The Fed - SR 22-4 / CA 22-3: Contact Information in Relation to Computer-Security Incident Notification Requirements Skip to main content An official website of the United States GovernmentHere's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock (LockLocked padlock icon ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. Back to Home Board of Governors of the Federal Reserve System Stay Connected Federal Reserve Facebook Page Federal Reserve Instagram Page Federal Reserve YouTube Page Federal Reserve Flickr Page Federal Reserve LinkedIn Page Federal Reserve Threads Page Federal Reserve X Page Federal Reserve Bluesky Page Subscribe to RSS Subscribe to Email Recent Postings Calendar Publications Site Map A-Z index Careers FAQs Videos Contact Search Submit Search Button Advanced Toggle Dropdown Menu Board of Governors of the Federal Reserve System The Federal Reserve, the central bank of the United States, provides the nation with a safe, flexible, and stable monetary and financial system. Main Menu Toggle Button Sections Search Toggle Button Search Search Submit Button Submit About the Fed Structure of the Federal Reserve System The Fed Explained Board Members Advisory Councils Federal Reserve Banks Federal Reserve Bank and Branch Directors Federal Reserve Act Currency Board Meetings Board Votes Careers Do Business with the Board Holidays Observed - K.8 Ethics & Values Contact Requesting Information (FOIA) FAQs Economic Education Fed Financial Statements Financial Innovation News & Events Press Releases Speeches & Testimony Calendar Videos Photo Gallery Conferences Monetary Policy Federal Open Market Committee About the FOMC Meeting calendars and information Transcripts and other historical materials FAQs Monetary Policy Principles and Practice Notes Policy Implementation Policy Normalization Policy Tools Reports Monetary Policy Report Beige Book Federal Reserve Balance Sheet Developments Review of Monetary Policy Strategy, Tools, and Communications Overview Supervision & Regulation Supervision Community Banks Regional Banks and Foreign Banks with U.S. Assets Large Banks and Large Foreign Banks Global Systemically Important Banks Financial Market Utilities Consumer Compliance Resources for Supervised Institutions Reports Federal Reserve Supervision and Regulation Report Reporting Forms Recent Reporting Form Updates Information Collections Under Review Financial Statements Securities Exchange Act of 1934 Applications/Structure Change FFIEC Municipal and Government Securities Activities Monitoring Micro Data Reference Manual Legal Developments Enforcement Actions and Legal Developments Mergers, Acquisitions, and Other Applications Process Filing Information Board and Reserve Bank Actions Supervision and Regulation Letters By Year By Topic Regulatory and Policy Resources Federal Reserve Act Bank Holding Company Act Regulations Supervision Manuals Federal Reserve Regulatory Service Disaster Preparedness and Recovery Resources Banking and Data Structure Beneficial Ownership Reports Large Commercial Banks Minority Depository Institutions U.S. Offices of Foreign Entities Financial Holding Companies Interstate Branching Securities Underwriting and Dealing Subsidiaries State Member Banks Supervised by the Federal Reserve Financial Stability Financial Stability Assessments About Financial Stability Types of Financial System Vulnerabilities & Risks Monitoring Risk Across the Financial System Proactive Monitoring of Markets & Institutions Financial Stability & Stress Testing Financial Stability Coordination & Actions Responding to Financial System Emergencies Cooperation on Financial Stability Reports Financial Stability Report Payment Systems Regulations & Statutes Regulation CC (Availability of Funds and Collection of Checks) Regulation II (Debit Card Interchange Fees and Routing) Regulation HH (Financial Market Utilities) Other Regulations and Statutes Payment Policies Federal Reserve's Key Policies for the Provision of Financial Services Guidelines for Evaluating Joint Account Requests Overnight Overdrafts Payment System Risk Sponsorship for Priority Telecommunication Services Reserve Bank Payment Services & Data Automated Clearinghouse Services Check Services Currency and Coin Services Daylight Overdrafts and Fees FedNow® Service Fedwire Funds Services Fedwire Securities Services Fiscal Agency Services Master Account and Services Database National Settlement Service Financial Market Utilities & Infrastructures Supervision & Oversight of Financial Market Infrastructures Designated Financial Market Utilities International Standards for Financial Market Infrastructures Research, Reports, & Committees