Skip to main content

What CUs Need to Know About the New Cyber Incident Reporting Requirements

The NCUA’s final rule goes into effect on Sept. 1.

reported data breach Image: Shutterstock

The NCUA has approved new cyber incident reporting requirements for credit unions. Under the final rule, federally insured credit unions will be required to notify the NCUA of a “reportable cyber incident” within 72 hours of such an event. The NCUA’s final rule follows the 36-hour notification requirement implemented for banking organizations last year. While the final rule doubles the reporting time for credit unions, it also could require credit unions to notify the NCUA of a significantly broader set of incidents than required for banking organizations. The final rule continues the trend of regulators increasing their focus on the cybersecurity safeguards among financial institutions and, in particular, of requiring faster notifications when incidents occur.

The final rule will go into effect on Sept. 1, 2023. Here, we’ll provide a primer about the rule and proactive steps credit unions should be taking in anticipation of these new reporting requirements.

What Is a Reportable Cyber Incident?

The rule requires credit unions to notify the NCUA no later than 72 hours after it reasonably believes a reportable cyber incident has occurred. A reportable cyber incident is defined as any substantial cyber incident that leads to:

  • A substantial loss of confidentiality, integrity or availability of a network or member information system that results from the unauthorized access to or exposure of sensitive data, disrupts vital member services, or has a serious impact on the safety and resiliency of operational systems and processes;
  • A disruption of business operations, vital member services, or a member information system resulting from a cyberattack or exploitation of vulnerabilities; and/or
  • A disruption of business operations or unauthorized access to sensitive data facilitated through, or caused by, a compromise of a CUSO, cloud service provider, managed service provider, or other third-party data hosting provider or a supply chain compromise.

Examples of Reportable Incidents

The NCUA’s final rule contained some examples of what may constitute a reportable cyber incident, including, without limitation:

  • If a member information system has been unlawfully modified and/or sensitive data has been left exposed to an unauthorized person, process or device;
  • A failed system upgrade or change that results in unplanned widespread user outages for credit union members and employees; or
  • A distributed denial of service (DDoS) attack that disrupts member account access.

The rule does state that incidents such as unsuccessful malware attacks or failed attempts to gain access to systems do not have to be reported. In addition, third-party incidents that are unknown to a credit union and hold information about individuals who happen to be credit union members or employees do not impose a notification requirement.

How Should Incidents Be Reported?

According to the final rule, incidents may be reported to the NCUA “via email, telephone or other similar methods that the NCUA may prescribe.” The reporting methods are designed to give credit unions flexibility based upon the impact of a potential cyber incident. The NCUA has also stressed that an initial report does not have to include a full assessment of the incident.

Next Steps for Credit Unions

The NCUA will be providing additional guidance, including examples of reportable and non-reportable incidents, before the final rule becomes effective in September. In the meantime, credit unions should be reviewing and updating their incident response plans and vendor management programs to ensure that they are prepared to comply with these enhanced requirements.

Comments

Popular posts from this blog

New Year’s Resolution: Getting Your Estate in Order

        Helping families and their businesses plan for the future     Your Most Important New Year’s Resolution: Getting Your Estate in Order   Happy New Year to all. Every January, millions of Americans resolve to lose weight, exercise more, or learn a new skill. These are admirable goals. But there’s one resolution that matters more than all of them combined—one that most people avoid because it forces them to confront their own mortality. Get your estate in order. Not next year. Not when you retire. Now. The Problem With Tomorrow Here’s what I see constantly...

Leasing Set To Surge In 2026?—Credit Unions May Miss Out If They Don’t Move

  CINCINNATI—As credit unions look to revive auto lending in 2026 after a sluggish year, one lending tool may become indispensable: vehicle leasing. With new-car prices still historically high, negative equity rising, and manufacturers fighting for market share, leasing is poised for a major rebound this year—and credit unions that remain on the sidelines risk losing out on strong, recurring loan volume. That’s the message from Scot Hall, executive vice president at  Swapalease.com , who says the economic and market dynamics heading into 2026 are aligning in ways that make leasing not only attractive, but essential. “Prices are up and they’re not coming down anytime soon,” Hall said, noting that inflation, tariffs, supply volatility, and chip-related uncertainty continue to push vehicle pricing higher. “Leasing is a great way to combat that. It’s also a great way to get somebody out of negative equity in a relatively short period of time.” Market Conditions Are Setting the Sta...

NCUA Issues 2026 Supervisory Priorities Letter to Credit Unions

Alexandria, VA (January 14, 2026)  ― The National Credit Union Administration (NCUA) today announced its 2026 Supervisory Priorities, which continue the agency’s policy of “No Regulation by Enforcement,” while prioritizing safety and soundness. This policy underscores NCUA’s commitment to providing clarity and transparency in its oversight. The letter outlines NCUA’s priorities for the year and provides information to help credit unions prepare for examinations. This year, the agency will continue to focus on risk-based supervision, tailoring the examination scope to the credit union’s unique risk profile. Key Highlights of the 2026 Supervisory Priorities: Risk-Focused Examinations:  Examiners will concentrate on areas posing the greatest risk to credit union members, the credit union system, and the Share Insurance Fund. Balance Sheet Management and Lending:  With loan performance at its weakest point in over a decade, examiners will review credit risk management practic...

