Influencing policy: Cyber and Data Security
ICBA Expert Contact
Agency Guidance & Regulations
Community banks are navigating an increasingly complex cybersecurity landscape, shaped by evolving regulatory expectations, emerging threats, and industry best practices.
For ICBA members, key touchpoints include cybersecurity and information security guidance from the Federal Reserve, the Office of the Comptroller of the Currency (OCC), the Federal Deposit Insurance Corporation (FDIC), and the Federal Financial Institutions Examination Council (FFIEC).
Federal Reserve
- 12 CFR Part 225 (Bank Holding Companies)
Office of the Comptroller of the Currency (OCC)
- 12 CFR Part 30 (Safety and Soundness Standards)
- 12 CFR Part 53 (Computer-Security Incident Notification Requirements)
Federal Deposit Insurance Corporation (FDIC)
- 12 CFR Part 304 (Cyber incident notification)
- 12 CFR Part 364 (Computer-security Incident Notification Requirements)
Securities and Exchange Commission (SEC)
- 17 CFR Part 242 (Systems Compliance, Cybersecurity & Operations Resilience (Reg SCI)
- 17 CFR Part 248 (Customer Information Security & Privacy Safeguards)
- Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure Rule (2023)
U.S. Department of Treasury
- 31 CFR Part 1020 (Bank Secrecy Act Requirements)
Federal Trade Commission (FTC)
- 16 CFR Part 314 (Safeguards Rule)
U.S. Department Homeland Security
- Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)
NIST Frameworks
- NIST Cybersecurity Framework (CSF 2.0) - Supports identifying, protecting against, detecting, responding to, and recovering from cyber threats.
- NIST Cybersecurity Risk Management Framework (RMF) - Supports managing cybersecurity risk throughout the system lifecycle.
- NIST SP 800-53 Security and Privacy Controls for Information Systems and Organizations
- Interagency Guidance on Third-Party Risk Management - Issued by the Federal Reserve, OCC, and FDIC for managing risks associated with vendors, fintech partners, cloud service providers, and other third parties.
FFIEC Guidance
- FFIEC Information Security Booklet - Covers governance, risk management, security operations, threat intelligence, incident response, and information security program expectations.
- FFIEC Business Continuity Management Booklet - Addresses business continuity planning, disaster recovery, cyber resilience, third-party disruptions, and operational continuity.
Cyber and data security continues to be a top concern for community banks as cyber threats, fraud schemes, third-party risks, and data-sharing requirements become ever more complex.
Advances in AI and digital banking are creating new opportunities and new security considerations, making strong governance, resilience, and risk management top priorities.
Key Issues Community Bankers Should Watch
AI-Enabled Cyber Threats: The growing use of AI is increasing both cyber risk and the need for responsible AI governance.
Third-Party & Vendor Risk: Regulators and policymakers continue to focus on the security of companies that access, store, or process customer financial data.
Data Sharing & Open Banking: Expanded customer data access requirements are elevating concerns around privacy, security, liability, and third-party oversight.
Fraud & Cybercrime: Ransomware, data breaches, and progressively more sophisticated fraud attacks remain significant risks for community banks and their customers.
Threat Intelligence & Resilience: Industry and government collaboration on threat sharing, incident response, and operational resilience continues to grow in importance.
ICBA advocates for risk-based cybersecurity policies that recognize the unique needs of community banks while promoting stronger protections across the broader financial ecosystem.
Policy Position and Background Information
-
Any new Federal or state legislation, regulation, or guidance related to data or cybersecurity should be non-proscriptive and non-duplicative.
-
ICBA suggests that regulators broaden their supervision to include all companies that have access to consumer financial data.
-
Regulators should not mandate the use of any one framework, tool, or assessment, but rather support community banks’ ability to use the framework, tool or assessment that best suits their institution’s size, complexity, and risk tolerance.
-
ICBA supports bi-directional sharing of threat intelligence between the financial sector and the government.
-
ICBA supports stronger cybersecurity standards and practices for government.
-
ICBA supports financial sector initiatives such as .BANK and Sheltered Harbor.
To better address increasingly sophisticated threats, state and federal legislation, regulation, and guidance should enable community banks to implement risk-based security programs. Lawmakers and regulators should harmonize future legislation or regulatory action with existing regulatory requirements. Additionally, regulators should broaden their supervision to include all companies that have access to, use, or store consumer financial data. These companies should be subject to the standards outlined in the Gramm-Leach-Bliley Act (GLBA).
Community banks have various sizes, complexities, and risk tolerances. As such, regulators should allow community banks to choose the assessment tool that best fits their institution’s risk profile.
ICBA recognizes that the U.S. Government also has a responsibility to safeguard financial and personally identifiable information (PII) and to provide banks with visibility into the government’s business continuity, incident response, and other critical resiliency plans. Bi-directional threat information sharing initiatives, such as the Financial Services Information Sharing and Analysis Center (FS-ISAC), are critical to threat mitigation.
.BANK, Sheltered Harbor, and other financial sector efforts enhance protection for bank customer account data.