It's not hard to believe that the financial services industry is a high value target for cyber threat actors. Firms in this sector are 300 times more likely to be targeted by a cyberattack and over 50% of these companies are at heightened risk of becoming a victim of ransomware.
On July 21, 2022, the National Credit Union Administration Board held its seventh open meeting of 2022 and unanimously approved a notice of proposed rulemaking on cyber incident notification requirements. The proposed rule would require federally charted credit unions to report within 72 hours any incident that leads to the "substantial loss" of confidentiality, integrity or availability of member information.
“NCUA Board approval for issuing the proposed rule before us today is a critical step to increasing cybersecurity awareness and protection within the financial system,” Chairman Todd M. Harper said.
Under the proposed rule, a federally insured credit union would be required to report a cyber incident that leads to a substantial loss of confidentiality, integrity, or availability of a member information system as a result of the exposure of sensitive data, disruption of vital member services, or that has a serious impact on the safety and resiliency of operational systems and processes. With credit unions being NCUA’s "eyes and ears," they are hoping that by credit unions reporting these cyber incidents early, they can contribute to keeping the nation secure from similar cyberattacks elsewhere.