Trending
A November 2021 data breach has resulted in federal regulatory action against Lake Shore Savings Bank.
The incident was disclosed quietly in March. According to a letter sent to Lake Shore customers in Vermont by the Vermont Attorney General's Office, the bank had a data breach that kept employees from accessing internal systems and information. Bank officials hired a digital forensics team to find out how much information had been accessed and notified the FBI and federal Office of the Comptroller of the Currency. Through March, Lake Shore Savings Bank officials hadn't found any personal information misused.
Earlier this week, however, Lake Shore Savings Bank officials entered into an agreement with the federal Office of the Comptroller of the Currency, which works under the Securities and Exchange Commission. Lake Shore Savings Bank has to create a compliance committee to monitor and oversee the bank's compliance with the Agreement and submit quarterly reports to the bank board and OCC.
The agreement between the bank and office doesn't list specific issues tied to the data breach. But it does require the bank's board to ensure competent management. The bank was given 10 days to form a Compliance Committee that includes at least three board members who are not employees or officers of the bank. Lake Shore Savings has to create a Compliance Committee of at least three board members who are not employees or officers of the bank or its subsidiaries. By Sept. 30, and then every 30 days after, the committee will submit a written progress report setting out in detail a description of the the correction actions to reach complaince, the specific corrective actions undertaken to comply with each article in the agreement and the results and status of the corrective action.
The board will then determine whether management changes should be made.
"Within sixty days of the date of this agreement, and on an ongoing basis thereafter, the board shall ensure that the bank has competent management in place on a permanent and full-time basis, including, but not limited to, in its chief executive officer, chief operating officer, chief technology officer, and information security officer positions, vested with sufficient authority to fulfill the duties and responsibilities of the position, carry out the board's policies, ensure the bank's adherence to corporate governance and decision-making processes, ensure compliance with this Agreement, applicable laws, rules and regulations, and manage the day-to-day operations of the bank in a safe and sound manner within the scope of that position's responsibilities."
Lake Shore Savings Bank currently does not have a chief technology officer, but has a vice president of information technology responsible for technological advancement across the organization, network administration, implementation of new branch locations, roll out of new products and services, purchasing technology equipment, supporting employees, and is the liaison to the bank's core processor vendor, Fiserv.
Bank officers who the board decides should remain in their jobs will undergo a skills evaluation. The board will then have to devise a written program to improve the skills of bank officers who need training and to improve the officer's supervision and management of the bank.
The federal OCC also is requiring the creation and implementation of a written program to effectively assess and manage the bank's information technology. That plan must be approved by the OCC. Lake Shore Savings Bank will also have to develop, adopt and implement a written information security program that includes administrative, technical and physical safeguards to ensure the security and confidentiality of customer information, subject to review and approval by the OCC. Lastly, the bank will develop, adopt and implement a written automated clearing house risk management program, subject to review and approval by the OCC.
"The bank will not be deemed to be in compliance with this agreement until it has adopted, implemented, and adhered to all of the corrective actions set forth in each article of this agreement; the corrective actions are effective in addressing the Bank's deficiencies; and the OCC has verified and validated the corrective actions. An assessment of the effectiveness of the corrective actions requires sufficient passage of time to demonstrate the sustained effectiveness of the corrective actions."