The customer experiences an interrupted service
A customer usually notices a failed payment or an unavailable balance before learning which system caused it. A payroll customer needs to know whether instructions were received, whether money moved and whether resubmission would duplicate the payment. An app returning online does not answer those questions. Recovery must include accurate balances and transaction status.
The notification rule gives supervisors early visibility into qualifying incidents. It does not make regulatory notice a substitute for restoration or customer assistance. The OCC’s explanation covers material operational disruption as well as information harm, including incidents without malicious intent. That makes resilience relevant to routine technology changes and provider outages, not only to attackers. [1]
A binding notification rule, with two paths
The OCC, Federal Reserve and FDIC adopted the joint computer-security incident notification rule in November 2021. A bank must notify its primary federal regulator as soon as possible, and no later than 36 hours after determining that a qualifying notification incident occurred. This is not a universal 36-hour deadline beginning with every security alert. [1, 2]
Bank service providers have a separate obligation: notify affected customer banks as soon as possible after determining that a covered incident materially disrupted or degraded, or is reasonably likely to disrupt or degrade, covered services for four or more hours. The four-hour language describes the disruption threshold, not permission to delay every notice for four hours. [1, 3]
Operational harm matters alongside data theft
The rule addresses actual harm to confidentiality, integrity or availability and a materiality threshold for bank notification. A significant system failure can matter even without a hacker or stolen records. Assess customer access, business operations and the relevant financial-system implications using the rule’s definitions. [1, 2]
Analysis: incident response often starts with a technical severity label. The notification decision needs a business-impact assessment as well. A small component failure may interrupt all payment posting, while a noisy attempted intrusion may be contained without the qualifying effect. Map critical services to customer and balance-sheet consequences.
Recovery economics depend on the transaction backlog
Suppose a hypothetical incident leaves 12,000 payment instructions needing reconciliation. Reviewing each at two minutes would require 400 hours. If reliable system evidence resolves 90% automatically, the remaining 1,200 cases require 40 review hours at the same pace. The 360-hour difference measures potential capacity; it does not mean those staff costs disappear or every automated match is correct.
Speed has value only if the evidence supports the decision. Releasing an uncertain backlog can create duplicates or leave valid payments missing. The customer-facing recovery plan should distinguish confirmed payments, rejected instructions and unresolved items, with a clear next update. Those distinctions let businesses plan while technical investigation continues.
Keep a defensible timeline
Recommended timeline fields include first alert, triage, confirmed facts, expected duration, materiality determination, regulatory notice, customer communication and restoration validation. Record who made each assessment and what was known then. Later facts can change the analysis; retain earlier judgments rather than rewriting the incident history.
The deadline should not become the target. A bank that knows it has a qualifying event should follow the as-soon-as-possible requirement, using the appropriate supervisory contact. Initial notification and a final forensic report serve different purposes. Build backup contacts and a communication path that survives failure of the normal collaboration system.
Supplier notice and bank notice are distinct
Illustrative operating responsibilities:
Scroll horizontally to see all columns.
| Actor | Decision | Control evidence |
|---|---|---|
| Service provider | Does the covered-services disruption meet its trigger? | Impact estimate, affected-bank list and notice record |
| Bank incident owner | What customer/business functions are affected? | Independent service-impact assessment |
| Bank notification owner | Has the bank determined a notification incident occurred? | Dated determination and supervisory communication |
| Recovery owner | Can restored records be trusted? | Reconciliation, duplicate checks and unresolved exceptions |
Shared infrastructure changes the meaning of a backup
Two service contracts may still depend on the same underlying cloud, telecommunications route or software component. Buying a second provider therefore does not by itself establish independence. A useful continuity exercise tests whether the alternate service can receive current records, handle the required volume and settle transactions when the primary path is unavailable.
Financial institutions benefit from specialization and shared infrastructure, so eliminating every dependency would be unrealistic and expensive. The business tradeoff is which functions need rapid alternatives and which can tolerate a managed delay. Evidence should include restored customer functions and reconciled payments, alongside elapsed outage time and the notification timeline.
Worked example: payment processing outage
Hypothetical: a provider’s error interrupts loan-payment posting at 09:00. At 10:15 it determines that material disruption is likely to last six hours. The provider should assess its notification obligation then, rather than wait for the fourth elapsed hour. The bank evaluates its own impact and makes its own notification determination; receipt of a vendor email is not automatically that determination.
After restoration, 2,000 payment files may still require reconciliation. Showing the website as available does not establish that every account was posted correctly. Confirm duplicates, fees, effects and customer notices. Recovery controls and the regulator-notification clock must run in parallel.
Integration with the wider response program
Analysis: run a single incident record with separate obligation tracks for the bank rule, applicable privacy law, contractual reporting and customer remediation. Combining the tracks into one longest deadline invites error. Conversely, indiscriminately reporting every alert can obscure the most consequential incidents.
Measure time to impact assessment, notice delivery and verified recovery. Tabletop exercises should include a weekend, unreachable supplier contact and corrupted rather than merely unavailable records. Revisit after material sourcing changes or revised agency instructions. These are operating recommendations; applicability and the precise legal trigger come from the rule, not the example.
Sources
- 1. OCC Bulletin 2021-55; November 23, 2021Official sourceBack to text: ↑1↑2↑3↑4
- 2. Interagency final rule; November 2021Official release · PDFBack to text: ↑1↑2
- 3. FDIC FIL-74-2021; November 18, 2021Official sourceBack to text: ↑