LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label Disaster Recovery. Show all posts
Showing posts with label Disaster Recovery. Show all posts

Wednesday, July 2, 2025

Safeguards Rule: Information Security Program

QUESTION 

We are a mortgage broker in the Midwest. In our last state audit, the examiner told us that we did not comply with the Safeguards Rule. It's my understanding that it's required by the GLBA, which behooves us to have an information security program. 

Well, we have one! Never had a problem before with it, yet now we've got an examiner saying that our information security plan is no good. I got it from a reputable manual company – at least I thought they were reputable until the banking department told me it was not in compliance. 

Now we've got to figure out what this Safeguards Rule is all about! I hope you can enlighten me. My office manager tried to find something on it, but it reads like a bunch of legal mumbo-jumbo. And, anyway, I don't know how to change the information security plan. I will contact your company to get help. Here's my question!

What does the Safeguards Rule cover? 

SOLUTION 

PRIVACY TUNE-UP®

INFORMATION SECURITY PLAN 

PRIVACY POLICY

RESPONSE 

Thanks for writing me. I will try to get you past the legalese. I'll provide citations in case you or your office manager wants them. That said, you can contact me and we'll get you back on track! 

Keep in mind that regularly assessing the Information Security Program, Plan, or Policy (ISP) is a function of the Second Line of Defense. A self-assessment or self-evaluation should be conducted at least once a year. If you have not already done so, you should conduct a risk assessment immediately. Alternatively, you can contact us for our Privacy Tune-up®, an audit that meets regulatory scrutiny. Or ask for our comprehensive Information Security Plan or the Privacy Policy.

The Federal Trade Commission's (FTC) Safeguards Rule, implemented under the Gramm-Leach-Bliley Act (GLBA), requires financial institutions to establish and maintain a comprehensive Information Security Program (ISP) to protect customer data. This includes developing written security plans with administrative, technical, and physical safeguards. The rule requires financial institutions to safeguard customer information against threats and unauthorized access. 

A few years ago, a mortgage broker contacted us to find out if her company was required to comply with the GLBA. The short answer is yes, indeed. A wide range of financial institutions is covered. A "financial institution,"[i] for our purposes, means an entity that provides real estate settlement services (because providing real estate settlement services is a financial activity)[ii], and the statute specifically denotes a mortgage broker as a financial institution.[iii] 

I'll get to your compliance responsibilities shortly. But first, you need to know what constitutes the Safeguards Rule ("Rule"). If your ISP does not have these key components textualized in some way, an examiner may find it defective. 

Five Key Components 

There are five Safeguards, as follows: 

1. Administrative Safeguards 

These involve policies and procedures for managing and overseeing the information security program. 

2. Technical Safeguards 

These include measures like firewalls, encryption, and access controls to protect data. 

3. Physical Safeguards 

These involve physical security measures to protect data storage locations and access to sensitive information. 

4. Oversight of Affiliates and Service Providers 

The Rule also mandates that financial institutions ensure their affiliates and service providers safeguard customer information.

Thursday, May 2, 2024

Business Continuity Plan: Insufficient Recovery

QUESTION 

According to the bank examiner, our Business Continuity Plan does not provide “sufficient recovery and resolution planning requirements” to manage stresses caused by system failures during a disaster. The problem is that they did not give us guidelines to determine what constitutes sufficient recovery procedures. 

As a result, I am not sure we will satisfy their expectations. I have had our compliance department and lawyers come up with an outline of procedures, but they keep giving me scenarios, and I am not convinced that just listing scenarios is the way to go. I am our company’s founder and president. I will tell you we have never had a catastrophic system failure caused by a disaster. That’s not to say it can’t happen. And I get it! We need to be ready at all times. 

But I don’t want to go out with only scenarios. I am concerned that this approach is not comprehensive, and, more to the point, I think it will annoy the examiner. I need something that the whole company can integrate into operations. 

I hope you can provide a management approach I can implement in all our departments and divisions. Each department will then work to comply with management’s requirements. I will ask our compliance people to ensure companywide oversight of those requirements. 

What are some steps, an outline, toward managing business continuity during disasters? 

COMPLIANCE SOLUTION 

Business Continuity and Disaster Recovery Plan 

BCP Tune-up

ANSWER 

A credible Business Continuity Plan[i] must consider market and companywide stresses and idiosyncratic risks that can imperil the continuity of a financial institution’s critical operations and core business lines. Indeed, proper planning can reduce the adverse broader impact on the financial system. 

