Skip to main content

What CUs Need to Know About the New Cyber Incident Reporting Requirements

The NCUA’s final rule goes into effect on Sept. 1.

reported data breach Image: Shutterstock

The NCUA has approved new cyber incident reporting requirements for credit unions. Under the final rule, federally insured credit unions will be required to notify the NCUA of a “reportable cyber incident” within 72 hours of such an event. The NCUA’s final rule follows the 36-hour notification requirement implemented for banking organizations last year. While the final rule doubles the reporting time for credit unions, it also could require credit unions to notify the NCUA of a significantly broader set of incidents than required for banking organizations. The final rule continues the trend of regulators increasing their focus on the cybersecurity safeguards among financial institutions and, in particular, of requiring faster notifications when incidents occur.

The final rule will go into effect on Sept. 1, 2023. Here, we’ll provide a primer about the rule and proactive steps credit unions should be taking in anticipation of these new reporting requirements.

What Is a Reportable Cyber Incident?

The rule requires credit unions to notify the NCUA no later than 72 hours after it reasonably believes a reportable cyber incident has occurred. A reportable cyber incident is defined as any substantial cyber incident that leads to:

  • A substantial loss of confidentiality, integrity or availability of a network or member information system that results from the unauthorized access to or exposure of sensitive data, disrupts vital member services, or has a serious impact on the safety and resiliency of operational systems and processes;
  • A disruption of business operations, vital member services, or a member information system resulting from a cyberattack or exploitation of vulnerabilities; and/or
  • A disruption of business operations or unauthorized access to sensitive data facilitated through, or caused by, a compromise of a CUSO, cloud service provider, managed service provider, or other third-party data hosting provider or a supply chain compromise.

Examples of Reportable Incidents

The NCUA’s final rule contained some examples of what may constitute a reportable cyber incident, including, without limitation:

  • If a member information system has been unlawfully modified and/or sensitive data has been left exposed to an unauthorized person, process or device;
  • A failed system upgrade or change that results in unplanned widespread user outages for credit union members and employees; or
  • A distributed denial of service (DDoS) attack that disrupts member account access.

The rule does state that incidents such as unsuccessful malware attacks or failed attempts to gain access to systems do not have to be reported. In addition, third-party incidents that are unknown to a credit union and hold information about individuals who happen to be credit union members or employees do not impose a notification requirement.

How Should Incidents Be Reported?

According to the final rule, incidents may be reported to the NCUA “via email, telephone or other similar methods that the NCUA may prescribe.” The reporting methods are designed to give credit unions flexibility based upon the impact of a potential cyber incident. The NCUA has also stressed that an initial report does not have to include a full assessment of the incident.

Next Steps for Credit Unions

The NCUA will be providing additional guidance, including examples of reportable and non-reportable incidents, before the final rule becomes effective in September. In the meantime, credit unions should be reviewing and updating their incident response plans and vendor management programs to ensure that they are prepared to comply with these enhanced requirements.

Comments

Popular posts from this blog

A Perfect Example - What Makes Credit Unions Different from Banks!

When the government shutdown hit in October and paychecks stopped, thousands of federal employees were left wondering how to make ends meet. Credit unions across the country stepped up—but Keesler Federal Credit Union went above and beyond. No loans, no hassle—just your paycheck Instead of making members apply for emergency loans, Keesler Federal launched its Paycheck Relief Program. Revolutionary in its simplicity, it worked like this: if you were a federal employee with direct deposit at Keesler Federal, your paycheck kept coming—interest-free, fee-free, and stress-free. Each qualified member could receive up to $6,000 per pay period for as long as 90 days. No hoops, no headaches. From October 1 until the shutdown ended, Keesler Federal advanced more than 5,000 paychecks totaling $6.5 million to 1,710 members. For non-members, they even offered zero-interest loans up to $6,500 with a year to pay it back. This proactive approach meant that before the first missed paycheck, Keesler Fed...

Sunday Reading - What's the point of a consumer electronics show?

  What's the point of a consumer electronics show? Consumer electronics shows are large convention-type events where companies debut new technologies and products. The largest and most notable shows are CES in Las Vegas, a trade show every January, and IFA Berlin, which takes place annually in September. The events have historically introduced novel, cutting-edge products that later became household standards, like HDTVs, VCRs, DVDs, and gaming consoles ( see list ).   Over time, these shows evolved from product showcases ( see last year's coolest gadgets ) into complex industry ecosystems, serving as a meeting ground for startups, multinational technology companies, investors, and the media. Hardware launches, keynote speeches, and...

Eight Credit Unions Pay $42 Million in Special Dividends to 1.1 Million Members

  By  Jim DuPlessis   | January 05, 2026 at 04:00 PM So far this season, CU Times has tallied 19 credit unions, which have announced $160.3 million in special dividends for members.       Eight more credit unions have reported special dividends, paying their 1.1 million members $42.1 million in December and January. The bulk of the dividends came from Police and Fire Federal Credit Union of Philadelphia and Eastman Credit Union of Kingsport, Tenn., which each announced $16 million in rewards approved by their boards. The late January payout from Eastman ($9.7 billion, 356,492 members) will bring its total special dividends to $225 million since 1998. A news release from the credit union said “the Extraordinary Dividend is never guaranteed, but the strong financial performance of ECU in 2025 enabled the Board of Directors to approve this year’s $16 million payout.” Eastman’s $16 million payout represents about $47 per member and 19 basis points of its averag...

