Sullivan & Cromwell LLP Logo Sullivan & Cromwell LLP Logo
  • Lawyers
  • Practices
  • Insights
  • About
  • Careers
  • Alumni
  • Twitter icon
  • LinkedIn icon
  •  icon
  • Podcasts icon
© 2026 Sullivan & Cromwell LLP
    • Home
    • Lawyers
    • Practices
    • Insights
    • About
    • Careers
    • Alumni
    Home /  Insights /  Memos and Newsletters /  Memo
    Memos

    Federal Banking Agencies Issue Final Rule Regarding Cyber Incident Notification Requirements

    Final Rule Requires Banking Organizations to Notify Primary Federal Regulator of Certain Cyber Incidents Within 36 Hours, and Bank Service Providers to Notify Banking Organization Customers as Soon as Possible

    November 22, 2021 | min read |
    • Related Practices

    On November 18, 2021, the Board of Governors of the Federal Reserve System (the “Board”), the Office of the Comptroller of the Currency (the “OCC”), and the Federal Deposit Insurance Corporation (the “FDIC,” and together, the “Agencies”) issued a final rule (the “final rule”) mandating the reporting of certain significant cybersecurity incidents to regulators.

    Read More
    Stay Updated

    Subscribe to stay current on S&C Insights.

    Related Practices Related Practices

    • Cybersecurity
    • Financial Services
    • National Security
    • Privacy
    Sullivan & Cromwell LLP Logo Sullivan & Cromwell LLP Logo
    • Twitter icon
    • LinkedIn icon
    • RSS Feed icon
    • Podcasts icon
    • Contact Us
    • Cookies
    • Privacy & Disclaimers
    • Attorney Advertising
    © 2026 Sullivan & Cromwell LLP