What Happened
The Federal Reserve Board, FDIC, and OCC recently issued a joint statement on handling banks' sensitive examination records. They introduced two changes: examiners may leave highly sensitive materials on bank systems instead of copying them, and the agencies promise to notify banks within 72 hours if confidential supervisory information is compromised.
However, this promise isn't enforceable. Banks can't sue to compel the 72-hour notification; it relies on regulatory goodwill. This follows the OCC's email breach from 2023-2025, where intruders accessed about 148,000 emails over 18 months. The OCC discovered the breach on February 11, 2025, but didn't notify banks until April 2025.
Timeline
May 2023: Unauthorized access to OCC email systems begins.
February 11, 2025: OCC detects unusual administrative account activity.
February 12, 2025: OCC confirms unauthorized activity.
February 26, 2025: OCC issues a public notice claiming "no indication of any impact to the financial sector."
April 7, 2025: OCC reclassifies the incident as major.
April 8, 2025: OCC discloses to Congress that the breach included "highly sensitive information" about regulated institutions.
April 14, 2025: Acting Comptroller Rodney E. Hood writes to bank executives acknowledging uncertainty about what data was taken.
June 2024: Trade groups request secure handling commitments and a 72-hour notification standard.
January 2025: Agencies issue a joint statement with a 72-hour promise and unenforceable disclaimer.
Which Controls Failed or Were Missing
The OCC breach revealed three critical control failures:
Detection lag: It took 18 months to identify unauthorized access. Your email security should flag abnormal behavior within hours. If you're relying on periodic reviews, you're at risk.
Scope determination: Two months passed before determining which banks were affected. The 72-hour clock starts once the agency believes a compromise occurred and determines the affected banks. This gap should be addressed in your incident response procedures.
Notification delay: Banks learned about the breach through public disclosure, not direct notification. This delay shows the risk when notification obligations lack enforcement.
The statement doesn't address these technical failures. It offers a promise without changing the infrastructure or response capabilities that allowed the breach.
What the Relevant Standard Requires
Banks must follow the 2021 computer-security incident notification rule, notifying regulators within 36 hours of a serious incident. "Serious" means the incident threatens your viability, customer account access, or financial sector stability.
This 36-hour requirement is codified in federal regulation. The agencies' 72-hour promise is in guidance that creates no enforceable rights. You can't sue if the deadline passes.
The asymmetry is clear: You have a binding 36-hour requirement, while regulators have an unenforceable 72-hour promise.
Lessons and Action Items for Your Team
Map what qualifies as "highly sensitive" before the next exam. You're responsible for flagging sensitive materials. Prepare your list now: network diagrams, penetration test results, IT control weaknesses, succession plans.
Document your flagging rationale. Be ready to explain why material is highly sensitive. Your rationale should tie to potential harm if compromised.
Understand that "consider" means discretion. Examiners may choose to read documents on your systems or accept redacted versions. This is at their discretion, not your right.
Don't adjust your breach notification procedures based on the 72-hour promise. Your 36-hour obligation remains binding. Plan your incident response timeline around your obligations, not regulatory promises.
Recognize the trust-dependence. Trust is crucial for banking supervision. The statement asks for trust without enforcement. The OCC breach timeline shows why skepticism is reasonable.
Treat the 72-hour trigger ambiguity as a planning constraint. The clock starts when the agency "has a reasonable basis to believe a compromise has occurred and determines the banks affected." These are agency determinations you can't control.
The statement offers a 72-hour promise and the option to flag sensitive materials, but not enforceable standards. Adjust your expectations accordingly.



