Financial institutions must maintain a comprehensive written information security programme appropriate to their size, complexity and the sensitivity of the information held.

Programme elements. Designation of a qualified individual responsible for the programme; a written risk assessment; safeguards addressing access controls, data inventory, encryption of data at rest and in transit, secure development, multi-factor authentication, disposal, change management and activity monitoring; continuous monitoring or annual penetration testing with periodic vulnerability assessments; training; oversight of service providers; a written incident response plan; and an annual report to the board.

Incident notification. Regulators require notification of significant computer security incidents within short periods — as little as thirty-six hours for banking organisations in some regimes — and service providers must notify their institution customers.

State breach notification statutes impose separate obligations to affected individuals and attorneys general, with varying triggers and deadlines.

Vendor obligations. Contracts must require appropriate safeguards, permit assessment, and require incident notification promptly enough to meet the institution’s own deadlines.

Documentation. The programme is judged on evidence — completed risk assessments, test results with remediation tracking, training completion, and board reporting. A well-drafted policy with no evidence of operation is a finding.