With our BCP Tune-up, we have reviewed the Business Continuity Plans of many companies, So, I believe we have a unique perspective on regulatory expectations. Many clients use the BCP Tune-up as a self-assessment tool. Self-assessment is an essential Best Practice encouraged by most banking departments. Our review is cost-effective and we provide a report that describes current risks as well as recommendations that help to meet regulatory scrutiny.

Business continuity is inherently linked to disaster recovery. Your company must develop the ability to prepare for, adapt to, and withstand or recover from disruptions. Disruptions may result from external events like natural disasters, malicious actors, pandemics, global conflicts, or weak internal systems, controls, or risk management. Adapting is essential. For instance, we revised our Business Continuity Plan during the pandemic to add an entire section for Pandemic and Epidemic Response. 

Obviously, disruptions may impede the provision of services, such as payments and clearing and settlement, or adversely impact systems or corrupt data. 

However, the current focus of many banking departments is on exploring baseline “operational resilience” requirements with respect to critical operations, including third-party service providers. 

Such baseline requirements often include the following: 

·       Establishing clear definitions for identifying critical activities and core business lines. 

·       Defining tolerances for disruption, such as caused by cyber-attacks.[ii] 

·       Requiring testing and validation of “resilience” capabilities. 

·       Incorporating third-party risk management expectations.[iii] 

·       Stipulating clear communication expectations among stakeholders and counterparties. 

·       Addressing expectations for critical service providers, emphasizing governance and risk management expectations. 

A company subject to recovery or resolution planning requirements can leverage the information I’m providing in an outline form. You can send it to your departments and divisions for feedback and implementation. In my view, the outline conforms to existing regulations and guidance, the results of which should promote sound business continuity management.[iv] 

In your question, you mentioned the term “recovery” was used by the bank examiner. I use that term, in accordance with regulatory guidance, to refer to the restoration of clearing and settlement activities after a wide-scale disruption. I use the term “resumption” to refer to the capacity to accept and process new transactions and payments after a wide-scale disruption.[v] 

I make no claim that the following nine practices are comprehensive. However, the outline may be considered “sufficient” for deriving an overall plan for business continuity and disaster recovery. 

Business Continuity Management 

1)    Business Impact Analysis 

The company’s business continuity management incorporates business impact analysis,[vi] testing, training, awareness programs, and communication and crisis management policies. 

2)    Contingency 

The company periodically reviews its business continuity plan to ensure contingency strategies remain consistent with current operations, risks and threats, its tolerance for disruption, and recovery priorities.[vii] Containment strategies must align with existing guidance for a company that performs payment, clearing, and settlement activities in critical financial markets.[viii] 

3)    Testing 

The company tests business continuity plans, reviews the execution of tests, and improves plans by incorporating lessons learned. Business continuity tests and exercises incorporate dependencies of critical operations and core business lines on third parties. The company participates in disaster recovery and business continuity testing with third parties associated with critical operations and core business lines. 

4)    Scenarios 

The company confirms that functional testing procedures for assessing the ability of a company’s IT systems to deliver minimum service capacity to critical operations and core business lines are consistent with its business continuity objectives. Business continuity management incorporates scenarios where service capacity and business continuity objectives cannot be met. 

5)    Personnel 

The company identifies and manages the availability of personnel essential to executing its critical operations and core business lines.[ix] The company has (an) alternate site(s) that has sufficient resources (including personnel), technology capabilities, and functionality to execute the company’s critical operations and core business lines in the event of a disruption.[x] The alternate site(s) is (are) located at a sufficient geographical distance from the primary site and has (have) a distinct risk profile. 

6)    Remote Access 

Business continuity management includes remote access contingencies that allow personnel to continue delivering the company’s critical operations and core business lines during the disrupting event.[xi] The management of contingencies prioritizes critical operations and core business lines and provides personnel with adequate connectivity, communication, collaboration tools, essential technology resources, and access to network systems. These contingencies incorporate transitioning personnel back to normal operations following the resolution of a disruption.[xii] 

7)    Training 

The company trains essential personnel responsible for executing critical operations and core business lines and performing backup roles should a disruption occur. The company implements an operational resilience training and awareness program to evaluate the effectiveness of personnel-related business continuity arrangements, and the program is continually improved as shortcomings are identified. 

