logo

Financial institutions ordered to notify customers after a breach, have an incident response plan

ID: c92917bd-e5e6-5691-b165-7054db652403

STIX ID: report--c92917bd-e5e6-5691-b165-7054db652403

Feed Name: Malwarebytes Blog

Date Published: 2024-05-20

Date Updated: 2026-04-28

...
...

The SEC adopted amendments to Regulation S-P requiring registered broker-dealers, investment companies, advisers, and transfer agents to maintain written incident response policies and to notify customers within 30 days of discovering a breach involving customer information; notices must include incident details, data affected, and steps customers can take. The rule takes effect 60 days after Federal Register publication, with 18 months for larger entities and 24 months for smaller ones to comply, aiming to strengthen protection of consumer financial data amid rising identity theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.