ARTICLE
4 May 2022

Will Banks Be Able To Comply With The New 36 Hour Cyber Notification Deadlines?

FL
Foley & Lardner

Contributor

Foley & Lardner LLP looks beyond the law to focus on the constantly evolving demands facing our clients and their industries. With over 1,100 lawyers in 24 offices across the United States, Mexico, Europe and Asia, Foley approaches client service by first understanding our clients’ priorities, objectives and challenges. We work hard to understand our clients’ issues and forge long-term relationships with them to help achieve successful outcomes and solve their legal issues through practical business advice and cutting-edge legal insight. Our clients view us as trusted business advisors because we understand that great legal service is only valuable if it is relevant, practical and beneficial to their businesses.
This legislation is crucial because timely notification plays a significant role in restricting an attack's scale, especially for institutions dependent on threat intelligence for defensive capability,..
United States Technology

BankInfoSecurity.com reported that "New cyber incident reporting rules are set to come into effect in the U.S. on May 1. Banks in the country will be required to notify regulators within the first 36 hours after an organization suffers a qualifying "computer-security incident."  The April 29, 2022 report entitled "New US Breach Reporting Rules for Banks Take Effect May 1" included these comments from Marcus Fowler (senior vice president of strategy engagements and threats at cybersecurity AI firm Darktrace):

This legislation is crucial because timely notification plays a significant role in restricting an attack's scale, especially for institutions dependent on threat intelligence for defensive capability,..

Cybercriminals often conduct attacks as part of broader campaigns, including executing supply chain attacks that affect dozens of victims.

Supply chain attacks are often industry-centric because of reliance on the same or similar software or supplier for business operations.

Once a campaign is discovered, attackers often accelerate their offensive operations to scoop up as many victims as possible before defenders can put a patch in place or broadly distribute an indicator of compromise,...

Please stay tuned to see how effective these new Rules are!

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More