8)    Implementation 

The company’s recovery or resolution planning is integrated into its governance and operating processes and is part of business-as-usual activities, including companywide risk management processes. To ensure sufficient implementation, recovery or resolution planning is understood as complementary to, and linked with, existing risk management and business continuity management processes. 

9)    Interconnections 

The company harvests and leverages information in its recovery or resolution plans to identify options to respond to a wide range of severe but plausible internal and external stress scenarios. The company similarly leverages the identification of interconnections and interdependencies among critical operations and core business lines affiliates, subsidiaries, and third parties. 

While sound practices prioritize business continuity and disaster recovery of critical operations and core business lines of a financial institution and its material entities,[xiii] it also should identify and address the resilience of other operations, services, and functions for which a disrupting event could have a significant adverse impact on the company or its customers.

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group
_______________________________

[i] For more information, consider the Federal Financial Institutions Examination Council (FFIEC) Information Technology Examination Handbook, which includes the booklet Business Continuity Management (November 2019). This booklet describes principles and practices for IT and operations to ensure safety and soundness, consumer financial protection, and compliance with applicable laws and regulations.
[ii] In 2021, the federal banking agencies adopted the Computer-Security Incident Notification Rule to bolster cyber defenses.
[iii] The federal banking agencies have issued interagency guidance on third-party risk management, building off of the Office of the Comptroller of the Currency’s (OCC) longstanding guidance on the topic.
[iv] Guidance includes SR letter 03-9 and OCC Bulletin 2003-14 Interagency White Paper on Sound Practices to Strengthen the Resilience of the U.S. Financial System (April 8, 2003), which outline practices for geographic diversity and resiliency of data centers and operations, as well as recovery and resumption time objectives and related testing standards for firms that perform payment, clearing, and settlement activities in critical financial markets.
[v] Idem
[vi] Op. cit. i, Section III.A. Business Impact Analysis of the FFIEC Information Technology Examination Handbook booklet Business Continuity Management describes the business impact analysis process.
[vii] Ibid, Section II.A. Board and Senior Management Responsibilities
[viii] Op. cit. iv
[ix] Op. cit. i, Section IV.A.4 Personnel
[x] Op. cit. i, Section V.C Facilities and Infrastructure
[xi] Operational risk management and independent internal (or external) audit functions should also consider remote access and any other related conditions.
[xii] Op. cit. ix
[xiii] For purposes of this article, I define a material entity as one that is significant to the activities of an identified critical operation or core business line or is financially or operationally significant to the company's recovery from a disrupting event.

Thursday, August 31, 2023

Mitigating Cyberattacks

QUESTION 

Well, it finally happened! We were hit with a cyberattack. We’re a small bank but have handled our cybersecurity carefully and passed safety and soundness exams. Yet, we were attacked. It seems nobody is safe! 

We don’t know where the attack came from, but a new computer consultant thinks our cybersecurity will need to be improved. She is especially concerned about internal threats by employees who do not follow our system rules. 

We would like you to suggest the types of proactive measures we should take to protect ourselves from cyberattacks. 

In what ways can we mitigate cyberattacks? 

ANSWER 

Your organization must be vigilant in protecting your data and operations from all threats, including ransomware, phishing, social engineering leading to business email compromises, and distributed denial-of-service (DDoS) attacks. The attacks include incidents directly related to critical vulnerabilities. 

All financial institutions and associated entities should take immediate and comprehensive action to protect their systems, sensitive data, and the financial well-being of their members. 

I will recommend certain primary mitigation steps and best practices. Monitoring, testing, and training must be ongoing to safeguard against evolving cyber threats. 

Here are nine proactive measures you can take to mitigate cyber threats. 

MITIGATING CYBER THREATS

1. Multifactor authentication 

Implement multifactor authentication for all sensitive accounts and systems, including email accounts and remote access portals. This measure adds an extra layer of protection against unauthorized access and phishing attempts. 

2. Employee cybersecurity awareness training 

Conduct regular cybersecurity training for all employees to raise awareness about phishing, social engineering, and other common attacks. Educate employees about the risks and implications of clicking suspicious links or opening malicious attachments. 

3. Email security and anti-phishing measures 

Deploy advanced email security solutions with phishing detection and blocking capabilities. Here are a few that come to mind: Slender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Authentication, Reporting, and Conformance (DMARC) protocols to prevent email spoofing and enhance email authenticity. If you’re unfamiliar with these terms, speak to your consultant about them. 

