FINANCE, POLICY & MARKETSPublished by Paul Ivinskas
fc.The Financial CurrentDAILY INTELLIGENCEWhat matters across finance
Deep-dive library

Bank cyber incidents: notification, payment continuity and recovery

5 min read · estimatedAI-generated analysis · Methodology
Current version · 2 versions · Publication details

First published . This version published .

Version history

What changed in this update

Expanded beyond notification timing to customer payment needs, shared-provider dependence and the economics of verified recovery.

Compare with an earlier version →
Related research, policy & entities ↓

At a glance

Excerpts from this version
What it covers
The 36-hour notification rule sits inside a wider problem: restoring reliable financial services when banks and shared providers are disrupted.
The customer experiences an interrupted service
A customer usually notices a failed payment or an unavailable balance before learning which system caused it. A payroll customer needs to know whether instructions were received, whether money moved and whether resubmission would duplicate the payment. An app returning online does not answer those questions. Recovery must include accurate balances and transaction status.Read in context
0% through article

Tap a dotted-underlined term for a definition; terms are highlighted once per section. Use Aa in the navigation for reading preferences.

In this article

The customer experiences an interrupted service

A customer usually notices a failed payment or an unavailable balance before learning which system caused it. A payroll customer needs to know whether instructions were received, whether money moved and whether resubmission would duplicate the payment. An app returning online does not answer those questions. Recovery must include accurate balances and transaction status.

The notification rule gives supervisors early visibility into qualifying incidents. It does not make regulatory notice a substitute for restoration or customer assistance. The OCC’s explanation covers material operational disruption as well as information harm, including incidents without malicious intent. That makes resilience relevant to routine technology changes and provider outages, not only to attackers. [1]

A binding notification rule, with two paths

The OCC, Federal Reserve and FDIC adopted the joint computer-security incident notification rule in November 2021. A bank must notify its primary federal regulator as soon as possible, and no later than 36 hours after determining that a qualifying notification incident occurred. This is not a universal 36-hour deadline beginning with every security alert. [1, 2]

Bank service providers have a separate obligation: notify affected customer banks as soon as possible after determining that a covered incident materially disrupted or degraded, or is reasonably likely to disrupt or degrade, covered services for four or more hours. The four-hour language describes the disruption threshold, not permission to delay every notice for four hours. [1, 3]

Operational harm matters alongside data theft

The rule addresses actual harm to confidentiality, integrity or availability and a materiality threshold for bank notification. A significant system failure can matter even without a hacker or stolen records. Assess customer access, business operations and the relevant financial-system implications using the rule’s definitions. [1, 2]

Analysis: incident response often starts with a technical severity label. The notification decision needs a business-impact assessment as well. A small component failure may interrupt all payment posting, while a noisy attempted intrusion may be contained without the qualifying effect. Map critical services to customer and balance-sheet consequences.

Recovery economics depend on the transaction backlog

Suppose a hypothetical incident leaves 12,000 payment instructions needing reconciliation. Reviewing each at two minutes would require 400 hours. If reliable system evidence resolves 90% automatically, the remaining 1,200 cases require 40 review hours at the same pace. The 360-hour difference measures potential capacity; it does not mean those staff costs disappear or every automated match is correct.

Speed has value only if the evidence supports the decision. Releasing an uncertain backlog can create duplicates or leave valid payments missing. The customer-facing recovery plan should distinguish confirmed payments, rejected instructions and unresolved items, with a clear next update. Those distinctions let businesses plan while technical investigation continues.

Keep a defensible timeline

Recommended timeline fields include first alert, triage, confirmed facts, expected duration, materiality determination, regulatory notice, customer communication and restoration validation. Record who made each assessment and what was known then. Later facts can change the analysis; retain earlier judgments rather than rewriting the incident history.

The deadline should not become the target. A bank that knows it has a qualifying event should follow the as-soon-as-possible requirement, using the appropriate supervisory contact. Initial notification and a final forensic report serve different purposes. Build backup contacts and a communication path that survives failure of the normal collaboration system.

Supplier notice and bank notice are distinct

Illustrative operating responsibilities:

Scroll horizontally to see all columns.

ActorDecisionControl evidence
Service providerDoes the covered-services disruption meet its trigger?Impact estimate, affected-bank list and notice record
Bank incident ownerWhat customer/business functions are affected?Independent service-impact assessment
Bank notification ownerHas the bank determined a notification incident occurred?Dated determination and supervisory communication
Recovery ownerCan restored records be trusted?Reconciliation, duplicate checks and unresolved exceptions

Shared infrastructure changes the meaning of a backup

Two service contracts may still depend on the same underlying cloud, telecommunications route or software component. Buying a second provider therefore does not by itself establish independence. A useful continuity exercise tests whether the alternate service can receive current records, handle the required volume and settle transactions when the primary path is unavailable.

Financial institutions benefit from specialization and shared infrastructure, so eliminating every dependency would be unrealistic and expensive. The business tradeoff is which functions need rapid alternatives and which can tolerate a managed delay. Evidence should include restored customer functions and reconciled payments, alongside elapsed outage time and the notification timeline.

Worked example: payment processing outage

Hypothetical: a provider’s error interrupts loan-payment posting at 09:00. At 10:15 it determines that material disruption is likely to last six hours. The provider should assess its notification obligation then, rather than wait for the fourth elapsed hour. The bank evaluates its own impact and makes its own notification determination; receipt of a vendor email is not automatically that determination.

After restoration, 2,000 payment files may still require reconciliation. Showing the website as available does not establish that every account was posted correctly. Confirm duplicates, fees, effects and customer notices. Recovery controls and the regulator-notification clock must run in parallel.

Integration with the wider response program

Analysis: run a single incident record with separate obligation tracks for the bank rule, applicable privacy law, contractual reporting and customer remediation. Combining the tracks into one longest deadline invites error. Conversely, indiscriminately reporting every alert can obscure the most consequential incidents.

Measure time to impact assessment, notice delivery and verified recovery. Tabletop exercises should include a weekend, unreachable supplier contact and corrupted rather than merely unavailable records. Revisit after material sourcing changes or revised agency instructions. These are operating recommendations; applicability and the precise legal trigger come from the rule, not the example.

Sources

  1. 1. OCC Bulletin 2021-55; November 23, 2021Official sourceBack to text: ↑1↑2↑3↑4
  2. 2. Interagency final rule; November 2021Official release · PDFBack to text: ↑1↑2
  3. 3. FDIC FIL-74-2021; November 18, 2021Official sourceBack to text: ↑

Flag an error or suggest a correction →Public corrections log →