Congressional Hearing on FDIC Cybersecurity Breaches
January 1, 2017
Track this bill to get notified when it advances a stage. One tap to stop, anytime.
The Frame
The hearing addresses the security of sensitive consumer banking information and the effectiveness of federal oversight regarding the FDIC's management of data breaches and internal threats.
Potentially affected actors named in the source documents. Mention is not a position.
FDIC
The agency is the subject of the investigation regarding its cybersecurity practices and internal management.
Bank Consumers
Consumers are affected by the security of their banking information held by the FDIC.
Last recorded activity January 1, 2017.
Next step not available in the current record.
Summary
Key Facts
- The FDIC experienced at least eight major data breaches meeting Office of Management and Budget reporting guidelines.
- A September 2015 breach in New York involved a disgruntled employee downloading sensitive 'living wills' (resolution plans) without authorization.
- The Inspector General determined the September 2015 breach required law enforcement involvement.
- The Committee's investigation alleged the FDIC Chief Information Officer created a toxic work environment and retaliated against whistleblowers.
- The Committee report alleges the FDIC deliberately evaded Congressional oversight.
- The Inspector General found that a formal insider threat program could have potentially prevented the 2015 breach.
- The hearing took place on July 14, 2016, in the Rayburn House Office Building.
Frequently Asked Questions
What was the nature of the data breaches at the FDIC?
What were the primary concerns raised by the Committee?
Why It Matters
The hearing addresses the security of sensitive consumer banking information and the effectiveness of federal oversight regarding the FDIC's management of data breaches and internal threats.
News Coverage
Sponsors
Discoveries
Patterns POLISCOPE noticed across the record. These are observations to investigate, not conclusions.
Insider Threat Program Deficiency
The hearing highlights a critical failure to implement a formal insider threat program, which was identified as a preventative measure for data breaches.
Connected Entities
Sources
www.govinfo.gov
Analysis Score
0–100- Significance85How much this matters to a regular citizen
- Controversy80Intensity of disagreement among stakeholders
- Entertainment60Compellingness for a non-policy-wonk reader
- Buzz40Current news / social attention level
Publisher tools