In December 2023, the Financial Crimes Enforcement Network (FinCEN) proposed a rule requiring banks and other financial institutions subject to Bank Secrecy Act obligations to report significant cyber events within four business days. The proposal creates a new category of regulatory notification distinct from existing SEC disclosure requirements, with a different threshold, timeline, and reporting mechanism.

For chief executives, chief compliance officers, general counsel and board members, the question is not whether your institution can technically file a form. It is who inside the organization has the authority and context to determine whether an event qualifies as reportable, and whether that person can make the determination within the four-day window while investigations are still underway.

What the Proposal Requires

The proposed rule would require financial institutions to notify FinCEN of any significant cyber event that has occurred or is occurring. The notification must be submitted within four business days of when the institution reasonably believes a reportable event has occurred.

The regulation does not require the institution to have completed its investigation or determined root cause before reporting. It requires notification based on reasonable belief at the time, which places pressure on early-stage incident assessment and decision-making processes that may not be designed for regulatory determination.

What Constitutes a Reportable Cyber Event

A significant cyber event under the proposal is one that materially disrupts or degrades the institution's ability to carry out core operations or significantly compromises the confidentiality of customer information. This is a function-based test, not a technical one.

The determination requires judgment about operational materiality and customer impact during a period when facts are incomplete. It cannot be delegated to technical responders who lack visibility into business operations, and it cannot be delayed until the incident is fully understood without risking noncompliance.

Examples of potentially reportable events include ransomware that prevents access to transaction systems, distributed denial-of-service attacks that take customer-facing services offline for an extended period, or data exfiltration involving customer financial records. The threshold is operational disruption or confidentiality compromise, not the presence of a particular attack type.

How This Differs From SEC Incident Disclosure

Public companies are already subject to the SEC's four-business-day disclosure requirement for material cybersecurity incidents under rules that took effect in December 2023. The FinCEN proposal creates a parallel but distinct obligation with a different standard.

SEC disclosure is triggered by materiality to investors. FinCEN reporting is triggered by operational disruption or customer information compromise, regardless of investor materiality. An event can be reportable to FinCEN but not the SEC, reportable to the SEC but not FinCEN, or reportable to both under different standards at the same time.

This creates a coordination problem. The general counsel's office evaluates materiality for SEC purposes. Compliance evaluates Bank Secrecy Act obligations. IT evaluates technical containment. Without a single point of accountability for translating technical findings into regulatory determinations, institutions risk inconsistent or delayed reporting.

The Leadership Question: Who Decides and When

The four-day window requires institutions to make a regulatory determination while incident response is in progress. This is a governance problem disguised as a technical one.

Technical responders can tell you what systems are affected and what data may be at risk. They cannot tell you whether the operational impact crosses the materiality threshold for FinCEN reporting or how to characterize the event in regulatory language. Compliance can tell you what the filing process requires. They cannot determine technical scope or business impact without input from operations and security.

Adequate ownership means a named executive with access to real-time incident information, authority to make the reportability determination, and accountability for ensuring the filing is complete and accurate within the deadline. That person must be identified before an incident occurs, with clear escalation criteria and decision rights documented.

Incident Readiness and the Regulatory Determination Process

Incident response plans describe how to contain threats and restore systems. They rarely describe how to make a regulatory determination within four days using incomplete information, or who has authority to do so.

Readiness for regulatory reporting means defining the decision-making process in advance. This includes which stakeholders participate in the determination, what information is required, how conflicting assessments are resolved, and who approves the final filing. It also means documenting the basis for the determination at the time it is made, regardless of how the investigation ultimately concludes.

Institutions that have not made these assignments in writing will attempt to form consensus in real time under pressure, with predictable delays and disagreement about threshold interpretation.

What Leadership Should Do Now

The proposal is not yet final, but the preparation work does not depend on the final rule text. The following steps establish accountability and process regardless of how the threshold language or timeline evolves.

  • Name the executive accountable for making the FinCEN reportability determination during an incident. Confirm they have authority to access incident information in real time and approve regulatory filings without further escalation.
  • Document the decision-making process for regulatory reporting. Specify which stakeholders participate, what information is required for the determination, and how disagreements are resolved. Record the basis for the determination contemporaneously.
  • Map the interaction between FinCEN and SEC reporting obligations. Clarify which office leads each determination, how the two processes coordinate, and how discrepancies in materiality assessment are handled.
  • Test the process before it is needed. Simulate a scenario requiring a reportability determination within four days and identify where the process breaks down or requires information that is not readily available.
  • Review existing incident response plans for gaps in regulatory decision-making. Confirm that the plan addresses who makes the determination, not just who files the form.

For institutions that lack internal security leadership with regulatory fluency, [virtual CISO services](/vciso/) can provide the executive ownership that closes this gap: strategy, governance, risk decisions, regulatory position and reporting. This is not a technical implementation role. It is the person who sits between IT, compliance, legal and operations to ensure that security outcomes align with regulatory obligations and board expectations.

A Confidential Conversation

If your institution is subject to Bank Secrecy Act obligations and the questions above do not have clear answers, we can help. Heights provides fractional CISO leadership to financial institutions and other regulated organizations where the security function exists but lacks executive-level ownership.

A confidential consultation begins with your current state: who is accountable for security decisions today, what gaps exist in incident readiness, and where regulatory obligations create risk that no one owns. From there, we can design the governance structure, decision rights and processes that ensure your institution can meet its reporting obligations with confidence. Contact Heights to schedule a conversation.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Related service: Incident Readiness and Response Planning

A response plan that names decision makers, defines escalation and notification paths, and has been tested with the executives who would have to use it.

Read about Incident Readiness and Response Planning