US banks to report cybersecurity incidents within 36 hours

US banks will now have to report significant cybersecurity incidents to the government within 36 hours, according to sources reported by Bloomberg.

The news comes as banks in the UK are also facing scrutiny from regulators regarding the quality of their cyber defences.

A Bank of England (BoE) backed project set to test the IT resilience of the UK’s financial services (FS) sector was opened to FS firms of all sizes in October, according to sources reported by the Financial Times.


The US rule will apply to incidents expected to materially impact a bank's ability to conduct its operations, or which could impact the stability of the financial sector according to the sources.

Previously, there were no specific laws in the US governing how quickly banks needed to report cyber incidents.

The rule, approved by the Federal Reserve, Federal Deposit Insurance Corporation, and Office of the Comptroller of the Currency, issued on Thursday is set to come into effect on May 1.

The sources said the new rule will also impact third parties who provide services to banks.

    Share Story:

Recent Stories


Data trust in the AI era: Building customer confidence through responsible banking
In the second episode of FStech’s three-part video podcast series sponsored by HCLTech, Sudip Lahiri, Executive Vice President & Head of Financial Services for Europe & UKI at HCLTech examines the critical relationship between data trust, transparency, and responsible AI implementation in financial services.

Banking's GenAI evolution: Beyond the hype, building the future
In the first episode of a three-part video podcast series sponsored by HCLTech, Sudip Lahiri, Executive Vice President & Head of Financial Services for Europe & UKI at HCLTech explores how financial institutions can navigate the transformative potential of Generative AI while building lasting foundations for innovation.

Beyond compliance: Building unshakeable operational resilience in financial services
In today's rapidly evolving financial landscape, operational resilience has become a critical focus for institutions worldwide. As regulatory requirements grow more complex and cyber threats, particularly ransomware, become increasingly sophisticated, financial services providers must adapt and strengthen their defences. The intersection of compliance, technology, and security presents both challenges and opportunities.

Unleashing generative AI: A force multiplier for financial crime teams
This FStech webinar, sponsored by NICE Actimize sees industry experts examine the revolutionary impact of generative AI on financial crime operations, and provides actionable insights to enhance your compliance strategies.