The National Credit Union Administration published a final rule in November 2021 requiring every federally insured credit union to maintain a written incident response plan, report cybersecurity incidents to its board, and notify the NCUA within 72 hours when a substantial incident occurs. The rule took effect January 2022, with full compliance required by September 2022.
The regulation imposes three distinct obligations. First, leadership must approve and maintain a written plan describing how the credit union will respond to cybersecurity incidents. Second, management must report incidents to the board promptly after discovery. Third, the credit union must notify the NCUA within 72 hours of determining that a substantial cybersecurity incident has occurred or is occurring.
The business problem is not the rule itself. The problem is that leadership is accountable for a security outcome without a clear owner, a defensible sequence of decisions, or a way to measure whether the organization is ready before an incident occurs.
Why This Matters to Credit Union Leadership
The NCUA rule shifts responsibility from technical response to governance. The board is not being asked to understand malware; it is being asked to ensure the organization has a defensible process, knows when that process has been triggered, and can demonstrate accountability.
Consequences attach to failures in three areas. If the credit union cannot demonstrate that it maintains an adequate plan, examiners will cite the deficiency. If management fails to inform the board after discovering an incident, leadership has failed a reporting duty. If the credit union misses the 72-hour notification window after determining that a substantial incident has occurred, it has violated a federal requirement.
The regulation does not prescribe what an adequate incident response plan looks like in detail, which means leadership must make risk-informed judgments about adequacy and must be able to explain those judgments. That requires someone who can translate cybersecurity risk into business terms, articulate the plan's logic to examiners and board members, and own the decision when the plan is tested.
What the Rule Requires
Written Incident Response Plan
The credit union must maintain a written incident response plan. The plan must describe how the organization will detect, respond to, and recover from cybersecurity incidents. It must identify roles and responsibilities, outline notification and escalation procedures, and describe how the credit union will communicate with members, regulators, and third parties.
The plan is not a technical runbook alone. It is a governance document that defines who makes decisions, what triggers those decisions, and what information leadership needs to act. A plan that IT staff can execute but executive leadership cannot explain to the board does not satisfy the intent of the rule.
Board Reporting
Management must report cybersecurity incidents to the board as soon as possible after the credit union becomes aware of them. The board does not need a technical forensic summary; it needs enough information to understand the business impact, the response underway, and the decisions that require board judgment or oversight.
This obligation requires someone who can assess an incident's business significance in real time and prepare a board-level summary quickly. Most IT leaders are not positioned to make that translation, and most boards do not have the background to ask the right questions without structured input.
72-Hour Notification to the NCUA
The credit union must notify the NCUA within 72 hours of determining that a substantial cybersecurity incident has occurred or is occurring. A substantial incident is one that materially disrupts operations, results in unauthorized access to sensitive data, or involves a significant loss of confidentiality, integrity, or availability of member or credit union data.
The 72-hour clock starts when the credit union makes the determination, not when the incident began. That determination is a judgment call, and it must be made by someone with the authority and context to decide when the threshold has been crossed. Waiting for perfect information means the window will close. Acting prematurely creates regulatory noise. Someone must own that decision.
Who Owns Incident Readiness in Practice
Most credit unions have assigned incident response tasks to IT staff or to an outsourced managed service provider. That model addresses technical execution but it does not address governance. IT teams are positioned to contain malware, restore systems, and preserve evidence. They are not positioned to decide what constitutes a substantial incident, prepare board-level summaries, or own the regulatory relationship with examiners.
The gap is executive ownership. Incident response is a risk decision with regulatory, operational, and reputational consequences. It requires someone who can assess business impact, translate technical findings into executive language, coordinate across internal stakeholders, and make time-sensitive judgment calls that can be explained to the board and defended to regulators.
That role is the Chief Information Security Officer. In larger organizations, the CISO is a full-time executive. In credit unions that cannot justify a full-time security executive, [virtual CISO leadership](/vciso/) provides that function fractionally: strategy, governance, risk decisions, regulatory positioning, and incident coordination.
What Leadership Should Do Next
First, confirm that the credit union maintains a written incident response plan and that the plan was reviewed within the past twelve months. If the plan exists only as a technical procedure document, it likely does not satisfy the governance intent of the rule.
Second, identify who is responsible for determining when an incident is substantial enough to trigger the 72-hour notification requirement. If that responsibility has not been explicitly assigned, it will default to whoever is available during the incident, which is not a defensible governance model.
Third, test the reporting path from incident discovery to board notification. Simulate a scenario and measure how long it takes to produce a board-ready summary. If the exercise reveals that no one can prepare that summary without starting from scratch, the credit union is not ready.
Fourth, clarify who owns the incident response plan as a governance document. That person must be able to explain the plan's logic to the board, justify its adequacy to examiners, and coordinate response decisions across IT, compliance, operations, and communications. If no one currently holds that accountability, leadership must either assign it internally or engage someone who can provide that function.
How This Relates to Incident Readiness and Response Planning
The NCUA rule is prescriptive about outcomes but not about process. It requires that the credit union be ready, that incidents be reported, and that substantial events be escalated promptly. It does not specify how to achieve readiness, how to train responders, or how to measure whether the plan will work under pressure.
Incident readiness is broader than the plan document. It includes the training that enables staff to execute the plan, the tabletop exercises that reveal gaps before an incident occurs, the communication templates that allow rapid board reporting, and the decision frameworks that help leadership determine when the 72-hour clock has started.
Response planning is the discipline of translating regulatory obligations and business constraints into a defensible, executable sequence of decisions. It requires understanding what the credit union must protect, what failure modes are most likely, who must be involved in response decisions, and what information the board and regulators will need when an incident occurs. That discipline is the foundation of the virtual CISO function.
Start with a Confidential Consultation
If your credit union lacks clear executive ownership of incident readiness, or if leadership cannot confidently explain how the organization would meet the 72-hour notification requirement during an actual event, Heights Consulting Group offers a confidential consultation to map governance, identify gaps, and define what adequate ownership looks like in your context.
The consultation is a single structured conversation with your executive team. There is no obligation and no follow-up unless you decide the conversation was useful. Contact Heights at [email protected] to schedule.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Incident Readiness and Response Planning
A response plan that names decision makers, defines escalation and notification paths, and has been tested with the executives who would have to use it.