Featured Product

    US Congress Report Examines Data Privacy and Cybersecurity Regulations

    March 13, 2023

    The U.S. Congressional Research Service published a report on banking, data privacy, and cybersecurity regulation. The report examines the existing legislative framework for financial cybersecurity, in addition to providing context on how regulators currently promulgate, supervise, and enforce various data privacy provisions. The report also presents a few policy considerations as Congress continues to explore the issue of a unified and modernized legislative framework in this area.

    The report highlights that most of the legislative and regulatory data privacy framework established for banks and credit unions is constructed from a patchwork of cybersecurity provisions. Similarly, the implementation of cybersecurity supervisory programs among financial institution regulators is fragmented and potential risks to the financial system have emerged as new technologies evolve. The report focuses on the cybersecurity regulatory framework among the federal banking regulators—the Federal Deposit Insurance Corporation (FDIC), the Office of the Comptroller of the Currency (OCC), the Board of Governors of the Federal Reserve System (FED), the National Credit Union Administration (NCUA), and the Consumer Financial Protection Bureau (CFPB). Together, these agencies are responsible for implementing and ensuring compliance with banking laws.

    The report findings show that cybersecurity threats pose operational, reputational, and systemic risks, which are a major concern for banks and banking regulators. Banking regulators implement the cybersecurity legislative framework through rulemaking and then supervise institutions to ensure that banks are following regulations. The findings reveal that no single law provides a framework for regulating cybersecurity in the United States. Instead, multiple laws require financial regulators to establish cybersecurity standards for financial institutions and provide regulators the authority to ensure compliance with such standards. The Gramm-Leach-Bliley Act of 1999 (GLBA) is the most comprehensive law which directs financial regulators to implement disclosure requirements and mandate security measures to safeguard private information. Other laws—such as the Sarbanes-Oxley Act of 2002, Fair and Accurate Credit Transactions Act (FACT Act), Bank Protection Act, and Bank Service Company Act of 1962—complete the general legislative framework for cybersecurity.

    The report also identifies several policy issues that address regulator concern over the patchwork nature of regulatory standards for consumer privacy and security. The policy issues relate to how new technologies that facilitate financial data-sharing should be treated under the existing cybersecurity framework. Another issue relates to how and whether the data privacy protections that exist for data-sharing should also apply to data collection. The Data Privacy Act of 2023 (H.R. 1165), which the House Financial Services Committee ordered to be reported as amended in February 2023, examines several of these issues. Moreover, the report notes that technology partnerships, particularly at smaller banks, with institutions such as cloud management companies, have led to new cybersecurity risks to the banking system. This has raised concerns among policymakers about the capacity of the existing framework to address new risks. To that end, the report notes that, considering the financial stability, concentration, and systemic risks stemming from the increasing bank reliance on cloud services, the scope of bank supervision may expand to cloud service providers. This may lead to technical resource mismatches, and regulators, like banks, may find themselves with a shortage of cloud skills necessary to examine cloud service providers. These service providers may also not be familiar with or amenable to audits or bank-like examinations. It is also expected that banks may adopt multi-cloud strategies—contracts with multiple cloud service providers—to avoid lock-in risk. In addition to increasing costs, this introduces potentially two or more providers in the form of cloud service providers, and banks must manage these relationships effectively to ensure cybersecurity.

     

    Related Link: Report (PDF)


    Keywords: Americas, US, Banking, Regtech, Data Privacy, Operational Risk, Systemic Risk, Cloud Service Providers, Disclosures, Cyber Risk, Operational Resilience, US CRS

    Featured Experts
    Related Articles
    News

    BIS Paper Outlines Vision for Future Financial System

    In a recent paper, the General Manager of Bank for International Settlements (BIS) and the Indian entrepreneur (Infosys co-founder) Nandan Nilekani have laid out a vision for the Finternet, which is proposed to be a network of multiple financial ecosystems, much like the internet.

    April 29, 2024 WebPage Regulatory News
    News

    NGFS Outlines Options for Supervisory Review of Transition Plans

    The Network for Greening the Financial System (NGFS) recently published three reports on the use of transition plans to boost sustainable finance and manage climate-related financial risks.

    April 29, 2024 WebPage Regulatory News
    News

    BCBS Issues Discussion Paper on Climate Scenario Analysis

    The Basel Committee on Banking Supervision (BCBS) issued a discussion paper on the use of climate scenario analysis to strengthen the management and supervision of climate-related financial risks.

    April 29, 2024 WebPage Regulatory News
    News

    OSFI Issues Phase2 Consultation on Climate Scenario Exercise for Banks

    The Office of the Superintendent of Financial Institutions (OSFI) recently announced a consultation on the second phase of the Standardized Climate Scenario Exercise (SCSE) for banks and other financial institutions it regulates in Canada.

    April 25, 2024 WebPage Regulatory News
    News

    CFIT to Chair Open Finance Taskforce Announced by UK Government

    The UK government announced the formation of an industry-led Open Finance Taskforce, chaired by the Center for Finance, Innovation, and Technology (CFIT).

    April 25, 2024 WebPage Regulatory News
    News

    BIS and Central Banks Experiment with GenAI to Assess Climate Risks

    A recent report from the Bank for International Settlements (BIS) Innovation Hub details Project Gaia, a collaboration between the BIS Innovation Hub Eurosystem Center and certain central banks in Europe

    March 20, 2024 WebPage Regulatory News
    News

    Nearly 25% G-SIBs Commit to Adopting TNFD Nature-Related Disclosures

    Nature-related risks are increasing in severity and frequency, affecting businesses, capital providers, financial systems, and economies.

    March 18, 2024 WebPage Regulatory News
    News

    Singapore to Mandate Climate Disclosures from FY2025

    Singapore recently took a significant step toward turning climate ambition into action, with the introduction of mandatory climate-related disclosures for listed and large non-listed companies

    March 18, 2024 WebPage Regulatory News
    News

    SEC Finalizes Climate-Related Disclosures Rule

    The U.S. Securities and Exchange Commission (SEC) has finalized the long-awaited rule that mandates climate-related disclosures for domestic and foreign publicly listed companies in the U.S.

    March 07, 2024 WebPage Regulatory News
    News

    EBA Proposes Standards Related to Standardized Credit Risk Approach

    The European Banking Authority (EBA) has been taking significant steps toward implementing the Basel III framework and strengthening the regulatory framework for credit institutions in the EU

    March 05, 2024 WebPage Regulatory News
    RESULTS 1 - 10 OF 8962