Skip to main content
Privacy and Cybersecurity Update

U.S. Federal Bank Regulators Require Notifications For Material Cybersecurity Incidents

November 23, 2021

On November 18, 2021, a group of federal bank regulators announced a final rule requiring banks to notify their primary federal regulator of any “significant computer-security incidents.” Regulators must be notified no later than 36 hours after the bank has determined that the incident triggers the rule’s notification requirement. Further, bank service providers are now required to promptly notify all affected banks whenever a cybersecurity disruption lasts for four or more hours.

The rule is the latest regulation requiring entities that have suffered a cybersecurity incident to promptly notify a government agency. Unlike some of those regulations, this rule is not linked to compromised consumer data.

律师广告—Sidley Austin LLP 是一家全球性律师事务所。我们的地址及联系方式可在 www.sidley.com/en/locations/offices 查阅。

Sidley 提供本信息仅作为向客户及其他友好人士提供的服务,且仅供教育目的使用。本信息不应被解释或依赖为法律意见,亦不构成律师与客户关系。读者在未寻求专业顾问意见之前,不应依据本信息采取任何行动。Sidley 和 Sidley Austin 指 Sidley Austin LLP 及其关联合伙实体,详见 www.sidley.com/disclaimer

© Sidley Austin LLP

Related Blogs