System Report

US banks face 36‑hour cyber‑incident rule amid tighter reporting

New 36‑hour reporting rule forces banks to act fast The Federal Deposit Insurance Corporation, the Federal Reserve Board, and the Office of the Comptroller of the Currency approved a rule that obliges banking organiza…

High‑profile breaches push institutions toward tighter discipline The International Criminal Court announced last week that it detected "anomalous activity affecting its information systems" and activated urgent respo…

Incident reports need narrative discipline Andrea Fortuna’s essay on applying Chekhov’s gun to cybersecurity incident reports argues that every detail in a report must earn a payoff. She warns that mentioning a failed…

The regulatory tide: from banks to courts The 36‑hour rule reflects a broader shift toward mandatory, time‑bound disclosure across sectors that handle sensitive data. Financial regulators justified the rule by citing …

Read the full story

Continue on System Report

Open article