A binding notification rule, with two paths
The OCC, Federal Reserve and FDIC adopted the joint computer-security incident notification rule in November 2021. A bank must notify its primary federal regulator as soon as possible, and no later than 36 hours after determining that a qualifying notification incident occurred. This is not a universal 36-hour deadline beginning with every security alert. [1, 2]
Bank service providers have a separate obligation: notify affected customer banks as soon as possible after determining that a covered incident materially disrupted or degraded, or is reasonably likely to disrupt or degrade, covered services for four or more hours. The four-hour language describes the disruption threshold, not permission to delay every notice for four hours. [1, 3]
Operational harm matters alongside data theft
The rule addresses actual harm to confidentiality, integrity or availability and a materiality threshold for bank notification. A significant system failure can matter even without a hacker or stolen records. Assess customer access, business operations and the relevant financial-system implications using the rule’s definitions. [1, 2]
Analysis: incident response often starts with a technical severity label. The notification decision needs a business-impact assessment as well. A small component failure may interrupt all payment posting, while a noisy attempted intrusion may be contained without the qualifying effect. Map critical services to customer and balance-sheet consequences.
Keep a defensible timeline
Recommended timeline fields include first alert, triage, confirmed facts, expected duration, materiality determination, regulatory notice, customer communication and restoration validation. Record who made each assessment and what was known then. Later facts can change the analysis; retain earlier judgments rather than rewriting the incident history.
The deadline should not become the target. A bank that knows it has a qualifying event should follow the as-soon-as-possible requirement, using the appropriate supervisory contact. Initial notification and a final forensic report serve different purposes. Build backup contacts and a communication path that survives failure of the normal collaboration system.
Supplier notice and bank notice are distinct
Illustrative operating responsibilities:
Scroll horizontally to see all columns.
| Actor | Decision | Control evidence |
|---|---|---|
| Service provider | Does the covered-services disruption meet its trigger? | Impact estimate, affected-bank list and notice record |
| Bank incident owner | What customer/business functions are affected? | Independent service-impact assessment |
| Bank notification owner | Has the bank determined a notification incident occurred? | Dated determination and supervisory communication |
| Recovery owner | Can restored records be trusted? | Reconciliation, duplicate checks and unresolved exceptions |
Worked example: payment processing outage
Hypothetical: a provider’s error interrupts loan-payment posting at 09:00. At 10:15 it determines that material disruption is likely to last six hours. The provider should assess its notification obligation then, rather than wait for the fourth elapsed hour. The bank evaluates its own impact and makes its own notification determination; receipt of a vendor email is not automatically that determination.
After restoration, 2,000 payment files may still require reconciliation. Showing the website as available does not establish that every account was posted correctly. Confirm duplicates, fees, effects and customer notices. Recovery controls and the regulator-notification clock must run in parallel.
Integration with the wider response program
Analysis: run a single incident record with separate obligation tracks for the bank rule, applicable privacy law, contractual reporting and customer remediation. Combining the tracks into one longest deadline invites error. Conversely, indiscriminately reporting every alert can obscure the most consequential incidents.
Measure time to impact assessment, notice delivery and verified recovery. Tabletop exercises should include a weekend, unreachable supplier contact and corrupted rather than merely unavailable records. Revisit after material sourcing changes or revised agency instructions. These are operating recommendations; applicability and the precise legal trigger come from the rule, not the example.
Sources
- 1. OCC Bulletin 2021-55; November 23, 2021Official sourceBack to text: ↑1↑2↑3
- 2. Interagency final rule; November 2021Official release · PDFBack to text: ↑1↑2
- 3. FDIC FIL-74-2021; November 18, 2021Official sourceBack to text: ↑