2026-06-17
Added
This directive requires banking corporations to report significant technological failures, suspected cyber incidents, and data security incidents to the Banking Supervision Department. Initial reporting must occur via telephone within two hours of identification, followed by a written report within eight hours, with daily written updates required until the incident concludes. Banking corporations must appoint a Reporting Officer, establish independent incident investigation procedures, and submit a final investigation report within 45 days of completion or 60 days of identification. The directive also mandates documentation of any decision not to report an incident and applies to banking corporations, specific corporations under Section 11(b)(1), and payment service providers with prudential importance licenses.
More like this from BOI
We email you every new BOI publication the day it's published.