Federal Reserve Payments Study (FRPS) Payments Research Reports Payments System Policy Advisory Committee Economic Research Meet the Researchers Working Papers and Notes Finance and Economics Discussion Series (FEDS) FEDS Notes International Finance Discussion Papers (IFDP) Data, Models and Tools Economic Research Data FRB/US Model Estimated Dynamic Optimization (EDO) Model Survey of Consumer Finances (SCF) Data Data Download Program Bank Assets and Liabilities Aggregate Reserves of Depository Institutions and the Monetary Base - H.3 Assets and Liabilities of Commercial Banks in the U.S. - H.8 Assets and Liabilities of U.S. Branches and Agencies of Foreign Banks Charge-Off and Delinquency Rates on Loans and Leases at Commercial Banks Senior Financial Officer Survey Senior Loan Officer Opinion Survey on Bank Lending Practices Bank Structure Data Large Commercial Banks Minority Depository Institutions Structure and Share Data for the U.S. Offices of Foreign Banks Business Finance Commercial Paper Finance Companies - G.20 New Security Issues, State and Local Governments New Security Issues, U.S. Corporations Dealer Financing Terms Senior Credit Officer Opinion Survey on Dealer Financing Terms Exchange Rates and International Data Foreign Exchange Rates - H.10/G.5 International Summary Statistics Securities Holdings and Transactions Statistics Reported by Banks and Other Financial Firms in the United States Structure and Share Data for U.S. Offices of Foreign Banks Financial Accounts Financial Accounts of the United States - Z.1 Household Finance Consumer Credit - G.19 Household Debt Service Ratios Mortgage Debt Outstanding Survey of Consumer Finances (SCF) Survey of Household Economics and Decisionmaking Industrial Activity Industrial Production and Capacity Utilization - G.17 Interest Rates Selected Interest Rates - H.15 Micro Data Reference Manual (MDRM) Micro and Macro Data Collections Money Stock and Reserve Balances Factors Affecting Reserve Balances - H.4.1 Money Stock Measures - H.6 Other Yield Curve Models and Data Consumers & Communities Regulations Community Reinvestment Act (CRA) All Regulations Supervision & Enforcement CA Letters Enforcement Actions Independent Foreclosure Review Community Development Housing and Neighborhood Revitalization Small Business and Entrepreneurship Employment and Workforce Development Community Development Finance Rural Community and Economic Development Conferences Research & Analysis Survey of Household Economics and Decisionmaking Research Publications & Data Analysis Community Advisory Council Resources for Consumers Frauds and Scams Mortgage and Foreclosure Resources Federal Reserve Community Development Resources Home Supervision & Regulation Supervision and Regulation Letters 2022 Supervision and Regulation Letters below when display/hiding this option -- Share PDF RSS By topic TAG SO THAT THE SUBJECT DOES NOT WRAP TO A NEW LINE WITHIN THE H3-- SR 22-4 / CA 22-3: Contact Information in Relation to Computer-Security Incident Notification Requirements BOARD OF GOVERNORS OF THE FEDERAL RESERVE SYSTEM WASHINGTON, D.C. 20551 DIVISION OF SUPERVISION AND REGULATION DIVISION OF CONSUMER AND COMMUNITY AFFAIRS SR 22-4 / CA 22-3 March 29, 2022 TO THE OFFICER IN CHARGE OF SUPERVISION AT EACH FEDERAL RESERVE BANK SUBJECT: Contact Information in Relation to Computer-Security Incident Notification Requirements Applicability:  This letter applies to all banking organizations supervised by the Federal Reserve, including those with $10 billion or less in consolidated assets. This letter also applies to bank service providers of banking organizations supervised by the Federal Reserve. However, this letter does not apply to designated financial market utilities as defined at 12 U.S.C. § 5462(4). The Board of Governors of the Federal Reserve (Board), the Federal Deposit Insurance Corporation (FDIC), and the Office of the Comptroller of the Currency (OCC) (collectively, the agencies) issued a joint final rule to establish computer-security incident notification requirements for banking organizations and their bank service providers.1 The final rule takes effect on April 1, 2022, with a compliance date of May 1, 2022. As described in the final rule, this requirement will help promote early awareness of emerging threats to banking organizations and the broader financial system, helping the agencies react to these threats before they become systemic. This letter sets forth the Board-designated points of contact for banking organizations to notify the Board of “notification incidents.”2 A banking organization whose primary federal regulator is the Board