Transcription of FINANCIAL INSTITUTIONS DATA BREACH RESPONSE GUIDE …
1 data BREACH RESPONSE GUIDEHOW TO NAVIGATE THE FIRST 48 HOURS/////////////////////////////////// //////////////////////////////////////// //////////////////////////////////////// //////////////////////////////////////// /////// FINANCIAL INSTITUTIONSAVOIDING REGULATORYDOUBLE JEOPARDYHow to Stay Compliant While Adding Protection and Value for Customers WHITE PAPERINTRODUCTIONF inancial INSTITUTIONS face a daunting task when it comes to navigating government data security and BREACH regulations and that s putting it mildly. At the federal level many rules are vague by design. At the state level, complexity runs deep: banks and credit unions must comply with different guidelines in the 47 states that have BREACH , compliance is only one of many challenges FINANCIAL INSTITUTIONS face today. They also must respond to a range of demographic and technology-related trends that complicate their ability to secure data and remain compliant.
2 Key needs now include: Mobility and digital engagement Engaging with the millennial and high-value customer segments Technology integration to support outstanding customer experiences, streamlined processes and improved strategic decision-making Analytics for a better understanding of consumer behaviors and decision-making Ultimately, data reigns in modern FINANCIAL INSTITUTIONS and criminals will go to incredible lengths to get their hands on it. Even if you re doing everything right from a security standpoint, your institution could still suffer a BREACH . This white paper: Explores the FINANCIAL industry regulatory landscape along with some of the key trends that are influencing institutional operations. Explains how identity and data BREACH defense services can help your bank or credit union: Meet customer expectations Comply with state data BREACH laws while improving your standing with federal regulators Protect your brand reputation.
3 Provides five tips for choosing a good identity and data BREACH defense services THREATS, WORRIED CUSTOMERSF inancial INSTITUTIONS face escalating and increasingly sophisticated cyber threats that put their relationship with customers at risk. FIs are under pressure to innovate for their customers, yet technological advancements are a double-edged sword. On the one hand, new technology brings customer convenience and greater engagement. On the other hand, it creates more customer and employee access points and the potential for security risks and gaps. Everyone from lone actors and insiders to criminal organizations may be looking for opportunities in those gaps. Criminals use 1 GUIDE to Cybersecurity for FINANCIAL Services Firms, Lockheed Martin Corp., FACT:The finance sector experiences 300 percent more security incidents than other 1methods ranging from hacking to social engineering to malware to find holes in processes and systems, and get at money in different ways.
4 Sometimes, such as with account takeover or ransomware, it s direct. But there are plenty of indirect crimes related to data breaches. For example, crimes such as identity theft and new account fraud can go undiscovered for months or even years, in some cases. The Customer Protection DilemmaCustomers are increasingly awarethat they face risks online .. but that doesn t mean they percent of millennials rely on online 24- to 35 year-olds face the highest incidence of fraud and are least likely to take preventive percent of millennials and 77 percent of baby boomers worry about online consumers who don t believe they can effectively protect their FINANCIAL data often ignore preventive TO THE HEART OF data -RELATED COMPLIANCE CHALLENGESF ederal and state regulations related to data and customer protections are a confusing mishmash of rules. What s more, federal agencies tasked with protecting consumers add complexities and unknowns to compliance the federal level, banking regulations are generally focused either on what happens before data is lost or on preventing fraud.
5 There are no specifications about what FINANCIAL INSTITUTIONS must do once data is lost. For example: Gramm-Leach-Bliley Act requires FINANCIAL INSTITUTIONS to explain their information-sharing practices to their customers and to safeguard sensitive The Identity Theft and Assumption Deterrence Act of 1998 makes the FTC a central clearinghouse for identity theft complaints. It requires the FTC to log and acknowledge complaints, provide victims with relevant information and refer complaints to appropriate The Sarbanes-Oxley Act mandated a number of reforms to enhance corporate responsibility, boost FINANCIAL disclosures and combat corporate 2 GUIDE to Cybersecurity for FINANCIAL Services There s no slowing down millennials, First data Corporation, Online Fraud Perceptions: Millennials Vs. Boomers, ThreatMetrix, 2014 Identity Fraud Report, Javelin Strategy & 2016 Identity Fraud: Fraud Hits an Inflection Online Fraud Perceptions: Millennials Vs.
