News & Analysis as of

Cyber Incident Reporting Cybersecurity Financial Institutions

Mayer Brown Free Writings + Perspectives

SIFMA and Other Industry Groups Petition SEC for Recission of Cybersecurity Disclosure Requirement

In late May 2025, the Securities Industry and Financial Markets Association (SIFMA), together with the American Bankers Association, Bank Policy Institute, Independent Community Bankers of America, and Institute of...more

Barnea Jaffa Lande & Co.

DORA for Tech Vendors - What You Should Know (But Haven’t Asked)

DORA (Digital Operational Resilience Act) is an EU regulation that sets rules for how financial entities manage ICT (Information and Communication Technology) risks. It covers areas like cyber resilience, incident reporting,...more

A&O Shearman

FSB publishes finalised format for FIRE framework

A&O Shearman on

The Financial Stability Board (FSB) has published its finalised Format for Incident Reporting Exchange (FIRE), together with a press release and updated webpage. FIRE provides a standardised format for financial institutions...more

BCLP

Cybersecurity Risks for Financial Services Firms: Proactive Strategies to Stay Ahead

BCLP on

The 2024 CrowdStrike outage and the ransomware attack on NHS partner Synnovis hit mainstream news and highlighted the fragility of ICT supply chains and the risks posed by cyber incidents....more

King & Spalding

EU DORA: Are you in scope, and if so, how can you prepare?

King & Spalding on

The Digital Operational Resilience Act (DORA) establishes a harmonised and comprehensive framework for information and communication technology (ICT) risk management in the financial sector. It is a directly applicable EU...more

Constangy, Brooks, Smith & Prophete, LLP

FTC cyber breach notification rules: If you’re a non-banking financial institution, here’s what you need to know.

Financial institutions are now required to notify the Federal Trade Commission about any security breach that involves the information of 500 customers or more. The breach must be reported no later than 30 days after it is...more

Barnea Jaffa Lande & Co.

Understanding DORA: An Overview of the Digital Operational Resilience Act

The Digital Operational Resilience Act (DORA) is an EU regulatory framework, aimed at enhancing the financial sector’s ability to withstand and recover from ICT (information and communication technology) disruptions....more

Baker Donelson

[Webinar] New Privacy and Cybersecurity Regulations: What Financial Institutions Need to Know to Stay Compliant - June 13th, 10:00...

Baker Donelson on

The financial services industry has seen a litany of new data privacy and cybersecurity challenges through the first half of 2024. Financial institutions are facing unprecedented compliance hurdles resulting from the...more

Orrick, Herrington & Sutcliffe LLP

Indiana enacts SB 220 on cyber incident notification guidelines

On March 11, the Governor of Indiana signed SB 220 (the “Act”) which will add cyber incident notification guidelines for financial institutions. The Act defined the term "corporation" as the following entities organized in...more

Mitratech Holdings, Inc

Compliance Down Under: Understanding Australian Regulation CPS 230

The Australian Prudential Regulation Authority (APRA) released Prudential Standard CPS 230 in March 2017. At a glance, the regulation aims to strengthen the cybersecurity resilience and operational risk management of the...more

Wyrick Robbins Yates & Ponton LLP

Empire State of Security: New York DFS Finalizes Significant Amendment to Financial Services Cybersecurity Regulation

The New York State Department of Financial Services (“NYDFS”), which regulates financial services institutions including banks, insurance companies, and mortgage brokers, finalized an amendment to its Cybersecurity Regulation...more

Polsinelli

FTC Adopts Data Breach Notification Obligations for Non-Banking Financial Institutions

Polsinelli on

On October 27, 2023, the Federal Trade Commission (“FTC”) adopted an amendment to the FTC’s Safeguards Rule that will require non-banking financial institutions to notify the FTC within thirty days of discovering a data...more

Katten Muchin Rosenman LLP

New FTC Rule Requires Certain Financial Institutions to Report Loss of Unencrypted Customer Data