4. Incident response plan 

Develop and regularly test an incident response plan to ensure a swift and coordinated response in the event of a cyberattack. Assign specific roles and responsibilities to designated personnel and rehearse various attack scenarios. Be sure to have a robust Disaster Recovery and Business Continuity Plan. Also, establish a Crisis Command Structure. 

Learn about our Disaster Recovery and Business Continuity Plan. 

 5. Vendor risk management 

Review and assess the cybersecurity practices of all third-party vendors that provide financial services and products. Verify that vendors use sound risk management principles, have robust security measures, and regularly review their security posture. 

6. Network segmentation and DDoS protection 

Implement network segmentation to contain the impact of a potential compromise. Deploy DDoS protection measures, such as traffic filtering and rate limiting, to defend against DDoS attacks. Speak to your consultant about how best to implement this process. 

7. Regular data backups and recovery testing 

Maintain frequent data backups and test the data recovery process regularly. In a ransomware attack, backups can prevent data loss and reduce the need to pay the ransom. 

8. Threat intelligence sharing 

Participate in threat intelligence-sharing communities to stay informed about emerging threats and attack trends. Sharing information can help strengthen the industry’s collective defense. 

9. Continuous monitoring and security updates 

Monitor network traffic, logs, and systems continuously to detect and respond promptly to suspicious activities. Stay informed about the latest security updates and apply patches promptly. 

Proactive cybersecurity measures safeguard systems and data integrity and confidentiality. Consider adopting these mitigation steps and best practices, as they can enhance your security posture and protect against cyberattacks.

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group

Thursday, May 4, 2023

Data Breach – An Unprepared Company

QUESTION 

We were just hit with a data breach and were completely unprepared for it. Hackers took personal information from our corporate server. We believe that customer information was stolen. The hacker also went after our website, meaning information there may be exposed. 

Our Business Continuity policy is all of two pages. We put it together by pasting it from a few Google searches. You may think we are a small mortgage lender, but we have branches in eight states and originate a large volume of mortgage loans. 

We have already alerted law enforcement. We are working on a quick plan to notify investors and customers. But we have no process to follow for this data breach. We're working without a guide. 

All of us in management know you have written a lot about issues like ours. Please help as soon as possible. 

What should we do immediately if we are hacked? 

ANSWER 

NOTE: This article provides links to subject articles, presentations, and a complimentary Data Breach: Quick Reference Checklist. 

As many of you know, I am like a Mother Hen regarding our clients, always looking to protect them. And through these weekly newsletters, I try to ensure our readers are made aware of regulatory compliance challenges. However, some readers ignore my advice, one of which is the importance of having a policy for Business Continuity. 

Our Business Continuity plan is comprehensive. We believe it meets regulatory scrutiny; however, I don't care if you want ours or another firm's policy. Assuming the policy is reliable, get it and implement it! If you are not operating with a plan, your company is unprepared for a data breach. Also consider our mini-audit, BCP Tune-up, which provides a review of your Business Continuity plan and procedures.

For information about our Business Continuity Plan, click HERE.

For information about our BCP Tune-up, click HERE.

Here are just some articles I have published on Business Continuity: 

·       Disaster Recovery and Business Continuity

·       Cybersecurity Rule – Proposed Updates

·       Ransomware Payments

·       Prohibited Acts and Practices

·       Large Bank Cybersecurity Challenges

·       UDAAP Violations caused by Insufficient Data Protection

·       Mother of All Computer Bugs

·       Phishing Scams

·       Intrusion Detection Terms 

As Falstaff said, "Better three hours too soon than a minute too late." 

Don't delay. Procrastinate at your peril! 

Let's turn to the situation you find yourself in, to wit, a data breach and no plan for Business Continuity, which should include a Disaster Recovery component. 

If your company experiences a data breach, you should notify law enforcement, other affected businesses, and individuals. Since I do not know your company's size, complexity, or risk profile, my remarks are necessarily generic. 

However, I will provide a bulleted outline so you can act promptly. 

Request the complimentary Data Breach: Quick Reference Checklist. 

Evidence

·       Do not destroy evidence.

·       Don't destroy any forensic evidence in the course of your investigation and remediation.

·       Document your investigation. 

