Banks and credit unions that are already required to urgently report information about cybersecurity incidents to multiple regulators will soon have to add one more federal government agency to the list.
The Cybersecurity and Infrastructure Agency (CISA) in September is expected to implement a final rule for the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). It would require financial institutions, and other entities in 16 critical infrastructure sectors, to report substantial cyber incidents to CISA within 72 hours and ransomware payments within 24 hours.
The new proposed measure, which defines a bare minimum threat that is “substantial,” such as a breach, will add to an already complex and duplicative web of cybersecurity incident reporting requirements imposed on financial institutions of all sizes.
Anjelica Dortch, vice president of operational risk and cybersecurity policy for the Independent Community Bankers of America (ICBA), testified to that fact on June 18 — in one of four virtual town halls CISA held on CIRCIA’s requirements. “During a cyber incident, institutions should be focused on response and recovery and not navigating multiple reporting portals and duplicative reporting requirements,” she said. “We also encourage CISA to leverage existing reporting frameworks and establish a process where information is submitted once. . .and it can be shared across appropriate federal agencies.”
Just one month after Dortch’s testimony, the U.S. Government Accountability Office (GAO) issued a report that found nearly 70% of federal cybersecurity regulations across nine industries contained reporting requirements that are redundant. The report further states that a private entity in the financial services industry faces the most potential overlap.
Caleb Skeath, a partner and cybersecurity attorney at the law firm Covington & Burling, says it is a source of frustration for the financial institutions he represents. “I think the top line message is that there are a lot of reporting frameworks and regulations out there, and that the financial sector is one of the more heavily regulated ones in terms of security requirements and breach reporting requirements — something that has been consistent across the years,” he says.
A Web of Regulation
The number and types of regulators a financial institution must file cybersecurity incident reports with is determined by who their primary federal regulator is, if they have a state or national charter and whether they are privately or publicly owned.
All banks — whether nationally chartered and directly regulated by the Office of the Comptroller of the Currency, or state chartered and regulated by the Federal Deposit Insurance Corp. or Federal Reserve — must file a cybersecurity incident report to their primary regulator within 36 hours of learning about it. All credit unions, regardless of whether they are federally or state chartered, must report cybersecurity incidents to the National Credit Union Administration within 72 hours.
In addition to their primary regulator, publicly owned banks and holding companies must also report such incidents to the U.S. Securities and Exchange Commission, but only if they determine the “incident is material.” That means it has impacted the bank’s financial condition or operations, harmed its reputation, customer or vendor relationships or competitiveness, or could result in litigation or regulatory investigations. They have four days to file the report once making that determination.
And finally, every financial institution that detects a cybersecurity incident resulting a known or suspected violation of federal law, a suspicious transaction related to a money laundering activity or a violation of the Bank Secrecy Act must also file a Suspicious Activity Report with the Financial Crimes Enforcement Network (FinCEN) within 30 days of detection.
But those are just the federal reporting requirements financial institutions must meet. Steve Sanders, chief risk officer at CSI, a provider of banking and risk management solutions, says there are several state reporting requirements as well. And they don’t just apply to state chartered institutions. “I have told a lot of banks in the past, ‘You need to understand every state you’re doing business in,’” he says. “The state laws are interesting in that you have to do a lot of research. And frankly, I would advise a bank to get a good privacy or information security attorney to help them navigate that.”
Sanders says all of those various reporting requirements can really add up during a cyber incident. “I get that call at 2 a.m., ‘Get to the office now. We’re in the war room. We’ve got a real problem.’ And you get down there, and you’re trying to figure all this out,” he says. “In the back of your mind, you’re thinking, ‘OK, who do I have to notify? I’ve got a 36-hour notification in some cases.’”
Skeath says that is especially stressful for teams that have never experienced an actual cyber attack. “I think that is because it’s really hard to anticipate how an actual incident is going to unfold, who is going to be involved in that process and what challenges you might have to deal with,” he says.
Preparing for the Worst
Congress has 60 days to review all major agency rules once they are made final. That means if CISA approves its final rule on CIRCIA in September, it could go into effect as early as November. Skeath says financial institutions have to be ready for that timeline, but he is still holding out hope the agency will strongly consider the feedback given by the ICBA and other banking groups, and perhaps narrow or modify some of the proposed requirements.
“There was a lot of feedback from those town halls about the overlap from these CIRCIA reporting requirements with other preexisting reporting requirements,” Skeath says. “And does that lead to CISA revisiting anything that had been previously proposed, or adjusting how they might be approaching that framework overall? I think that’ll be very interesting to at least keep an eye on over the next couple months.”
But Skeath and Sanders both say financial institutions should be spending some time over the next few months preparing how they will handle all their current reporting requirements, and a new one with new time frames.
“I’ve never seen a community financial institution do this — when they run their tabletop [cybersecurity incident] exercise — talk through reporting requirements, because everybody’s only talking about recovering from the breach,” Sanders says. “If I were sitting in the seat at a community or even larger financial institution, I would want to make a matrix of every law that we are required to comply with. And so, I would list the laws, I would list the reporting requirements, time frames, what’s expected and I would put that all in a matrix and that would be part of my playbook. If we have an incident, I’m pulling that sheet out, and someone is going to be responsible for making sure we meet everything on that sheet.”
Skeath says it is important to have such a plan not only to guarantee timely reporting but also to ensure you are only sharing information that is absolutely required. He advises his clients to identify one person or a few key people that can be trusted to carry out that task without saying something that could be used against the institution in a future lawsuit or regulatory investigation.
“And making sure that the other relevant stakeholders who are involved know who that person is, that can really help things flow a lot more smoothly in the event of an actual incident,” he says.