Newsroom
NAFCU supports enhanced data security protections under safeguards proposal
NAFCU's Andrew Morris shared the association's support of the Federal Trade Commission's (FTC) efforts to modernize its Safeguards Rule in a letter sent Friday. The proposed amendments would amend the FTC's implementation of the Gramm-Leach Bliley Act's (GLBA) safeguards provisions by aligning data security standards for nonbank financial companies more closely with those already established by prudential regulators.
"Although federally-insured credit unions are not subject to the FTC's Safeguards Rule, they follow regulations and guidance promulgated by the National Credit Union Administration (NCUA) and the Federal Financial Institutions Examination Council (FFIEC)," wrote Morris, NAFCU's senior counsel for research and policy. "Given the severity and extent of recent data breaches at financial companies subject to the FTC's jurisdiction and Safeguards Rule, such as Equifax, it is imperative to adopt more comprehensive security requirements."
Morris acknowledged that the proposed incident response plan is an improvement in regards to cyber hygiene, but recommended that the FTC consider additional reporting and notification requirements to "ensure that security breaches can be contained and mitigated as quickly as possible."
"NAFCU considers mandatory reporting and disclosure essential in any federal data security standard and has, for many years, advocated for legislation that would hold merchants and other entities handling financial information accountable for the consequences of data breaches," Morris said.
NAFCU also sought clarification of the applicability of the Safeguards Rule to accommodate existing regulatory frameworks for data security.
NAFCU has long been active with lawmakers on the issue of data security and was the first group after the massive 2013 Target data breach to call for a legislative solution to reform the nation's data security system. The association has cybersecurity compliance resources available online.
Share This
Related Resources
Add to Calendar 2024-06-26 14:00:00 2024-06-26 14:00:00 Gallagher Executive Compensation and Benefits Survey About the Webinar The webinar will share trends in executive pay increases, annual bonuses, and nonqualified benefit plans. Learn how to use the data charts as well as make this data actionable in order to improve your retention strategy. You’ll hear directly from the survey project manager on how to maximize the data points to gain a competitive edge in the market. Key findings on: Total compensation by asset size Nonqualified benefit plans Bonus targets and metrics Prerequisites Demographics Board expenses Watch On-Demand Web NAFCU digital@nafcu.org America/New_York public
Gallagher Executive Compensation and Benefits Survey
preferred partner
Gallagher
Webinar
Add to Calendar 2024-06-21 09:00:00 2024-06-21 09:00:00 The Evolving Role of the CISO in Credit Unions Listen On: Key Takeaways: [01:30] Being able to properly implement risk management decisions, especially in the cyber age we live in, is incredibly important so CISOs have a lot of challenges here. [02:27] Having a leader who can really communicate cyber risks and understand how ready that institution is to deal with cyber events is incredibly important. [05:36] We need to be talking about risk openly. We need to be documenting and really understanding what remediating risk looks like and how you do that strategically. [16:38] Governance, risk, compliance, and adherence to regulatory controls are all being looked at much more closely. You are also seeing other technology that is coming into the fold directly responsible for helping CISOs navigate those waters. [18:28] The reaction from the governing bodies is directly related to the needs of the position. They’re trying to help make sure that we are positioned in a way that gets us the most possibility of success, maturing our postures and protecting the institutions. Web NAFCU digital@nafcu.org America/New_York public
The Evolving Role of the CISO in Credit Unions
preferred partner
DefenseStorm
Podcast
AI in Action: Redefining Disaster Preparedness and Financial Security
Strategy
preferred partner
Allied Solutions
Blog Post
Get daily updates.
Subscribe to NAFCU today.