Immediate Response

·       Secure physical areas potentially related to the breach. Lock them and change access codes.

·       Mobilize your breach response team right away to prevent additional data loss. The exact steps to take depend on the nature of the breach and the structure of your business.

·       Assemble a team of experts to conduct a comprehensive breach response. Depending on the size and complexity of your company, they may include forensics, legal, information security, information technology, operations, human resources, communications, investor relations, and management.

·       Identify a data forensics team. Consider hiring independent forensic investigators to help you determine the source and scope of the breach. They will capture forensic images of affected systems, collect and analyze evidence, and outline remediation steps.

·       Consult with legal counsel. You may consider hiring counsel with privacy and data security expertise. They can advise you on federal and state laws that a breach may implicate. 

Stop Data Loss

·       Take all affected equipment offline immediately — but don't turn any machines off until the forensic experts arrive.

·       Closely monitor all entry and exit points, especially those involved in the breach.

·       If possible, put clean machines online in place of affected ones.

·       Update credentials and passwords of authorized users. If a hacker stole credentials, your system will remain vulnerable until you change those credentials, even if you've removed the hacker's tools. 

Remove Web Vulnerability

·       Your website – If the data breach involved personal information improperly posted on your website, immediately remove it. Be aware that internet search engines store, or "cache," information for some time. You can contact the search engines to ensure that they don't archive personal information posted in error.

·       Other websites – Search for your company's exposed data to ensure no other websites have saved a copy. If you find any, contact those sites and ask them to remove it. This applies to websites operated by your company's loan officers and agents. 

Interviews

·       People who discovered the breach should be interviewed.

·       Talk with anyone else who may know about it. 

·       If you have a customer service center, ensure the staff knows where to forward information that may aid your investigation of the breach. 

Service Providers

·       If service providers were involved, examine what personal information they can access and decide if you need to change their access privileges.

·       Ensure your service providers take the necessary steps to ensure another breach does not occur.

·       If your service providers say they have remedied vulnerabilities, verify that they fixed things.

Thursday, September 22, 2022

Cybersecurity Rule – Proposed Updates

QUESTION

Our Cybersecurity Policy is a good one. I know this because we have had an examination, and the regulator approved it. 

Although we are a mid-west company, I notice that New York requires an update to its cybersecurity rule. That makes me nervous since New York’s cybersecurity requirements influence many states. 

I want to update our Cybersecurity Policy to reflect New York’s requirements. Sooner or later (probably sooner), our state is going to adopt the same requirements. 

What are the new Cybersecurity Policy requirements in New York? 

ANSWER

New York’s Department of Financial Services (DFS) has been quite active in requiring its licensees to comply with its Cybersecurity Rule (“Rule”). Effective March 1, 2017, the DFS promulgated a regulation[i] implementing the Rule. 

I published a White Paper about the Rule in advance of its effective compliance date, entitled 

Cybersecurity Guidelines – "First-in-the-Nation" Regulation. 

You’re welcome to download it HERE. 

From its inception, the DFS requires individuals and entities to comply with the Rule. These are called “Covered Entities.” A Covered Entities include, but are not limited to, partnerships, corporations, branches, agencies, and associations operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation, or similar authorization under the banking law, the insurance law, or the financial services law. 

I agree that the DFS influences other state banking departments vis-à-vis cybersecurity regulations. Now, the DFS is proposing to update the Rule.[ii] So, it’s a good time to anticipate policy and procedure revisions. Even if the proposed Amendments (“Amendments”) are not adopted in full or at all, given the rapidly evolving cyber threat landscape and, in particular, the growing prevalence of ransomware incidents, many aspects of the Amendments reflect Best Practices. 

Some of the proposed changes are rather significant. For instance, the updated Rule will have such requirements as a mandatory 24-hour notification for cyber ransom payments, heightened cyber expertise requirements for board members, and new access restrictions to privileged accounts. 

I will provide a brief summary of the proposed updates. Covered entities should monitor whether the DFS formally proposes amendments to ensure they are equipped technically, organizationally, and financially to meet the heightened governance, technical, and notification obligations. 

Notification Obligations 

The Amendments will create new requirements to notify the DFS of certain incidents. Specifically, there will be a requirement to notify the DFS within 72 hours of any unauthorized access to privileged accounts or deployment of ransomware within a material part of the covered entity’s information systems. 

