CU Trade Groups—Again—Call For Improved Data Security Standards

cybersecurity

WASHINGTON—In conjunction with yesterday’s data security hearing in the House Financial Services Committee, NAFCU and CUNA, along with four other financial services trade groups, sent the committee a letter calling for improved data security standards in the U.S.

The letter re-emphasized the growing threat to the security of personal financial data, that FIs bear a large share of data breach costs, and that a national data security standard is needed—one that would apply the same standards followed by banks and credit unions to retailers and other companies, as well.

The letter, which was also signed by the American Bankers Association, Independent Community Bankers of America, The Clearing House and the Consumer Bankers Association, urged congressional support for H.R. 2205, the Data Security Act of 2015, introduced by Financial Institutions Subcommittee Chairman Neugebauer (R-TX) and Representative Carney (D-DE).

The trade groups noted that from January 2005 through May 6, 2015, more than 5,000 breaches exposing more than 800-million records have occurred nationwide. Moreover, more than 100- million records were compromised between January and May of 2015 due largely to the Anthem breach in which 78-million records were compromised.

“These numbers point to the central challenge associated with breaches of financial account data or personally identifiable information: while the preponderance of data breaches occur at entities far removed from the banking sector, it is oftentimes the bank’s and credit union’s customer at the end of the line who must be protected,” the letter said.

“It is an unfortunate truth that, in the end (and often well after the breach has occurred and the financial institutions have made customers whole) banks and credit unions generally receive pennies for each dollar of fraud losses and other costs that were incurred by banks in protecting their customers,” the groups continued. “This minuscule level of reimbursement, when taken in concert with the fact that banks and credit unions bear over 60 percent of reported fraud losses yet have accounted for less than 8 percent of reported breaches in the United States since 2005, is clearly inequitable.”

The letter pointed out that according to a 2014 survey conducted by the American Bankers Association among their membership, only 33.1% of the 535 respondents reported having received any reimbursements for breaches between 2009 and 2014.

“Of those, the majority of respondents (83.1% percent) reported a reimbursement rate of no more than 10 cents on the dollar, with 46.2 percent reporting less than 1 cent on the dollar,” the groups stated. “Additionally, according to the Independent Community Bankers of America, recent wide-scale retailer data breaches resulted in community banks reissuing more than 11.5 million debit and credit cards at a cost of more than $130 million. That is why banks and credit unions should be fully reimbursed for the costs they bear for breaches that occur elsewhere.

The letter shared recommendations to improve U.S. data security standards, including:

  • All players in the payments system must improve their internal systems as criminal threats continue to evolve.
  • Protecting the payments system is a shared responsibility, among all players in the payments chain.
  • A national data breach standard is essential.

The letter stated the trade groups’ support for H.R. 2205.

“This important legislation would apply to all industries that handle sensitive information and would provide meaningful and consistent protection for consumers nationwide. H.R. 2205 recognizes that it is not necessary or productive to duplicate data protection and consumer notice requirements that are already in place for financial institutions under the Gramm-Leach-Bliley Act (GLBA) and subsequent regulations. Banks and credit unions already have a system in place that protects sensitive customer information and it makes sense to extend similar safeguards to other industries that handle sensitive information.”

Section: Standard
Word Count: 727
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto.flux5.ccplatform.net/Fresh-Today/CU-Trade-Groups-Again-Call-For-Improved-Data-Security-Standards