A 10% Cap, A Busy Congress, And Big Stakes For Credit Unions This Week

WASHINGTON—Credit union trade groups entered the week in Washington closely monitoring developments after President Trump’s proposal for a nationwide 10% cap on credit card interest rates, even as Congress returns to work on funding, financial services reform, and digital asset legislation. Both the Defense Credit Union Council and America’s Credit Unions say the rate-cap proposal poses an immediate threat to consumers credit unions disproportionately serve, while a fast-moving legislative agenda could shape the industry’s operating landscape for years. DCUC President and CEO Anthony Hernandez said the defense-focused trade group mobilized within hours of the President’s announcement, warning the cap could sharply limit access to credit for junior enlisted servicemembers, young officers with student loan debt, and federal workers already strained by a potential shutdown. Anthony Hernandez Hernandez said DCUC began responding within hours, providing comments to the press Friday night an...

Syracuse Fire Department Credit Union

 Congrats, Tonia, on your promotion! ================================================= Remember, you're not alone with  NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

IRS Issues Ruling on Federal Credit Unions and COVID Credit

WASHINGTON–The Internal Revenue Service has issued a ruling that credit unions can receive a 2021 COVID Credit, but not 2020. In other words, federally chartered CUs can’t claim the employee retention credit for periods in 2020 but can do so for periods in 2021, because later amendments to the terms of the credit made them eligible, according to the IRS. Specifically, FCUs can’t claim the credit for wages paid after March 12, 2020, and before Jan. 1, 2021. The ruling was issued by the IRS Office of Chief Counsel in a newly released legal  memorandum . According to the IRS, FCUs are able to claim the credit for wages paid after Dec. 31, 2020, and before Oct. 1, 2021, the IRS said. The Employee Retention Credit (ERC) – sometimes called the Empl...

What Could Tokenized Deposits Mean for CUs?

WASHINGTON—Noting that the FDIC has expressed support for tokenized deposits as insured bank liabilities, not experimental digital assets, a new analysis offers some insights into what that could mean for financial institutions, credit unions and the market in 2026 and beyond.  As PYMNTS Intelligence pointed out in its report, regulatory clarity reduces risk for banks moving from pilots to live deployments, and large banks and infrastructure providers are already testing real-world tokenized deposit use cases.  “At its simplest, tokenization converts an existing claim into a digital representation on a distributed ledger,” the report explained. “The underlying asset does not change, but the infrastructure that tracks ownership and settlement does. In banking, that distinction is critical. Tokenized deposits do not create new money. They represent traditional bank deposits, issued and redeemed by regulated institutions but designed to operate on modern, programma...

7 Things to Do (And Avoid) with SMS/Text in Credit Union Marketing

By not using SMS text messaging for marketing, you are missing a channel with a 98% open rate and a rapid response rate. Consumers love the convenience and are open to receiving personalized and relevant texts from their bank and credit union. Naturally there are some caveats to be aware of. Here are seven pointers. Are you content to have your customers take 90 minutes to respond back to a communication you’ve sent, or would 90 seconds be better? That’s the difference in average response times between email and SMS text. Then there is the open rate: SMS texts have high open rates — up to 98%, according to Gartner and 82% by another source. The average open rate of email is around 20%. If you send an email with a link to a survey to find out what a consumer thinks about the virtual meeting with a lending officer they just had, it may linger in the consumers’ inbox for days, at which point the experience is no longer top-of-mind or the consumer decides to simply delete the ...

Working at Home will Upset Banks & Credit Unions

Permanent Working at Home Will Rock Banks and Credit Unions The longer Americans' office at home, the better it may look to both workers and employees. No commuting, more living and the chance to work in sweatpants all the time. But the ripple effects will hit many industries, including financial institutions large and small.   READ ARTICLE   _________________________________________________________________________ Some Helpful Links You can track your stimulus check, starting this week How to get the coronavirus tracking app from Apple, Google Make a face mask at home News, advice and more about COVID-19

NCUA: Unlimited Share Insurance for Credit Unions Set to Expire at Year End

http://www.viningsparks.com/     The NCUA recently issued a Letter to Credit Unions regarding the scheduled expiration of two insurance coverage programs on December 31, 2012.     The Temporary Corporate Credit Union Share Guarantee Program and the unlimited Share Insurance Fund coverage for non-interest-bearing transaction accounts will expire.     On January 1, 2013, NCUA share insurance coverage on deposits in corporate credit unions and non-interest-bearing transaction accounts will be limited to the standard maximum share insurance amount of $250,000. The insurance coverage is currently unlimited.     Credit unions should evaluate their uninsured corporate account holdings and perform appropriate due diligence for credit risk implications. If you have any questions on how this may affect your credit union contact; Vining Sparks a GOLD Sponsor of NCOFCU Lee Chandler Senior Vice President Office 800-78...