Furthermore, covered entities will be required to notify the DFS within 24 hours of a covered financial institution making a ransomware payment connected to a cybersecurity event; additionally, there will be a requirement to provide the DFS within 30 days with an explanation of (a) why the payment was necessary, (b) whether alternatives were considered, and (c) what sanctions diligence was conducted. 

Risk Assessments 

There are risk assessment requirements under the current Cybersecurity Rule. Under the Rule, a covered entity must conduct a periodic risk assessment of its information systems “sufficient to inform the design of” its cybersecurity program required by the Rule and must update the risk assessment to address various changes, developments, and threats. The Amendments will expand upon the Rule’s definition of a “Risk Assessment” and more clearly articulate that an assessment must “take into account the specific circumstances of the covered entity.” And the Amendments also would clarify that a covered entity’s risk assessment must be updated at least annually or whenever a change in business or technology “causes a material change to the covered entity’s cyber risk.” 

Heightened Monitoring 

The Amendments will add several new monitoring requirements to the Rule, including:

 

·     Completion of an asset inventory that tracks information (e.g., owner, location, classification or sensitivity, support expiration date, and recovery time requirements) for each technology asset (e.g., hardware, operating systems, applications, infrastructure devices, APIs, and cloud services), and requirements for updating and validating the asset inventory;

 

·     Heightened access controls for privileged accounts, such as limiting access to a need-to-know basis, implementing multifactor authentication, and securely configuring or disabling protocols that permit remote control of devices;

 

·     Regular phishing training and exercises for all personnel; and

 

·     Monitoring and filtering of emails to block malicious content.

Governance 

Governance will be updated in the Amendments to include new obligations, including:

 

·     CISO independence and authority to ensure that cyber risks are appropriately managed;

 

·     Additional CISO reporting obligations to the board of directors  include plans for remediating inadequacies and timely reporting on material cybersecurity issues or major cybersecurity events (which are not defined);

 

·     Expertise and knowledge thresholds for board members (or requirements that persons with such expertise and knowledge advise them) such that they can exercise effective oversight of cyber risk;

 

·     Cybersecurity policy approval by the board (i.e., not senior management);

 

·     Annual certification of compliance with the Cybersecurity Rule by CEO and CISO, as differentiated from a senior officer;

 

·     Required business continuity and disaster recovery (“BCDR”) plans, which would be necessary to include certain prescribed content, such as identification of essential data, personnel, and infrastructure, a communications plan in the event of a disruption, and procedures for the maintenance of backup infrastructure;

 

·     Periodic testing of incident response and BCDR plans, and ability to restore systems from backups, including to address ransomware incidents and the ability to recover from backups; and

 

·     Annual review by CISO of the feasibility of encryption and effectiveness of the compensating controls, as well as a requirement to implement a written policy requiring industry-standard encryption to protect nonpublic information held at rest or transmitted over external networks by the covered entity. 

Larger (Class A) Companies 

The Amendments will impose additional cybersecurity obligations on a new category of covered entities, so-called “Class A Companies.” Under the Amendments, a “Class A Company” would be a covered entity with: (1) over 2,000 employees; or (2) over $1 billion in gross annual revenues averaged over the last three years from all of its business operations and those of its affiliates.  

These Class A Companies would be subject to additional cybersecurity obligations, including: 

·     Annual independent audits of the company’s cybersecurity program; 

·     Weekly vulnerability assessments will be conducted, including systematic vulnerability scans and reviews of information systems, and documentation and reporting to the board and senior management of material gaps identified by these assessments; 

·     Password controls, including a “vaulting solution” for privileged accounts and an automated method for blocking commonly used passwords; 

·     Monitor anomalous activity by way of endpoint detection and response solution, with a centralized solution for logging and security event alerting; and 

·     Risk assessments by external experts at least once every three years. 

Even if a covered entity is not a large company, smaller companies should consider implementing at least some of the Class A obligations.


Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director 
Lenders Compliance Group


[i] 23 NYCRR Part 500

[ii] Announced by the DFS on July 29, 2022

Thursday, September 1, 2022

UDAAP Violations caused by Insufficient Data Protection

QUESTION

Last year, we were criticized by our regulator for not “safeguarding consumer data.” We revamped our policies and procedures for several weeks, hired an IT company, did penetration testing, and even hired a law firm to check our system. They brought in a firm such as yours to do an overview of our policies. So, we thought we covered all the bases. 

