The Securities Exchange Commission has proposed stricter regulations on how financial institutions deal with data breaches as cyberattacks climb.
The SEC proposed amendments to its “Privacy of Consumer Financial Information and Safeguarding Customer Information” regulation, implemented in 2000, according to a May 15 fact sheet from the commission.

The federal watchdog is looking to implement the following updates, according to the fact sheet:
- Time allotted to inform customers: FIs must inform customers within 30 days of data breach. Before the update, “there was no explicit federal time limit set by the SEC for such notifications,” Amer Deeba, chief executive and co-founder at cyber security company Normalyze, told Bank Automation News.
- Incident response program: FIs must have an incident response program in place to deal with detection, response and recovery of consumer data from data breaches.
“Over the last 24 years, the nature, scale and impact of data breaches has transformed substantially,” SEC Chair Gary Gensler said in a May 16 release. These amendments will “help protect the privacy of customers’ financial data. The basic idea for covered firms is if you’ve got a breach, then you’ve got to notify.”
Pervasive threat of breaches
Some 52% of companies globally have experienced data breaches while 48% have experienced cyber extortion and 45% have experienced ransomware attacks, according to a January report by cybersecurity company Splunk.
Splunk conducted a survey of 1,650 security executives in December 2023 and January 2024 in countries including the United States, Australia, France, Japan and the United Kingdom.
Financial institutions, including brokerage firms, investment companies and insurance companies, will also have to comply with the updated SEC rules, according to the release.
The proposed regulations will take effect 60 days from the ruling proposal date, according to the release. Large FIs must comply within 18 months to comply while smaller FIs will have 24 months.
Since the start of 2024, multiple major financial institutions have experienced data breaches:
- Santander Bank suffered a data breach at a third-party vendor last week, according to the bank’s May 14 release;
- American Express notified cardholders in March that their personal information may have been compromised due to a merchant processor being hacked, according to the card giant’s Feb. 27 notice filed with the Massachusetts Office of Consumer Affairs and Business Regulation; and
- Infosys McCamish, a data service provider for Bank of America, reported it was hacked in October, leading to a data breach at the $2.4 trillion bank.