Sunday Reaing - Can the seasons really make you depressed?

    Can the seasons really make you depressed? Seasonal affective disorder   is a form of depression that repeats during predictable seasonal shifts, impacting an estimated 5% of the global population—predominantly women. Symptoms of the condition occur with significant cyclical changes in daylight hours, with prevalence increasing in regions north of 40 degrees latitude (less commonly in the Southern Hemisphere). Its etiology—or root cause—remains unclear to researchers. Though “winter blues” are commonly reported, SAD is a distinct, diagnosed subtype of major depressive disorder first formally described in 1984 ( see criteria ). Key symptoms—lasting roughly four months each year—resemble common depression: fatigue, increased sleep, carbohydrate cravi...

Syracuse Fire Department Credit Union

 Congrats, Tonia, on your promotion! ================================================= Remember, you're not alone with  NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

ADA Uncertainty Continues

WASHINGTON —Due to the uncertainty that continues to surround how the Americans with Disabilities Act applies to websites and online access, credit unions continue to be hit with lawsuits alleging violations. As a result, CUNA reported it has just filed two briefs in Ohio and Texas related to such litigation with the trade group saying finding a solution remains a top priority. “This kind of advocacy is only part of our 360-degree approach to finding a permanent solution for credit unions facing these predatory lawsuits,” said CUNA President/CEO Jim Nussle. “As we work with Congress and the Department of Justice, filing briefs with our state leagues will help make an impact in the legal arena.” CUNA filed a brief with the Ohio Credit Union League in the Southern District of Ohio in  Mitchell v. BMI FCU , and with the Cornerstone Credit Union League in the Southern District of Texas in  Thurston v. KBR Heritage FCU . CUNA has joined with leagues to file brief...

The Federal Reserve “will act as appropriate to sustain the expansion,” Chairman Jerome Powell

JACKSON HOLE, Wyo.–In comments at the conclusion of the Fed’s annual summer retreat here, Federal Reserve Chairman Jerome Powell said objective is to maintain the economic expansion, but also made an indirect reference to President Trump’s tariffs by saying “trade policy uncertainty” was the new challenge. Less than an hour after delivering his comments, Trump tweeted the Fed has done “NOTHING” and then added, “My only question is, who is our biggest enemy, Jay Powell or Chairman Xi?” During his prepared statement, on several occasions Powell said the Fed “will act as appropriate to sustain the expansion,” adding that when it comes to the Fed’s dual mandate on full employment and price stability, the “economy is close to both goals.”   “Our challenge now is to do what monetary policy can do to sustain the expansion so that the benefits of the strong jobs market extend to more of those still left behind, and so that inflation is centered...

Auto Link, Home Link, and CalcuLink Unite Under New Parent Brand: Centergy Solutions

Auto Link, Home Link, and CalcuLink Unite Under New Parent Brand: Centergy Solutions Auto Link announced a major rebrand that unifies its three established product lines- Auto Link, Home Link, and CalcuLink- under one cohesive parent brand. The transition marks a strategic evolution designed to simplify the company’s ecosystem, strengthen product synergy, and enhance the overall experience for credit unions and the members they serve. The new Centergy Solutions brand reflects the company’s mission to deliver a more connected and integrated suite of digital tools across auto and home lending, auto and home buying, and financial decision-making. From an operational perspective, the unified brand also allows Centergy Solutions to accelerate innovation and improve platform alignment. Under the new parent brand: • Auto Link continues to support financial institutions with industry-leading digital auto lending tools that boost member engagement and loan volume. • Home Link provides consume...

Temporary Corporate Credit Union Share Guarantee Expires December 31, 2012

NCUA LETTER TO CREDIT UNIONS NATIONAL CREDIT UNION ADMINISTRATION 1775 Duke Street, Alexandria, VA 22314 DATE: March 2012 LETTER No.: 12-CU-03 TO: Federally Insured Credit Unions SUBJ: Temporary Corporate Credit Union Share Guarantee Expires December 31, 2012 Page Content ​ Dear Board of Directors and Chief Executive Officers: We are entering the final phase in the successful stabilization of the corporate credit union system. By the end of this year, all products and services offered by conserved corporate credit unions will be seamlessly transitioned to other providers – with no interruption of service to members. In the meantime, all ongoing corporate credit unions are meeting NCUA’s higher regulatory standards for capital, investments, and governance. ***READ COMPLETE LETTER; Temporary Corporate Credit Union Share Guarantee Expires December 3...

Become a Royal Credit Union

Welcome Royal Member Services Royal Member Services About Royal   We stand behind the most dependable automotive service plans in the business. We offer a range of automotive service plans for new and used vehicles that provide exceptional protection against repair costs while increasing dealer value on each and every sale. Our plans are backed by more than 50 years of dependability and customer satisfaction. We offer a world-class service organization, marketing, training, and a complete line of services. We have plans to fit most every vehicle and consumer budget. Call today and put Roya...