US regulators approve a rule requiring banks to report cyberattacks that disrupt operations or impact the US financial system within 36 hours, starting May 2022
Banks must report major cybersecurity incidents to federal officials within 36 hours under a rule that U.S. financial regulators finalized on Thursday.
Context & Ripple Effects
The banking rule finalized here is the opening move in what became a cascade of mandatory cyber-incident disclosure across US finance. Within months, the SEC followed with a parallel proposal for investment funds and advisers on a 48-hour reporting clock, and separately began weighing four-day breach disclosure for publicly traded companies.
What makes this rule matter is its scope: it targets incidents that disrupt operations or threaten the financial system itself, not just data loss — putting bank cyber events on the same footing as other systemically important risk reports regulators already collect.
First-order effects
- Banks must stand up internal processes to detect, triage, and file major incident reports within 36 hours by May 2022 — a compliance buildout touching security operations, legal, and regulator liaison teams at every covered institution.
- Federal officials gain near-real-time visibility into attacks hitting banks, letting them spot cross-institution campaigns and systemic exposure far earlier than post-hoc disclosures allowed.
Second-order effects
- The SEC's subsequent moves — the four-day disclosure requirement it weighed for public companies and its later approved rules requiring filing within four days of material impact — extend the same logic beyond banks, forcing issuers and asset managers to build comparable reporting pipelines rather than treating cyber response as purely operational.
- Compliance tooling and incident-response vendors gain a regulated demand floor, since meeting hard deadlines across multiple agencies pushes institutions toward automated detection-to-report workflows.
Third-order effects
- Cyber incidents are being reclassified from private operational matters into reportable regulatory events, with the banking rule as the template later extended to customer notification — the SEC's 30-day breach notice requirement for some financial institutions pushes accountability one step further down to affected consumers.
- If the pattern holds, financial firms face layered disclosure obligations to multiple regulators on different clocks, raising the cost of underreporting and making coordinated inter-agency incident data a structural feature of financial supervision.
The trend: US regulators are standardizing rapid mandatory cyber-incident disclosure across the financial system, with the banking sector's 36-hour rule serving as the template that securities and consumer-protection rules then generalized.