Skip to Main Content
ICBA
  • Member Login
  • Member Login

Cyber and Data Security

Influencing policy: Cyber and Data Security

ICBA Expert Contact

Anjelica Dortch

Vice President, Operational Risk & Cybersecurity Policy

ICBA

Contact Example Text

Agency Guidance & Regulations

Community banks are navigating an increasingly complex cybersecurity landscape, shaped by evolving regulatory expectations, emerging threats, and industry best practices. 

For ICBA members, key touchpoints include cybersecurity and information security guidance from the Federal Reserve, the Office of the Comptroller of the Currency (OCC), the Federal Deposit Insurance Corporation (FDIC), and the Federal Financial Institutions Examination Council (FFIEC).  

Federal Reserve 

  • 12 CFR Part 225 (Bank Holding Companies) 

Office of the Comptroller of the Currency (OCC) 

  • 12 CFR Part 30 (Safety and Soundness Standards) 
  • 12 CFR Part 53 (Computer-Security Incident Notification Requirements) 

Federal Deposit Insurance Corporation (FDIC) 

  • 12 CFR Part 304 (Cyber incident notification) 
  • 12 CFR Part 364 (Computer-security Incident Notification Requirements) 

Securities and Exchange Commission (SEC) 

  • 17 CFR Part 242 (Systems Compliance, Cybersecurity & Operations Resilience (Reg SCI) 
  • 17 CFR Part 248 (Customer Information Security & Privacy Safeguards) 
  • Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure Rule (2023) 

U.S. Department of Treasury  

  • 31 CFR Part 1020 (Bank Secrecy Act Requirements) 

Federal Trade Commission (FTC) 

  • 16 CFR Part 314 (Safeguards Rule) 

U.S. Department Homeland Security  

  • Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)  

NIST Frameworks 

FFIEC Guidance 

Cyber and data security continues to be a top concern for community banks as cyber threats, fraud schemes, third-party risks, and data-sharing requirements become ever more complex.

Advances in AI and digital banking are creating new opportunities and new security considerations, making strong governance, resilience, and risk management top priorities. 

Key Issues Community Bankers Should Watch 

AI-Enabled Cyber Threats: The growing use of AI is increasing both cyber risk and the need for responsible AI governance.  

Third-Party & Vendor Risk: Regulators and policymakers continue to focus on the security of companies that access, store, or process customer financial data.  

Data Sharing & Open Banking: Expanded customer data access requirements are elevating concerns around privacy, security, liability, and third-party oversight.  

Fraud & Cybercrime: Ransomware, data breaches, and progressively more sophisticated fraud attacks remain significant risks for community banks and their customers.  

Threat Intelligence & Resilience: Industry and government collaboration on threat sharing, incident response, and operational resilience continues to grow in importance.  

ICBA advocates for risk-based cybersecurity policies that recognize the unique needs of community banks while promoting stronger protections across the broader financial ecosystem. 

Be Heard Example Text

News and Articles

Showing 1 to 3 of 9

Policy Position and Background Information

Robust cybersecurity and data protection are critical to maintaining trust and compliance in community banking. Learn how advanced defenses and risk management strategies shield sensitive information from growing cyber threats.

  • Any new Federal or state legislation, regulation, or guidance related to data or cybersecurity should be non-proscriptive and non-duplicative.  

  • ICBA suggests that regulators broaden their supervision to include all companies that have access to consumer financial data. 

  • Regulators should not mandate the use of any one framework, tool, or assessment, but rather support community banks’ ability to use the framework, tool or assessment that best suits their institution’s size, complexity, and risk tolerance.  

  • ICBA supports bi-directional sharing of threat intelligence between the financial sector and the government.  

  • ICBA supports stronger cybersecurity standards and practices for government.  

  • ICBA supports financial sector initiatives such as .BANK and Sheltered Harbor.  

To better address increasingly sophisticated threats, state and federal legislation, regulation, and guidance should enable community banks to implement risk-based security programs. Lawmakers and regulators should harmonize future legislation or regulatory action with existing regulatory requirements. Additionally, regulators should broaden their supervision to include all companies that have access to, use, or store consumer financial data. These companies should be subject to the standards outlined in the Gramm-Leach-Bliley Act (GLBA). 

Community banks have various sizes, complexities, and risk tolerances. As such, regulators should allow community banks to choose the assessment tool that best fits their institution’s risk profile. 

ICBA recognizes that the U.S. Government also has a responsibility to safeguard financial and personally identifiable information (PII) and to provide banks with visibility into the government’s business continuity, incident response, and other critical resiliency plans. Bi-directional threat information sharing initiatives, such as the Financial Services Information Sharing and Analysis Center (FS-ISAC), are critical to threat mitigation. 

.BANK, Sheltered Harbor, and other financial sector efforts enhance protection for bank customer account data.  

Artificial Intelligence

Artificial intelligence is transforming community banking and creating new opportunities to better serve customers while introducing new risks that must be managed. 

Learn More Example Text

Cyber Incidents and Breaches

Safeguarding customer information is critical to maintaining the public’s trust in the banking system. Data breaches in the private and public sectors jeopardize consumer financial data and increase the chances of financial fraud of all types.

Learn More Example Text

Payments Fraud & Scams

Community banks and their customers have been increasingly challenged by a rise in fraud and scams across payment types. Most significantly, check fraud has emerged over the last several years as a leading concern.

Learn More Example Text

Customer Data Access/Open Banking

Section 1033 of the Dodd-Frank Act gives consumers the right to access their financial records in electronic form. In 2024 the CFPB finalized a rule implementing Section 1033. 

Learn More Example Text