Search:


Print View | Disable Glossary

Regulations

Data Breach

Last Reviewed: May, 2018

News stories about data breaches are becoming more common. Credit unions are required to implement measures to safeguard members’ information. Credit unions also must have procedures in place to respond to data breaches at other organizations or corporations that compromise members’ information.

What does a credit union need to do in the event there is unauthorized access of member information?
The National Credit Union Administration (NCUA) amended its security program requirements (Part 748 of the Rules and Regulations) to include a response program to address instances of unauthorized or attempted unauthorized access to member information. The final rule requires that every federally insured credit union develop and implement an Information Security and Response Program (ISRP) designed to address incidents of unauthorized access to member information maintained by the credit union or its service provider.

In addition, most states have requirements for notification in case of a security breach, (see Security Breach Notification Laws in Related Links)

Background Information
The Gramm-Leach-Bliley Act required the NCUA and other banking agencies to establish standards for their financial institutions relating to administrative, technical and physical safeguards of consumer records and information. The NCUA amended Part 748 of its Rules and Regulations and added Appendix A, "Guidelines for Safeguarding Member Information". The safeguards are intended to:

  1. Insure the security and confidentiality of member records and information;
  2. Protect against any anticipated threats or hazards to the security or integrity of such records; and
  3. Protect against unauthorized access to or use of such records or information that could result in substantial harm or inconvenience to a member.

Over the past few years there has been an increase in the number of breaches or attempted breaches of member information that has resulted in identity theft. To address this situation, amended Part 748, requiring credit unions to add to their security programs a response program that addresses incidents of unauthorized access to or use of member information that could result in substantial harm or serious inconvenience to a member. The rule includes Appendix B, "Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice", which provides details of what should be included in these response programs.

The Federal Financial Institution Examinations Council (FFIEC) has established criteria to be used to evaluate the credit union’s information security program. NCUA and state regulators use these guidelines to evaluate the program during annual IT examinations.

Definitions
Information security and response program (ISRP) - establishes a formalized process to prevent, detect, and respond to security vulnerabilities with respect to maintaining member data integrity and confidentiality.

Member information system – any method used to access, collect, store, use, transmit, protect or dispose of member information, including systems maintained by service providers.

Security incident – an adverse event, or the threat of one, that affects the credit union’s computer network and/or information system. Security incidents can occur in innumerable ways and include, but are not limited to:

  • Attempted or unauthorized access to a credit union’s network.
  • Attempted or unauthorized access to a credit union’s third-party vendor network (where the vendor has access to or maintains confidential member information).
  • Stolen or lost laptops, data disks, or mobile devices (i.e. Smartphones, PDAs, tablet PCs).
  • Malicious code, network probes, denial of service attacks, malware, network takeovers, and system crashes.
  • Confidential information attached to or contained within an e-mail without utilizing some form of encryption, etc.
  • Negligent data disposal.

Sensitive member information – a member’s name, address, or telephone number, in conjunction with the member’s social security number, driver’s license number, account number, credit or debit card number, or a personal identification number or password that would permit access to the member’s account. It also includes any combination of components of member information that would allow someone to log onto or access the member’s account, such as user name and password or password and account number.

Appendix B to Part 748 – Guidance on Response Programs for Unauthorized Access to Member Information and Member Notice
The guidance in Appendix B to NCUA’s Part 748 describes response programs, including member notification procedures, that credit unions should develop and implement to address unauthorized access to or use of member information that could result in substantial harm or inconvenience to the member.

Response Program Components
The credit union’s response program should contain procedures which allow the credit union to:

  • Assess the nature and scope of an incident, and identity what member information systems and types of member information have been accessed or misused.
  • Notify the appropriate regulatory authority, as soon as possible, when the credit union becomes aware of an incident involving unauthorized access to or use of sensitive information:
    • NCUA Regional Director – Federally-insured credit unions
    • State Supervisory Authority - Non-federally-insured credit unions
  • Consistent with Bank Secrecy Act regulations, notify appropriate law enforcement authorities and timely filing of suspicious activity reports or other reports required by law.
  • Take appropriate steps to contain and control the incident to prevent further unauthorized access to or use of member information.
  • Notify members when warranted.

Where an incident of unauthorized access to member information involves the credit union’s member information systems maintained by a credit union’s third-party service providers, it is the responsibility of the credit union to notify its members and regulator. However, a credit union may authorize or contract with its service provider to notify members or regulators on its behalf.

FFIEC exam questions:

  • Does the program outline procedures to address incidents of unauthorized access to member information in systems maintained by its domestic and foreign third-party service providers?
  • Does the credit union’s response program contain:
    • Procedures for assessing the nature and scope of an incident?
    • Procedures for identifying what member information systems and types of member information have been accessed without permission?
    • Procedures for notifying the appropriate federal or state regulatory authorities, as soon as possible, when the credit union becomes aware of an incident involving unauthorized access to or use of sensitive member information?
    • Procedures for filing suspicious activity reports (initially and on a continuing basis, if necessary) and other reports that may be required by regulation?
    • Procedures for notifying appropriate law enforcement authorities of situations requiring immediate attention?
    • Appropriate steps to contain and control the incident to prevent further unauthorized access to or use of member information?
    • Procedures for notifying members, when warranted?
    • Procedures for notifying affected members when the incident involves unauthorized access to member information systems maintained by a credit union’s third-party service providers?

Member Notification
When a credit union becomes aware of an incident of unauthorized access to sensitive member information, it should conduct a reasonable investigation to promptly determine the likelihood that the information has been or will be misused. If the credit union determines that misuse of its information about a member has occurred or is reasonably possible, it should notify the affected member as soon as possible.

