27.3 Customer Incident Notices and Regulatory Notification Clocks

Key Takeaways

  • Customer notice depends on the applicable misuse standard and notice guidance.

  • The thirty-six-hour banking-agency notification rule starts after determination of a qualifying notification incident.

  • Service-provider notices have their own disruption threshold and prompt-notification duty.

Last updated: October 2026

Definition of Sensitive Customer Information

Sensitive customer information is defined under Supplement A as a customer's name, address, or telephone number in conjunction with any one or more of the following:

  • Social Security Number (SSN);
  • Driver's license number or state identification card number;
  • Account number, credit card number, or debit card number;
  • Personal Identification Number (PIN) or security access code; or
  • Password or credentials that would permit access to the customer's account.

It also includes any combination of components of customer information that would allow someone to log onto or access the customer's account (such as user identification and security question answers).

Notice Delivery Timing and Law Enforcement Delay

  • Delivery Timing: Notice must be delivered in a clear and conspicuous manner as soon as possible after the institution concludes its investigation to determine the likelihood of misuse and has taken necessary containment measures.
  • Law Enforcement Delay Exception: Delivery of customer notice may be delayed only if an appropriate law enforcement agency determines in writing that notification will impede a criminal investigation and formally requests a temporary delay.

A customer notice should be clear and conspicuous, describe the incident and the types of information involved, and give a telephone number for assistance. Explain protective measures and steps the consumer can take. Depending on circumstances, include additional information on reports, fraud alerts and FTC assistance. The guidance permits delivery methods designed to ensure actual receipt, including mail, telephone or electronic means for customers with valid addresses who agreed to electronic communications; it does not prescribe one universal five-item format.


4. Computer-Security Incident Notification Rule (12 CFR Part 53 / Part 225 / Part 304)

Promulgated jointly by the OCC, Federal Reserve Board, and FDIC (effective May 1, 2022), this regulation establishes separate, rapid operational notification mandates designed to maintain supervisory situational awareness of systemic cyber threats.

Banking Organization 36-Hour Notification Mandate

A banking organization must notify its primary federal banking regulator of any "computer-security incident" that rises to the level of a "notification incident" as soon as possible and no later than 36 hours after the bank determines that a notification incident has occurred.

Definition of Notification Incident

A computer-security incident constitutes a notification incident if it has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, a banking organization's:

  1. Ability to carry out banking operations, activities, or processes, or deliver banking products and services to a material portion of its customer base;
  2. Business lines that, upon failure, would result in a material loss of revenue, profit, or franchise value; or
  3. Operations, the failure of which would pose a threat to the financial stability of the United States.

Examples of Notification Incidents: Large-scale ransomware attacks encrypting core banking servers; massive distributed denial of service (DDoS) attacks disabling consumer online and mobile banking for extended durations; or system-wide mainframe hardware failures halting check clearing or wire processing.

Bank Service Provider 4-Hour Notification Mandate

A bank service provider that provides covered operational or IT services to a banking organization must notify each affected bank customer as soon as possible when the service provider determines that it has experienced a computer-security incident that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, covered services for 4 or more hours.


5. Comparison: GLBA Supplement A vs. Computer-Security Incident Notification Rule

Compliance DimensionGLBA Supplement A (Customer Breach Notice)Computer-Security Incident Notification Rule
Governing Regulation12 CFR Part 30 / Part 364 App. B, Supp. A12 CFR Part 53 (OCC), Part 225 (FRB), Part 304 (FDIC)
Regulatory FocusConsumer financial privacy and data protectionOperational resilience and systemic safety/soundness
Triggering EventUnauthorized access to sensitive customer informationMaterial disruption or degradation of banking operations
Regulator Notice Timing"As soon as possible" upon becoming awareNo later than 36 hours after determining incident occurred
Customer Notice MandateNotice when misuse has occurred or is reasonably possibleNone (focuses on regulatory and inter-entity reporting)
Service Provider MandateContractual notification covenantsMandatory notice to bank if disruption lasts 4+ hours
Substantive ScopePersonally identifiable data breaches (SSN, account #)Ransomware, DDoS, core platform outages, cyber disruptions

Investigate unauthorized access to sensitive customer information. When the bank determines misuse has occurred or is reasonably possible, notify affected customers as soon as possible. A properly authorized law-enforcement delay may apply when notice would impede an investigation. Unauthorized access is an important trigger for investigation but does not automatically make every incident subject to customer notice. The separate 36-hour regulator-notification rule starts when the bank determines a notification incident occurred, not necessarily at the first alert. Service providers have a separate prompt notification obligation for qualifying service disruption or degradation lasting, or reasonably likely to last, four or more hours.

Test Your Knowledge

At 9:00 AM on Tuesday, a regional bank experiences a widespread ransomware attack that completely encrypts its core deposit processing servers, halting transaction processing across all retail branches and online banking. By 1:00 PM on Tuesday, IT leadership and senior executive management conclude that a notification incident has occurred under the Computer-Security Incident Notification Rule (12 CFR Part 53 / Part 225 / Part 304). By what deadline must the bank notify its primary federal banking regulator?

A

Within 72 hours of incident confirmation (1:00 PM Friday).

B

Within 4 hours of core system disruption (5:00 PM Tuesday).

C

Within 24 hours of incident discovery (9:00 AM Wednesday).

D

No later than 36 hours after determining that a notification incident occurred (1:00 AM Thursday).

Test Your Knowledge

A commercial bank discovers that an external cyber attacker bypassed network perimeter defenses and exfiltrated an unencrypted database table containing the full legal names, home street addresses, dates of birth, and Social Security numbers of 8,500 active deposit customers. Forensic investigators confirm the data was downloaded to an overseas IP address. Under Supplement A to Appendix B of the Interagency Guidelines, what is the bank's customer notification obligation?

A

The bank must deliver clear and conspicuous customer notice as soon as possible, because unauthorized access to sensitive customer information occurred and misuse has occurred or is reasonably possible based on the investigation.

B

The bank is prohibited from notifying customers until the federal banking regulator completes its formal supervisory examination.

C

The bank is exempt from notifying customers if it offers 12 months of free credit monitoring within 60 calendar days.

D

The bank may notify customers exclusively through a general press release posted on its website homepage.

Sections you finish are checked off in the contents.