6 Boomers, ThreatMetrix, Gramm-Leach-Bliley Act, Federal Trade Commission, The Identity Theft and Assumption Deterrence Act of 1998, Federal Trade Commission, FACT:80 percent of FINANCIAL instiutions cite cyber risks as a top 2and accounting fraud. It created the Public Company Accounting Oversight Board to oversee the activities of the auditing fraud and data privacy laws aside, several agencies also have mandates to protect consumers. Take the Consumer FINANCIAL Protection Bureau (CFPB), which is tasked with ensuring that banks, lenders and FINANCIAL companies treat consumers The CFPB can create new rules or guidelines or even go after INSTITUTIONS for an inadequate RESPONSE to a data BREACH . But it s difficult to know how they may respond to different scenarios until they take enforcement majority of states at least require written notification in the event of a BREACH .
7 But beyond that it s the Wild West, with varying rules from state to state. Let s briefly look at some of the considerations around the more opaque regulatory bodies and state-by- state REGULATORY CHALLENGEST oday, forty-seven states mandate that entities provide at least written notification in the event of a data BREACH . The timelines for notifications and requirements, however, vary. For example, Connecticut mandates that organizations provide BREACH notifications within 90 days. When Social Security numbers are exposed, organizations must also provide appropriate identity theft protection or mitigation services at no cost for at least a In Oregon, on the other hand, businesses must notify customers of breaches impacting more than 250 people and provide a sample copy of the BREACH notification to the Oregon Attorney Only Alabama, New Mexico and South Dakota currently have no regulations are also evolving rapidly.
8 In 2015 alone, 33 states considered new bills or resolutions. Most of the bills were focused either on reporting breaches to stage agencies or on broadening the types of personal information that should be considered in a security BREACH . Meanwhile, New York s Department of FINANCIAL Services made news by introducing some of the most stringent and far-reaching cyber security rules to date. The new roles, scheduled to go into effect in March 2017, focus on improving cyber security programs, governance and formal processes, among other requirements. Given evolving threats and increasing citizen awareness, it s likely that other states will adopt similar regulations in the future. A federal law could simplify matters to some extent, but currently there are no options in the CONSUMER FINANCIAL PROTECTION BUREAUThe CFPB has a broad mandate, with a lot of room for interpretation. That s why many FINANCIAL INSTITUTIONS are uneasy about what they need to be doing to protect customers and themselves from regulatory actions.
9 The CFPB s goal is to protect consumers and promote fair, transparent and competitive markets. 15 At a high level, 10 Sarbanes-Oxley Act of 2002, Securities and Exchange Commission, # Consumer FINANCIAL Protection Bureau, New data security law in Connecticut imposes new requirements on businesses, regulated entities, and statecontractors, data Protection Report, July 27, Search data Security Breaches, Oregon Department of Justice and Consumer 2015 Security BREACH Legislation, National Conference of State Legislatures, December Compliance and Guidance, Consumer FINANCIAL Protection Bureau. 3the CFPB has similar consumer protection jurisdiction over the banks and credit unions that the Federal Trade Commission has over practically every other type of business in the In other words, the banking industry has its very own federal consumer protection agency.
10 16 How the CFPB is going to pursue its mandate in the FINANCIAL industry is unclear. Just consider that the CFPB pursued its first data security enforcement action in 2016 against an online payments company. The CFPB alleged the company was misrepresenting data security practices. It hit the offender with a $100,000 fine and training and security requirements and there wasn t even a It remains to be seen how the CFPB may react in the event of an actual BREACH incident with a FINANCIAL CFPB does note that identity monitoring or identity theft protection services may help consumers correct identity theft related problems, but that the terms and conditions of the service are especially important. For example, it suggests that consumers carefully consider service options, making sure that: free trial offers don t include hidden fees, trial periods or cancellation requirements the provider hasn t been subject to actions by local consumer protection agencies or the state attorney general s THE OFFICE OF THE COMPTROLLER OF THE CURRENCYThe OCC has made cyber security actions a key focus area in recent years.