Notice may be delayed if an appropriate law enforcement agency determines that the notification will interfere with a criminal investigation and provides the credit union with a written request for the delay. The credit union should notify its members as soon as notification will no longer interfere with the investigation.

After its investigation, if a credit union can determine from its logs or other data precisely which member information has been improperly accessed, it may limit notification to those members with regard to whom the credit union determines that misuse of their information has occurred or is reasonably possible. There may be situations where the credit union determines that a group of files has been accessed improperly, but is unable to identify which specific member’s information has been accessed. If the circumstances of the unauthorized access lead the credit union to determine that misuse of the information is reasonably possible, it should notify all members in the group.

FFIEC exam questions:

  • Does the credit union’s response program contain procedures for notifying members, when warranted?
  • Does the credit union’s response program contain procedures for notifying affected members when the incident involves unauthorized access to member information systems maintained by a credit union’s third-party service providers?

Notice Content
The notice should be clear and conspicuous, and should be delivered in any manner designed to ensure that the member can reasonably be expected to receive it. The credit union may choose to contact all affected members by telephone, mail, or electronic mail for those members for whom it has a valid e-mail address and who have agreed to receive communications electronically.

The notice should include the following information:

  1. Description of the incident in general terms and the type of member information that was the subject of unauthorized access or use;
  2. General description of what the credit union has done to protect the members’ information from further unauthorized access;
  3. A telephone number that members can call for further information and assistance;
  4. A reminder of the need to remain vigilant over the next twelve to twenty-four months, and to promptly report incidents of suspected identity theft to the credit union;
  5. A recommendation that the member review account statements and immediately report any suspicious activity to the credit union;
  6. A description of fraud alerts and an explanation of how the member may place a fraud alert in his or her credit report to put creditors on notice that the member may be a victim of fraud;
  7. A recommendation that the member periodically obtain credit reports from each nationwide credit reporting agency (CRA) and have information relating to fraudulent transactions deleted;
  8. An explanation of how the member may obtain a credit report free of charge* (www.annualcreditreport.com); and
  9. Information about the availability of the Federal Trade Commission’s (FTC) online guidance regarding steps that can be taken to protect against identity theft. The notice should encourage the member to report any incidents of identity theft to the FTC, and should provide the FTC’s website address (www.ftc.gov/idtheft) and toll-free telephone number (1-877-IDTHEFT) that members may use to obtain the identity theft guidance and report suspected incidents of identity theft.

If a credit union provides contact information for CRAs, NCUA encourages the credit union to notify the CRAs prior to sending this information to a large number of members.

FFIEC exam questions:

  • Does the member notice:
    • Provide information in a clear and conspicuous manner?
    • Describe the incident in general terms, as well as the type of member information that was the subject of unauthorized access or use?
    • Describe what the credit union has done to protect the members’ information from further unauthorized access or use?
    • Include a telephone number that members can call for further information and assistance?
    • Remind members of the need to remain vigilant over the next 12-to-24 months, and to promptly report incidents of suspected identity theft to the credit union?
       
  • Does the notice contain the following, when necessary:
    • A recommendation that the member review account statements and immediately report any suspicious activity to the credit union?
    • A description of fraud alerts and an explanation of how the member may place a fraud alert in their consumer reports to put creditors on notice that the member may be a victim of fraud?
    • A recommendation that the member periodically obtain credit reports from each nationwide consumer reporting agency and have information relating to fraudulent transactions deleted?
    • An explanation of how the member may obtain a credit report free of charge?
    • Information about the availability of the FTC’s online guidance regarding steps a consumer can take to protect against identity theft?

Media Response Components
An effective media response plan will help positively reinforce the public perception of the credit union. Consider integrating a media response plan as a component of the credit union’s information security and response program. The media response plan should cover a broad range of scenarios, ranging from general press releases to full-scale media assaults.

Like the credit union’s overall ISRP, the media response plan procedures should be regularly reviewed, including any pre-written statements, by the credit union’s attorney and media relations specialist. Procedures should document such areas as:

  • Individuals responsible for coordinating the media response.
  • Individuals responsible for communicating with the media.
  • Training for designated credit union spokespersons on speaking to the media.

Pre-Emptive Measures the Credit Union Should Take to Mitigate Risk
In an effort to ensure compliance and avoid potential exposure to fines and/or lawsuits, the credit union may want to consider implementing the follow information and security response program procedures:

  • Develop and maintain a written policy and procedures regarding what actions the credit union should take to help prevent, detect, and respond to security breaches.
  • Conduct a risk assessment to identify and classify confidential information.
  • Use personnel or hire outside consultants with sufficient expertise to assess risks and design procedures to prevent or mitigate risk.
  • Review the credit union’s third-party vendor contracts to ensure detailed allocation of liability, hold harmless, and indemnity.
  • Utilize best practices for the passwords for credit union employees and members, such as requiring strong passwords that contain alpha, numeric, and special characters; frequently-changing passwords; and utilizing different passwords for different accounts.
  • Consistently review and adjust the credit union’s security programs (i.e. install new software patches and attack prevention technologies, update firewalls, utilize virus protection, etc.).
  • Recognize that compliance is not a piece of software, but is achieved through a combination of controls, policies, procedures, processes, and individuals.
  • Implement a media response plan for those situations where the credit union may have to deal with unwanted publicity and media attention.
  • Be aware of news reports and information and advisories from regulatory agencies regarding security breaches.
  • Make sure staff is adequately trained on the credit unions policies and procedures.