Report a material computer-security incident to the bank as soon as possible
Incident Response policy, §5.2, §7.2
When the Company determines it has experienced a computer-security incident, with or without unauthorized access, that has materially disrupted or degraded, or is reasonably likely to materially disrupt or degrade, the services it provides to the sponsor bank for four hours or more, it notifies the bank as soon as possible. The notice is not held for a completed investigation, because it feeds the bank’s own 36-hour notice to its regulator.
Event-driven
As soon as possible after determining a disruption of 4 hours or more has occurred or is reasonably likely
Make the four-hour determination on confirmation, send the notice to the bank’s security contacts with what is known, log the time, and supply the details the bank needs for its regulatory notice.
- Determination record
Time the four-hour threshold was judged met or likely, and by whom
- Bank notice
Notice sent with the time, against the determination time
Compliance Officer
Leela can prepare the artifact and hand it to a person for review.
Leela can draft the notice from the outage record the moment the four-hour threshold is judged met and route it to the Compliance Officer to send.
Tell Leela about your company to see whether this applies.
Tell Leela how you handle it today, or hand it over: see what’s next.