Houston Chronicle

Regulators propose stricter cybersecur­ity rule for big banks

- By Kevin G. Hall

WASHINGTON — Federal regulators have a new reason to worry that some banks might be too big to fail — cybersecur­ity.

Collective­ly, these bank regulators Wednesday put out a notice of proposed rulemaking that, if enacted, would subject the nation’s largest banks to enhanced cyber risk management standards.

“Specifical­ly, the agencies are considerin­g a requiremen­t that covered entities develop a written, boardappro­ved, enterprise-wide cyber risk management strategy that is incorporat­ed into the overall business strategy and risk management of the firm,” they wrote in the proposed rule.

The recent hacks of the Democratic National Committee and of the email accounts of Hillary Clinton’s campaign chief John Podesta have served to highlight cyber threats. Consumers and the financial sector today depend heavily on the internet and mobile devices for transactio­ns and bank regulators worry that the interconne­ctedness of the financial system poses unique risks. Advance notice issued

The Federal Deposit Insurance Corp. issued an advanced notice Wednesday of the proposed rulemaking, and was joined by the Federal Reserve and the Office of the Comptrolle­r of the Currency.

“Separately, the Federal Reserve Board is considerin­g applying the standards to nonbank financial companies and financial market utilities, as well as other financial market infrastruc­tures subject to Federal Reserve supervisio­n,” FDIC Chairman Martin Gruenberg said in a statement.

Translatio­n: The tougher rules and standards would apply not just to banks but many of the critical components that go into the workings of the complex web of interconne­ctedness that is the financial system.

Under the 2010 revamp of financial regulation, which followed the near collapse of the financial sector in 2008, the largest banks were subjected to greater reporting requiremen­ts and limits on their risk taking. They escaped worse, given the talk of breaking up the largest institutio­ns on the grounds that they were so big that their failure could drag down the financial system. Five areas of risk

Wednesday’s proposed rule addresses that concern about the largest banks. It generally applies to institutio­ns with assets of $50 billion or more, and doesn’t spell out specific standards. Instead, it will require these institutio­ns to report to regulators about enhanced standards in five areas: cyber risk governance, cyber risk management, internal dependency management, external dependency management and incident response, which encompasse­s cyber resilience and situationa­l awareness.

Beyond their oversight of banks’ efforts, the agencies themselves have suffered some serious security breaches. Computers at the Fed were penetrated dozens of times between 2011 and 2015, according to House lawmakers. The breaches raised concerns about the Fed’s ability to safeguard sensitive financial informatio­n, the lawmakers said.

The Chinese government, meanwhile, is believed to have hacked into computers at the FDIC in 2010, 2011 and 2013, including the workstatio­n of then-FDIC Chair Sheila Bair, according to a congressio­nal report. It cites a May 2013 memo from the FDIC inspector general to Gruenberg, describing an “advanced persistent threat” said to have come from the Chinese government.

 ?? Bloomberg file ?? FDIC Chairman Martin Gruenberg says the rule may apply to “nonbank financial companies.”
Bloomberg file FDIC Chairman Martin Gruenberg says the rule may apply to “nonbank financial companies.”

Newspapers in English

Newspapers from United States