must notify the Board about a notification incident by email to [email protected] or telephone to (866) 364-0096.3 The Board must receive this notification from a banking organization as soon as possible and no later than 36 hours after the banking organization determines that a notification incident has occurred. If a banking organization is in doubt as to whether it is experiencing a notification incident for purposes of notifying the Board, the Board encourages the banking organization to contact the Board by email to [email protected] or telephone to (866) 364-0096. A banking organization should also contact its central point of contact about a notification incident. Bank Service Providers A bank service provider must notify each affected banking organization customer as soon as possible when the bank service provider determines that it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, services provided to such banking organization for four or more hours.4 A bank service provider is required to provide notice of the incident to at least one bank-designated point of contact at each affected banking organization as soon as possible. If a banking organization customer has not previously provided a bank-designated point of contact, the bank service provider must notify the Chief Executive Officer and Chief Information Officer of the banking organization customer, or two individuals of comparable responsibilities, through any reasonable means. The final rule takes effect on April 1, 2022, with a compliance date of May 1, 2022. If a bank service provider is in doubt as to whether a material disruption or degradation in services provided to a banking organization customer for four or more hours may have a material adverse impact on a banking organization customer, the Board encourages the bank service provider to contact the banking organization customer or its own legal adviser. Reserve Banks are asked to distribute this letter to the supervised banking organizations in their districts and to appropriate supervisory staff. Questions regarding this letter may be sent via the Board’s public website.5 signed by Arthur Lindo Deputy Director Division of Supervision and Regulation signed by Eric S. Belsky Director Division of Consumer and Community Affairs Notes: See 86 FR 66424 (November 23, 2021), available at: https://www.govinfo.gov/content/pkg/FR-2021-11-23/pdf/2021-25510.pdf.  Return to text. The final rule defines a “notification incident” as a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, a banking organization’s:  (i) ability to carry out banking operations, activities, or processes, or deliver banking products and services to a material portion of its customer base, in the ordinary course of business; (ii) business line(s), including associated operations, services, functions, and support, that upon failure would result in a material loss of revenue, profit, or franchise value; or (iii) operations, including associated services, functions and support, as applicable, the failure or discontinuance of which would pose a threat to the financial stability of the United States. The final rule defines a “computer-security incident” as an occurrence that results in actual harm to the confidentiality, integrity, or availability of an information system or the information that the system processes, stores, or transmits.  Return to text. The Board may identify other methods by which banking organizations may provide notice of cyber incidents in the future.  Return to text. This notification requirement does not apply to any scheduled maintenance, testing, or software update previously communicated to a banking organization customer.  Return to text. See http://www.federalreserve.gov/apps/contactus/feedback.aspx.  Return to text. Back to Top Last Update: March 29, 2022 Board of Governors of the Federal Reserve System About the Fed News & Events Monetary Policy Supervision & Regulation Financial Stability Payment Systems Economic Research Data Consumers & Communities Connect with the Board Tools and Information Contact Publications Freedom of Information (FOIA) Office of Inspector General Budget & Performance | Audit No FEAR Act Español Website Policies | Privacy Program Accessibility Stay Connected Federal Reserve Facebook Page Federal Reserve Instagram Page Federal Reserve YouTube Page Federal Reserve Flickr Page Federal Reserve LinkedIn Page Federal Reserve Threads Page Link to Federal Reserve X Page Link to Federal Reserve Bluesky Page Subscribe to RSS Subscribe to Email Board of Governors of the Federal Reserve System 20th Street and Constitution Avenue N.W., Washington, DC 20551 --