2026-06-17

Added · Updated

Reporting of Technological Failures, Data Security Incidents, and Cyber Attacks

This directive requires banking corporations to report significant technological failures, suspected cyber incidents, and data security incidents to the Banking Supervision Department. Initial reporting must occur via telephone within two hours of identification, followed by a written report within eight hours, with daily written updates required until the incident concludes. Banking corporations must appoint a Reporting Officer, establish independent incident investigation procedures, and submit a final investigation report within 45 days of completion or 60 days of identification. The directive also mandates documentation of any decision not to report an incident and applies to banking corporations, specific corporations under Section 11(b)(1), and payment service providers with prudential importance licenses.

Bank of Israel logo

Israel

Bank of Israel

Scan of the document's first page
Share

Get BOI alerts — same-day email on every new publication.

Read the rest free

Lineage: Amended

Reporting of Technological Fail…2020Reporting of Technological Failures and Cyber Events (2020-12-29)Circular No. 2669 dated 2021-09…Circular No. 2669 dated 2021-09-30Circular No. 2680 dated 2021-11…Circular No. 2680 dated 2021-11-24Circular No. 2736 dated 2013-01…Circular No. 2736 dated 2013-01-22Reporting of TechnologicalFailures, Data Security Incid…2026-06-17 · this documentReporting of Technological Failures, Data Security Incidents, and Cyber Attacks (2026-06-17)Amendments to Proper Conduct of…2026Amendments to Proper Conduct of Banking Business Directive No. 366 on Reporting of Technology Failure Incidents, Information Security Incidents, and Cyber Attacks (2026-06-17)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Bank of Israel — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from BOI

We email you every new BOI publication the day it's published.

Topics