Skip to Main Content
ICBA
  • Member Login
  • Member Login

Cyber and Data Security

Influencing policy: Cyber and Data Security

See Advocacy Actions Example Text

ICBA Expert Contact

Anjelica Dortch

Vice President, Operational Risk & Cybersecurity Policy

ICBA

Contact Example Text

Agency Guidance & Regulations

Community banks are navigating an increasingly complex cybersecurity landscape, shaped by evolving regulatory expectations, emerging threats, and industry best practices. 

For ICBA members, key touchpoints include cybersecurity and information security guidance from the Federal Reserve, the Office of the Comptroller of the Currency (OCC), the Federal Deposit Insurance Corporation (FDIC), and the Federal Financial Institutions Examination Council (FFIEC).  

Federal Reserve 

  • 12 CFR Part 225 (Bank Holding Companies) 

Office of the Comptroller of the Currency (OCC) 

  • 12 CFR Part 30 (Safety and Soundness Standards) 
  • 12 CFR Part 53 (Computer-Security Incident Notification Requirements) 

Federal Deposit Insurance Corporation (FDIC) 

  • 12 CFR Part 304 (Cyber incident notification) 
  • 12 CFR Part 364 (Computer-security Incident Notification Requirements) 

Securities and Exchange Commission (SEC) 

  • 17 CFR Part 242 (Systems Compliance, Cybersecurity & Operations Resilience (Reg SCI) 
  • 17 CFR Part 248 (Customer Information Security & Privacy Safeguards) 
  • Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure Rule (2023) 

U.S. Department of Treasury  

  • 31 CFR Part 1020 (Bank Secrecy Act Requirements) 

Federal Trade Commission (FTC) 

  • 16 CFR Part 314 (Safeguards Rule) 

U.S. Department Homeland Security  

  • Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)  

NIST Frameworks 

FFIEC Guidance 

Cyber and data security continues to be a top concern for community banks as cyber threats, fraud schemes, third-party risks, and data-sharing requirements become ever more complex.

Advances in AI and digital banking are creating new opportunities and new security considerations, making strong governance, resilience, and risk management top priorities. 

Key Issues Community Bankers Should Watch 

AI-Enabled Cyber Threats: The growing use of AI is increasing both cyber risk and the need for responsible AI governance.  

Third-Party & Vendor Risk: Regulators and policymakers continue to focus on the security of companies that access, store, or process customer financial data.  

Data Sharing & Open Banking: Expanded customer data access requirements are elevating concerns around privacy, security, liability, and third-party oversight.  

Fraud & Cybercrime: Ransomware, data breaches, and progressively more sophisticated fraud attacks remain significant risks for community banks and their customers.  

Threat Intelligence & Resilience: Industry and government collaboration on threat sharing, incident response, and operational resilience continues to grow in importance.  

ICBA advocates for risk-based cybersecurity policies that recognize the unique needs of community banks while promoting stronger protections across the broader financial ecosystem. 

Be Heard Example Text

News and Articles

Policy Position and Background Information

Robust cybersecurity and data protection are critical to maintaining trust and compliance in community banking. Learn how advanced defenses and risk management strategies shield sensitive information from growing cyber threats.
Related Topics: Artificial Intelligence Example Text Cyber Security & Breaches Example Text Fraud Example Text Payments Fraud and Scams Example Text Consumer Data Access and Open Banking Example Text View All Topics

  • Any new Federal or state legislation, regulation, or guidance related to data or cybersecurity should be non-proscriptive and non-duplicative.  

  • ICBA suggests that regulators broaden their supervision to include all companies that have access to consumer financial data. 

  • Regulators should not mandate the use of any one framework, tool, or assessment, but rather support community banks’ ability to use the framework, tool or assessment that best suits their institution’s size, complexity, and risk tolerance.  

  • ICBA supports bi-directional sharing of threat intelligence between the financial sector and the government.  

  • ICBA supports stronger cybersecurity standards and practices for government.  

  • ICBA supports financial sector initiatives such as .BANK and Sheltered Harbor.  

To better address increasingly sophisticated threats, state and federal legislation, regulation, and guidance should enable community banks to implement risk-based security programs. Lawmakers and regulators should harmonize future legislation or regulatory action with existing regulatory requirements. Additionally, regulators should broaden their supervision to include all companies that have access to, use, or store consumer financial data. These companies should be subject to the standards outlined in the Gramm-Leach-Bliley Act (GLBA). 

Community banks have various sizes, complexities, and risk tolerances. As such, regulators should allow community banks to choose the assessment tool that best fits their institution’s risk profile. 

ICBA recognizes that the U.S. Government also has a responsibility to safeguard financial and personally identifiable information (PII) and to provide banks with visibility into the government’s business continuity, incident response, and other critical resiliency plans. Bi-directional threat information sharing initiatives, such as the Financial Services Information Sharing and Analysis Center (FS-ISAC), are critical to threat mitigation. 

.BANK, Sheltered Harbor, and other financial sector efforts enhance protection for bank customer account data.