The Federal Deposit Insurance Corporation's November 2021 final rule establishes a binding obligation: FDIC-insured institutions must notify their primary federal regulator within 36 hours of a computer-security incident that materially disrupts or degrades the ability to deliver deposit, payment or settlement functions. The rule became effective in 2023. For community banks, this means the chief executive is now accountable for a security outcome that depends on strategy, governance, risk judgment and regulatory positioning that many institutions have not yet put in place.
What Constitutes a Notification-Requiring Incident
The rule does not require notification of every security event. The threshold is a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, the institution's ability to carry out one of three categories of activity for four or more hours:
- Deposit and loan operations, including the acceptance of deposits or disbursement of loan proceeds
- Payment, clearing and settlement functions
- The opening, closing and maintenance of customer accounts, including the processing of customer transactions
The four-hour threshold applies whether the impact is continuous or cumulative over a rolling 12-month period. A computer-security incident is defined as an occurrence that results in actual harm to the confidentiality, integrity or availability of an information system or the information the system processes, stores or transmits. This includes ransomware events, denial-of-service attacks, intrusions that compromise systems supporting deposit or payment functions, and third-party or vendor failures that prevent the bank from delivering these services.
The question of whether an incident is 'reasonably likely' to meet the threshold requires judgment. It cannot be deferred until certainty exists, because by then the 36-hour window may have closed. This is a strategic decision, not a technical one, and it falls to executive leadership.
Who Must Be Notified and When
Notification must be made to the bank's primary federal regulator no later than 36 hours after the institution determines that a notification-requiring incident has occurred. For FDIC-supervised institutions, this means the appropriate FDIC regional office. For state member banks, it means the Federal Reserve. For national banks and federal savings associations, the Office of the Comptroller of the Currency.
The 36-hour clock starts at the point of determination, not discovery. The rule recognizes that it may take time to assess whether the threshold has been met. But once the institution reasonably concludes that it has, the notification obligation is immediate. There is no requirement to have complete information before notifying. The notification is not a forensic report; it is an early alert to the regulator that an incident of regulatory significance has occurred.
Bank service providers that experience incidents meeting the same materiality threshold have a parallel obligation: they must notify each affected banking organization customer as soon as possible, and no later than 36 hours after determining that an incident has occurred. This means community banks must understand not only their own notification obligations, but also what they should expect from their vendors.
Why This Matters to the Business
The notification rule is not a technical compliance exercise. It creates direct accountability at the board and chief executive level for security outcomes. Failure to notify within the 36-hour window exposes the institution to enforcement action, regardless of how well the incident itself was managed. The rule presumes that leadership can make a threshold determination under pressure, with incomplete information, in a matter that has regulatory, operational, reputational and potentially criminal dimensions.
Most community banks operate without a chief information security officer. Technology leadership typically reports to operations or finance, not to the chief executive. Decisions about whether an incident is material, whether it is reasonably likely to persist, and whether notification is required are not questions that can be delegated to an IT manager or answered by reference to a checklist. They require an understanding of regulatory expectations, operational risk tolerance, the institution's recovery capacity, and the strategic implications of notifying the regulator before the full scope of an incident is known.
The consequence of non-compliance is not hypothetical. Examiners now explicitly assess whether institutions have the governance, procedures and judgment capacity to make accurate threshold determinations within the required timeframe. Where they find deficiencies, they issue findings. Where they find patterns of failure, they pursue enforcement.
What Governance Must Be in Place
The rule does not prescribe the internal structure required to comply, but examiners evaluate whether the institution has adequate governance to meet its obligations. At minimum, this means:
- A clear chain of decision-making authority that identifies who makes the threshold determination and on what basis
- Defined escalation procedures that ensure the right people are notified internally before the external notification is due
- Written criteria for assessing materiality, aligned to the institution's risk appetite and operational resilience
- Documented contact information for the primary federal regulator and tested notification procedures
- Pre-incident clarity about what information must be gathered to support the threshold determination
- A process for maintaining records of the determination and the basis for it
This governance must function during an incident. It cannot depend on people who may be unavailable, systems that may be compromised, or deliberation that takes longer than the notification window allows. Many institutions assume their incident response plan addresses this. It typically does not. Response plans focus on containment, recovery and continuity. They rarely define who decides whether to notify the regulator, what the decision threshold is, or how to document that decision under operational stress.
The Relationship to Incident Readiness and Response Planning
The notification rule intersects with, but does not replace, the institution's broader incident readiness and response planning. Incident response planning addresses detection, containment, eradication, recovery and post-incident review. The notification rule addresses a narrower question: does this incident meet the threshold, and if so, who have we told and when.
Effective readiness planning anticipates the notification decision. It defines what 'materially disrupts or degrades' means for the institution's specific deposit, payment and account maintenance functions. It establishes who has authority to make the call, and ensures they have the information, judgment and support to make it within 36 hours. It tests whether the notification process works when normal communication channels are unavailable.
The institutions that struggle with this are often those that have outsourced incident response to a technology vendor or cyber insurance carrier without retaining executive ownership of the regulatory threshold determination. A managed service provider can assist with containment and recovery. It cannot decide whether the institution is obligated to notify the FDIC. That remains a board-level accountability.
Who Owns This Inside the Organization
The FDIC holds the board and senior management accountable for compliance with the notification rule. In practice, this means the chief executive. The decision to notify cannot be made by the IT director, the compliance officer or outside counsel without executive sign-off, because it is fundamentally a risk and regulatory judgment, not a technical or legal one.
Adequate ownership looks like this: a senior executive, reporting to the chief executive or board, who has sufficient understanding of the institution's security posture, operational dependencies and regulatory obligations to assess whether an incident meets the threshold. This person does not need to be a technical specialist. They need to be able to evaluate incomplete information, consult the right advisors, understand the regulatory standard, and make a defensible determination within the required timeframe.
For institutions without a chief information security officer, this role is typically filled by [virtual CISO leadership](/vciso/). A vCISO provides the strategic oversight, regulatory judgment and executive accountability that the notification rule assumes is in place, without requiring the institution to hire a full-time security executive. The vCISO defines the threshold criteria, establishes the notification governance, ensures the board understands its obligations, and makes or directly supports the threshold determination when an incident occurs.
What Leadership Should Do Next
If your institution has not yet addressed these questions, begin with three concrete steps:
First, confirm who is accountable for making the notification threshold determination and on what authority. If this is not clearly documented, it is not in place.
Second, review your incident response procedures and identify where the regulatory notification decision is addressed. If it is absent, or if it assumes more time or more certainty than the rule allows, the procedures are incomplete.
Third, test the notification process. Simulate an incident that meets the threshold and determine whether the institution can identify it, make the determination, and notify the regulator within 36 hours using only the people, systems and information that would actually be available during an incident. If the test reveals gaps, address them before the next examination cycle.
For institutions that lack the internal capability to close these gaps, the decision point is whether to hire, designate or engage executive-level security leadership with the authority and judgment to meet the regulatory standard. That leadership does not need to be permanent or full-time, but it must exist. The alternative is to accept the regulatory and operational risk that the institution cannot meet its notification obligations when it matters.
If you would find it useful to discuss your institution's specific readiness position in confidence, we offer a single consultation at no cost and without obligation. Contact Heights Consulting Group directly to arrange it.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Incident Readiness and Response Planning
A response plan that names decision makers, defines escalation and notification paths, and has been tested with the executives who would have to use it.