We have just received a letter from the regulator. They are requesting an on-site visit soon. This was expected. But as we got ready for the examination, we learned that the CFPB is going after consumer protection violations, such as connecting to UDAAP violations. 

Since we covered everything – or thought we did! – it would be great if you could fill in any possible blanks to prepare for the coming examination. 

What important actions can we take to double-check our consumer data security? 

ANSWER

Safeguarding consumer data requires constant vigilance. Some companies dwell on the digital aspects, but that is certainly not enough, nor is it so narrowly adduced. I think your question is best understood in the context of insufficient data protection because insufficient data protection may indeed lead to UDAAP violations. 

The nexus to UDAAP violations is likely what the CFPB has in mind concerning safeguarding sensitive consumer information.[i] While the prohibitions in UDAAP are fact-specific, failure to implement common data security practices will significantly increase the likelihood that a firm may be violating UDAAP. 

The CFPB issuance you mention is meant to increase the focus on potential misuse and abuse of personal financial data. As part of this effort, the CFPB is explaining how and when firms may be violating the Consumer Financial Protection Act (CFPA) with respect to data security. Specifically, financial companies are at risk of violating the CFPA if they fail to have adequate measures to protect against data security incidents. 

I am going to describe the CFPB’s view of conduct that typically meets the first two elements of a UDAAP claim, that is, (1) the likeliness to cause substantial injury to consumers and (2) that it is not reasonably avoidable by consumers, which then increases the risk that an entity’s conduct triggers liability under the CFPA’s prohibition of unfair practices. 

To put this in stark, declarative terms: 

Inadequate data security can be an unfair practice in the absence of a breach or intrusion.[ii] 

Note that the linkage to UDAAP does not only involve inadequate data security, but also it pertains even in the absence of a breach or intrusion. How did we get here? 

Past data security incidents did it! For instance, the 2017 Equifax data breach led to the harvesting of sensitive personal data of hundreds of millions of Americans. In some cases, these incidents violated the CFPA and other laws. In the case of Equifax, the CFPB alleged that Equifax violated the CFPA’s prohibition on unfair acts or practices.[iii] The Federal Trade Commission (FTC) also alleged that Equifax violated the FTC Act and the FTC’s Safeguards Rule, which implements Section 501 of the Gramm-Leach-Bliley Act (GLBA) and establishes certain requirements that nonbank financial institutions must adhere to for the protection of financial information.[iv] 

Providers of consumer financial services are subject to specific requirements to protect consumer data. 

Safeguards 

In 2021, the FTC updated its Safeguards Rule, implementing section 501(b) of the GLBA to set forth specific criteria relating to the safeguards that certain nonbank financial institutions must implement as a part of their information security programs. 

Among other things, these safeguards include: 

·     Limiting who can access customer information. 

·     Require the use of encryption to secure such information. 

·     Require the designation of a single qualified individual to oversee an institution’s information security program, who reports at least annually to the institution’s board of directors or equivalent governing body. 

The federal banking agencies also have issued interagency guidelines to implement section 501 of the GLBA. 

Failure to comply with these requirements may violate the CFPA’s prohibition on unfair acts or practices in certain circumstances. 

Here’s a Rule of Thumb for defining an unfair act or practice: it is an act or practice 

·       That causes or is likely to cause substantial injury to consumers, 

·       Which is not reasonably avoidable by consumers, and 

·       Is not outweighed by countervailing benefits to consumers or competition.

Turning to insufficient data protection, there are at least three safeguards you can implement that may serve to overcome allegations of not sufficiently protecting sensitive consumer data. I will discuss them briefly here. However, your policies and procedures must require them, and you must test their implementation regularly. 

Safeguard Number One: Multi-Factor Authentication 

Multi-factor authentication (MFA) is a security enhancement that requires multiple credentials (factors) before an account can be accessed. There are three satisfactory types of MFA: 

1.       Something you know, like a password. 

2.       Something you have, like a token. 

3.       Something you are, like your fingerprint. 

Many of our clients use a common MFA setup that supplies both a password and a temporary numeric code to log in. Another MFA factor is the use of hardware identification devices. There are levels of security. MFA greatly increases the level of difficulty for adversaries to compromise enterprise user accounts and thus gain access to sensitive customer data. MFA solutions that protect against credential phishing – like using the web authentication standard supported by web browsers – are especially important.