legislation. Both the Defense Credit Union Council and America’s Credit Unions say the rate-cap proposal poses an immediate threat to consumers credit unions disproportionately serve, while a fast-moving legislative agenda could shape the industry’s operating landscape for years. DCUC President and CEO Anthony Hernandez said the defense-focused trade group mobilized within hours of the President’s announcement, warning the cap could sharply limit access to credit for junior enlisted servicemembers, young officers with student loan debt, and federal workers already strained by a potential shutdown. Anthony Hernandez Hernandez said DCUC began responding within hours, providing comments to the press Friday night an...

Syracuse Fire Department Credit Union

 Congrats, Tonia, on your promotion! ================================================= Remember, you're not alone with  NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

What Could Tokenized Deposits Mean for CUs?

WASHINGTON—Noting that the FDIC has expressed support for tokenized deposits as insured bank liabilities, not experimental digital assets, a new analysis offers some insights into what that could mean for financial institutions, credit unions and the market in 2026 and beyond.  As PYMNTS Intelligence pointed out in its report, regulatory clarity reduces risk for banks moving from pilots to live deployments, and large banks and infrastructure providers are already testing real-world tokenized deposit use cases.  “At its simplest, tokenization converts an existing claim into a digital representation on a distributed ledger,” the report explained. “The underlying asset does not change, but the infrastructure that tracks ownership and settlement does. In banking, that distinction is critical. Tokenized deposits do not create new money. They represent traditional bank deposits, issued and redeemed by regulated institutions but designed to operate on modern, programma...

IRS Issues Ruling on Federal Credit Unions and COVID Credit

WASHINGTON–The Internal Revenue Service has issued a ruling that credit unions can receive a 2021 COVID Credit, but not 2020. In other words, federally chartered CUs can’t claim the employee retention credit for periods in 2020 but can do so for periods in 2021, because later amendments to the terms of the credit made them eligible, according to the IRS. Specifically, FCUs can’t claim the credit for wages paid after March 12, 2020, and before Jan. 1, 2021. The ruling was issued by the IRS Office of Chief Counsel in a newly released legal  memorandum . According to the IRS, FCUs are able to claim the credit for wages paid after Dec. 31, 2020, and before Oct. 1, 2021, the IRS said. The Employee Retention Credit (ERC) – sometimes called the Empl...

The 10-Year Fixed-Rate Mortgage Worth Bragging About

Sound like anyone we know? “Approximately half of its membership is 50 years old or older, says Star One marketing manager Susanna Fong. The 10-year mortgage is meant to entice those members close to retirement to bring their loans — including the remainder of a 30-year-mortgage — to the credit union.” How Star One’s 14-month-old mortgage product attracts both young professionals and soon-to-be retirees. By Erik Payne creditunions.com For borrowers nearing retirement, desirable mortgage options are limited. Long-term loans can extend into retirement years and cut into savings earmarked for food, travel, and other expenses. Short-term loans can make budgeting difficult for the remaining working years. Star One Credit Union ($7.2B, Sunnyvale, CA) understands that borrowers want to be free of loan obligations before they leave the workforce without breaking the bank to do so. So in January of 2014, the credit union introduced a promotional 10-year fixed-rate mortgage that charges no...

NCUA Board to Deal With Interest Rate Risk, Loan Workouts, Derivatives

First meeting of 2012 set for next week, includes issues of considerable importance to credit unions. The agency said in its proposed rule that federally insured credit unions with assets of more than $50 million and smaller ones with potentially risky loan portfolios are required to have policies to evaluate the institution’s interest rate risk exposure, set risk limits and test for interest rate shocks. Federally insured credit unions with assets of $10 million to $50 million would have to comply if they hold first mortgages and investments with maturities greater than five years that are equal to or greater than 100% of their net worth.   Read More; NCUA Board to Deal With Interest Rate Risk, Loan Workouts, Derivatives :

Beware of CD Alternatives Being Pushed By Banks

One of my readers told me in an email that an investment guy at his bank was trying to sell him on bonds while he was redeeming a matured CD. In the last month I also have seen this. While I was at PNC and Chase, the bankers referred me to one of their investment advisors. It should be noted that you may also see this at credit unions. Some examples at large credit unions include Golden 1 Investment Services and BECU Investment Services . So I thought it was worth repeating the following advice from Clark Howard :  ***** Read More; Beware of CD Alternatives Being Pushed By Banks : Deposit Accounts