On October 27, the Federal Trade Commission (FTC or Commission) published a final rule expanding data breach notification requirements for certain financial institutions (Final Rule). Federal Register, will require entities...more

Jenner & Block

Client Alert: SEC’s Approach to Enforcement After Cyber Incidents: Key Takeaways for Public Companies from a Recent Speech

Jenner & Block on

Last month, Gurbir Grewal, the Director of the SEC’s Division of Enforcement, spoke at the Financial Times Cyber Resilience Summit. During the remarks, he outlined the importance of cybersecurity and signaled that the SEC is...more

Orrick, Herrington & Sutcliffe LLP

FSB: Greater convergence needed in cyber-incident reporting

On April 13, the Financial Stability Board (FSB) released a series of recommendations for achieving “greater convergence” in cyber-incident reporting (CIR). Issued at the request of the G-20, the final report draws from FSB’s...more

Bradley Arant Boult Cummings LLP

You Have 72 Hours: NCUA Finalizes New Cybersecurity Incident Reporting Rule for Federally Insured Credit Unions

Federally insured credit unions are now required to report a cyber incident to the National Credit Union Administration (NCUA) Board within 72 hours. This final rule was unanimously approved by the NCUA on February 17, 2023...more

Nelson Mullins Riley & Scarborough LLP

NCUA Announces New Cyber Threat Reporting Requirement

The NCUA stated the new rule, which was approved on Feb. 16, 2023, aims to mitigate cyber incidents “that [lead] to a substantial loss of confidentiality, integrity, or availability of a network or member information system...more

BakerHostetler

New York Department of Financial Services Publishes Proposed Second Amendment to Its Cybersecurity Regulation

BakerHostetler on

On Nov. 9, 2022, the New York State Department of Financial Services (NYDFS) published a proposed second amendment to its cybersecurity regulation. This follows its pre-proposed amendment that was published on July 29. ...more

Wiley Rein LLP

New York State Department of Financial Services Proposes Updates to Cybersecurity Regulation

Wiley Rein LLP on

On July 29, 2022, the New York Department of Financial Services (DFS) released Draft Amendments to its Part 500 Cybersecurity Rules. These changes are open for a preliminary public comment until August 18, and then an...more

Sheppard Mullin Richter & Hampton LLP

Fed Reports on Cybersecurity and Financial System Resilience

Recently, the Federal Reserve Board (Fed) published its annual Cybersecurity and Financial System Resilience report describing measures it has taken to strengthen cybersecurity in the financial services sector, including the...more

Goodwin

Cybersecurity Remains a Key Focus Area for the SEC and FINRA

Goodwin on

Cybersecurity and technology governance remain a top area of focus for the SEC and FINRA, as the regulators continue to concentrate on improving the overall cybersecurity posture and resiliency of the financial sector. FINRA...more

Polsinelli

Federal Banking Regulators Issue New Guidance for Complying with 36 Hour Cybersecurity Incident Reporting Requirement

Polsinelli on

On March 29, 2022, federal banking regulators issued important guidance for how banking organizations can comply with the upcoming requirement to notify regulators within 36 hours of ransomware or other disruptive...more

Goodwin

CFPB Launches New Initiative Focused on Rural Communities

Goodwin on

In This Issue. The Consumer Financial Protection Bureau (CFPB) announced a new initiative focused on financial issues faced by rural communities and also updated its examination procedures to cover unfair discrimination; the...more

Herbert Smith Freehills Kramer

Federal Bank Regulators Approve New Cybersecurity Incident Notification Rule

On Nov. 18, 2021, federal bank regulatory agencies approved a final rule requiring banking organizations to notify regulators of “any significant computer-security incident” as soon as possible and no later than 36 hours...more

Goodwin

SEC to Propose Cybersecurity Risk Governance Disclosures—Commissioner Roisman Shares His Views

Goodwin on

SEC Commission Elad Roisman recently spoke about cybersecurity threats and challenges facing the agency’s registrants, including public companies and financial institutions. One source of challenges (our words, not Roisman’s)...more

33 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide