Prevention and risk mitigation are key components in every aspect of bank operations - the same holds true in the protection of customer data.
All participants in the payments and financial services sector ecosystem, including but not limited to merchants, aggregators, technology companies, and entities with access to customer financial information, should be subject to Gramm-Leach-Bliley Act (GLBA) like data security standards.
ICBA supports national data security standards, including customer incident/breach notifications, to replace the current patchwork of state laws.
Community banks should be notified by impacted entities of a potential and/or actual breach as expeditiously as possible in order to mitigate losses.
The costs of data breaches should ultimately be borne by the party that incurs the breach. Barring a shift in liability to the breached entity, community banks should have continued access to various cost-recovery options, including account recovery programs and litigation.
All stakeholders must continue to freely innovate to effectively protect consumer data and consumer confidence.
ICBA supports stronger data security standards and practices for law enforcement, regulatory agencies, and other governmental departments and staff.
Data breaches at credit bureaus, retailers, hotel chains, social media networks, data aggregators, technology companies, and elsewhere jeopardize consumers’ financial integrity and confidence in the financial services industry.
Community banks are strong guardians of the security and confidentiality of customer information as a matter of good business practice and legal and regulatory compliance. Safeguarding customer information is critical to maintaining public trust and retaining customers. However, bad actors will continue to look for weaknesses in the payments and information systems in various industries, and breaches will occur.
Extend Gramm-Leach-Bliley Act-Like Standards
Under current federal law, retailers, data aggregators, technology companies, and other parties that process or store consumer financial data are not subject to the same federal data security standards and oversight as financial institutions. Securing data at financial institutions is of limited value if it remains exposed at the point-of-sale and other processing points. To effectively secure customer data, all participants in the payments system, and all entities with access to customer financial information, should be subject to and maintain well-recognized standards such as those created by the Gramm-Leach-Bliley Act (GLBA).
A National Data Security Breach and Notification Standard is Vital
Many states have enacted laws with differing requirements for providing notice in the event of a data breach. This patchwork of state notification laws and overly broad notification requirements only increase burdens and costs, foster confusion, and ultimately are detrimental to customers.
While notifying customers is appropriate, any national notification standard needs to be accompanied by GLBA-like data security standards for all participants of the financial services industry to provide consumers a greater level of protection. Federal banking agencies should continue to set the standard for financial institutions.
Banks Need Timely and Enhanced Breach Notification
It is equally important that community banks receive timely notification concerning the nature and scope of any breach that may have compromised customer information so that they may take steps to mitigate any damage. Enhanced breach notification can save community banks time and money and is in the best interest of customers. Technology and service providers should also, as a matter of course, provide visibility into their business continuity, incident response, and other critical resiliency plans.
Breach Liability Should Incentivize Stronger Security
Regardless of where a breach occurs, as stewards of the customer financial relationship, banks take a variety of steps at their own expense to protect the integrity of customer accounts. However, these costs should ultimately be borne by the party that incurs the breach. Barring a liability shift, community banks should have access to various cost recovery options. Too often, the breached entity evades accountability while financial institutions are left to mitigate damages to their customers.
Governmental Departments and Agencies Must Safeguard Data
Despite issuing rules, regulations, and guidance, and examining financial institutions for the safekeeping of customer data, regulatory bodies and governmental agencies have also been subject to data breaches. During bank examinations, regulators become privy to and hold sensitive bank information, including customer information.
Banks also submit information on customers to the Financial Crimes Enforcement Network through Suspicious Activity Reports (SARs). Like banks, Governmental departments and agencies have a responsibility to safeguard sensitive information. Liability for a breach of governmental systems may be unfairly assigned to the community banks that submitted data to them, though they did so securely.
Any federal or state cybersecurity legislation, regulation, guidance, or framework should recognize existing mandates and standards to ensure community banks are not burdened with the obligation to reassess their critical systems against a duplicative or overlapping standards, which would yield similar results.
Regulators should not mandate the use of any one framework, tool, or assessment, but rather support community banks’ ability to use the framework, tool or assessment that best suits their institution’s size, complexity, and risk tolerance.
ICBA supports voluntary information sharing among financial institutions of all sizes, public-private partnerships, and federal agencies for the purpose of identifying, responding to, and mitigating cybersecurity threats and vulnerabilities while appropriately balancing the need to secure customer information.
Regulators must broaden their supervision to include additional core processors, fintech companies, and other third-party technology and service providers on which community banks rely. Employees and subcontractors of technology service providers should comply with nondisclosure and confidentiality requirements similar to those that apply to banks.
Congress must subject credit reporting agencies and other customer financial data collectors/aggregators to federal examination and supervision comparable to that which applies to community banks and other financial institutions.
ICBA supports cybersecurity initiatives such as .BANK and Sheltered Harbor and will work with community bank core processors to ensure equitable and reasonable access to these initiatives.
ICBA supports stronger cybersecurity standards and practices for law enforcement, regulatory agencies, and other governmental departments and agencies.
The financial services industry, including community banks, is on the front lines defending against cybersecurity threats and takes its role in securing data and personal information very seriously. As a result of sophisticated and constantly evolving cyber threats and intrusions, the federal government and private industry are increasingly focused on cybersecurity.
Cybersecurity Risk Assessment Tools
Standards and technology policymakers must not be proscriptive in the use of cybersecurity frameworks. There are many acceptable tools and assessments such as the National Institute of Standards and Technology’s Cybersecurity Framework, and the Federal Financial Institutions Examination Council (FFIEC) Cybersecurity Assessment Tool (CAT).
Threat Information Sharing is Critical
The sharing of advanced threat and attack data between federal agencies and financial services sector participants helps manage cyber threats and protect critical systems. ICBA supports community banks’ involvement with services such as the Financial Services Information Sharing and Analysis Center (FS-ISAC), a non-profit information-sharing forum established by financial services industry participants to facilitate public and private sector sharing of physical and cybersecurity threat and vulnerability information.
ICBA supports FS-ISAC’s cross-sector information sharing efforts to enhance overall resiliency of the nation’s critical infrastructure. ICBA’s Sector Fraud Working Group shares fraud intelligence with a wide range of public and private stakeholders.
Oversight and Mitigation of Third-Party Risk
Community banks significantly rely on third party technology and service providers to support their systems and business activities. While community banks are diligent in their management of third parties, mitigating sophisticated cyber threats against them can be challenging, especially when they have connections to other institutions and servicers.
Regulators must be aware of the significant interconnectivity of these third parties and collaborate with them to mitigate risk. The agencies should evaluate the concentration risks of service providers to financial institutions and broaden supervision of technology service providers to include additional third-party technology and service providers.
Among other issues, employees of technology and service providers have access to confidential bank information that could be used to commit fraud, damage a bank’s reputation, or compromise customer privacy. Regulators must ensure that these service providers implement nondisclosure and confidentiality requirements similar to existing regulatory requirements for banks. They must provide disclosure when employees or contractors are non-U.S. citizens.
Examination and Supervision of Credit Rating Agencies
The 2017 Equifax data breach demonstrated how important it is that the credit rating agencies (CRAs) and other collectors/aggregators of customer financial data be subject to examination and supervision by prudential regulators. The release of this information has the potential to adversely affect American consumers for the remainder of their lives and presents unique challenges for all financial institutions in authenticating new and existing customers. Subjecting CRAs and similar organizations to appropriate oversight may prevent future breaches.
Sector Cybersecurity Initiatives
The .BANK web domain is a trusted, verified, secure, and easily identifiable location on the internet for the banking community and the customers it serves. With rigorous security standards in place, users of a .BANK website can be assured they are landing on participants’ actual websites as opposed to being redirected elsewhere such as a malicious or spoofed site. .BANK also provides email authentication to mitigate spoofing and phishing as well as encryption for internet connections to ensure data privacy and security.
Sheltered Harbor is designed to improve resiliency and provide enhanced protection for financial institution customer accounts and data. Sheltered Harbor enables financial institutions to securely store and rapidly restore account information. When an institution is unable to recover from a cyber incident in a timely fashion, Sheltered Harbor makes account information available to customers through a service provider or another financial institution.
Governmental Departments and Agencies
Despite issuing cybersecurity regulations and guidance covering financial institutions, governmental departments and agencies have also been subject to data breaches. The government has a responsibility to safeguard sensitive information. Liability and costs of a breach of governmental systems may be unfairly assigned to the banking sector and result in a loss in confidence. Additionally, there is high risk of identity theft of American citizens.
By their very nature, community banks and other financial institutions must collect sensitive nonpublic personally identifiable information (PII) about customers to meet their needs for financial services, which includes an array of deposit and loan services.
This information is also used to prevent fraud, identity theft and comply with various regulatory requirements. Safeguarding customer information is central to financial institutions maintaining public trust and retaining customers.
Third Party and Non-Bank Privacy. Information that is gathered by entities outside of the financial services industry is not held to the same standards as it relates to
safeguarding information. Once information is shared with permissioned third-parties, consumers may no longer have control of their personal and financial information.
The potential for abuse is real and can be extremely harmful to consumers. This leaves consumers vulnerable to entities that may mislead them about what they do with the information they collect. This places an extraordinary burden on consumers to be vigilant in their research and knowledge of firms to which they may provide their online account credentials.
For this reason, ICBA has profound concerns that non-bank entities which may be authorized by consumers to access their information and store their bank login credentials may not take the same care in protecting consumer privacy and data as community banks.
At a minimum, consumers must have the same GLBA-like privacy protections with permissioned third parties as they have with banks, including limitations on the use of consumer information and limitations on the disclosure of the consumer’s information to third parties.
Privacy Standards. Community banks are committed to complying with existing standards to protect customer privacy as outlined in the GLBA and the Safeguards Rule. However, many states are
establishing privacy requirements to enhance consumer protection.
While ICBA fully supports privacy standards, particularly as it relates to protecting consumer financial information and PII, creating a patchwork of differing state privacy laws and requirements creates unnecessary costs and burdens for community banks and other small businesses.
It is important to maintain one standard as opposed to many complex and potentially competing state-level standards.
GLBA Exemption. Community banks have protected consumer privacy for the last two decades under the Gramm-Leach-Bliley Act. ICBA supports the GLBA and the privacy standards and enforcement
Given the patchwork of state privacy laws currently in place and being signed into law, ICBA supports an entity-level exemption from proposed laws due to the strict privacy requirements in GLBA and stringent enforcement by federal regulators. Complying to both the GLBA and the various state laws which community banks may fall under, would be both unnecessarily burdensome and duplicative.
The GLBA requires financial institutions to provide protections for consumer’s data and prevents financial institutions from sharing consumers’ personal information under certain circumstances without offering consumers a reasonable opportunity
to opt out of such sharing.
Further, the GLBA’s Safeguards Rule requires financial institutions to review their consumer data, identify security risks and develop a comprehensive security program to protect consumer data from unauthorized use and disclosure. Including such an exemption in state privacy laws will continue to protect consumers while avoiding any unnecessary barriers to community banks.
Staff Contacts: Steven Estep and Susan Sullivan.