BPI Urges Tighter Safeguards for Regulatory Data Sharing
U.S. banks routinely provide regulators with strategic plans, capital data, trading records and cybersecurity details during examinations, often through regulator-run portals or encrypted email. The Bank Policy Institute says each transfer creates another copy outside a firm’s security perimeter, limiting its control over access, retention and deletion. The issue gained urgency after cyber incidents were discovered at the U.S. Treasury Department in December 2024 and the Office of the Comptroller of the Currency in February 2025, prompting a reassessment of supervisory data handling.
The Federal Reserve, Federal Deposit Insurance Corp. and OCC issued a joint statement on July 16, 2026, outlining coordinated treatment of highly sensitive examination information. BPI followed on July 23 with a risk-based framework urging fewer direct electronic transfers and greater use of firm-hosted applications, screen sharing and on-site reviews. For especially sensitive material, including pre-deal M&A information, it recommended oral briefings, summaries or narrower examiner access. If transfer is unavoidable, the parties should document storage, authorized users, safeguards, retention, onward sharing and disposal.
All Coverage
1 original reportsThe Backstory
The history behind this eventU.S. Financial Regulators Tighten Safeguards for Banks' Sensitive Data
The Federal Reserve, Federal Deposit Insurance Corporation and Office of the Comptroller of the Currency collect vast amounts of sensitive data while examining U.S. banks that collectively hold trillions of dollars in assets. As cyberthreats targeting the financial system have intensified in recent years, a breach of regulators' databases could jeopardize financial stability. Strengthening the protection and management of confidential examination data has therefore become a central issue in safeguarding U.S. financial cybersecurity.
The Fed, FDIC and OCC announced on July 16, 2026, that they would notify banks within 72 hours if their own data were compromised, but did not codify the commitment in formal regulations. The move met only 50% of the banking industry's requests. By contrast, current rules require banks to report cybersecurity incidents to regulators within 36 hours, leaving a gap between the two standards.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.