US regulators approve a rule requiring banks to report cyberattacks that disrupt operations or impact the US financial system within 36 hours, starting May 2022
Context & Ripple Effects
The bank reporting rule begins a related-coverage sequence that expands cyber-incident obligations across financial markets. The SEC later proposed 48-hour reporting for investment funds and advisers and approved four-day disclosures of material attacks by public companies, creating different reporting clocks for different regulated populations.
First-order effects
- Banks must build incident-escalation processes that identify operationally disruptive attacks or threats to the US financial system and notify US regulators within 36 hours beginning in May 2022.
- US regulators gain a faster channel for situational awareness when a bank cyberattack affects operations or the wider financial system.
Second-order effects
- Investment funds, advisers, and public companies face a regulatory environment in which cyber-incident reporting is increasingly time-bound, as reflected in the SEC's later 48-hour proposal and four-day disclosure rule.
- Banks subject to the 36-hour requirement will need to distinguish disruption and systemic impact quickly, while public companies later assess whether an incident has a material impact for their separate SEC disclosure obligation.
Third-order effects
- The related rules point toward a tiered US cyber-reporting regime: notification deadlines and recipients increasingly depend on whether the regulated entity is a bank, fund, adviser, or public company and on the incident's operational or material consequences.
- As these obligations accumulate, cyber response becomes an auditable governance function rather than solely a technical recovery process, with regulators receiving earlier incident signals across financial markets.
The trend: US financial cyber regulation is moving toward mandatory, deadline-driven incident reporting calibrated to the affected institution and the severity of the event.