Sep 16, 2026 · 5 min read

The NCUA 72-hour clock starts on belief, not on proof

NCUA gives a credit union 72 hours from the moment it reasonably believes it had a reportable cyber incident, not from the moment it can prove one.

Article header: The NCUA 72-hour clock starts on belief, not on proof

Insight Credit Union turned up on the extortion group Storm's leak site on Monday, September 15, 2026. ransomware.live logged the entry at 10:46 UTC with a claimed attack date of September 14, an onion claim URL, and a screenshot. Every fact about the intrusion is the attacker's claim: the only actor statement, quoted in DeXpose's September 16 write-up, is "We have successfully infiltrated Insight Credit Union's network." The homepage carried no member notice when checked on September 16. Nothing about a breach at Insight is confirmed. The argument below does not need it to be.

What is confirmed is which rules apply. NCUA's record for charter 67344 lists INSIGHT as a FISCU — a federally insured, state-chartered credit union in Winter Springs — with 41,917 members and $629,129,283 in assets. Federal insurance puts it under 12 CFR part 748; the Florida charter puts it under Fla. Stat. 501.171. Both clocks start on the same verb.

The verb is "believes," not "determines"

12 CFR 748.1(c) requires notification to an NCUA-designated point of contact "via email, telephone, or other similar methods that the NCUA may prescribe." The timing is the whole story:

The NCUA must receive this notification as soon as possible but no later than 72 hours after a federally insured credit union reasonably believes that it has experienced a reportable cyber incident or, if reporting pursuant to paragraph (c)(1)(i)(C) of this section, within 72 hours of being notified by a third-party, whichever is sooner.

Under 748.1(c)(1)(i)(A), a reportable cyber incident is one leading to "a substantial loss of confidentiality, integrity, or availability of a network or member information system … that results from the unauthorized access to or exposure of sensitive data." Limb (C) reaches the same outcome through a service organization, cloud provider, or supply chain — hence the third-party trigger above, which can start the 72 hours before you have looked at anything.

Florida is drafted the same way. 501.171(3)(a) requires notice to the Department of Legal Affairs for a breach affecting 500 or more Floridians "no later than 30 days after the determination of the breach or reason to believe a breach occurred," with 15 additional days available only if written good cause is filed inside the original 30. Individual notice under 501.171(4)(a) reaches everyone whose personal information "was, or the covered entity reasonably believes to have been, accessed."

Timeline: if the September 15 leak-site listing formed belief, the 12 CFR 748.1(c) notification window to NCUA closes 72 hours later on September 18, the Fla. Stat. 501.171(3)(a) notice to the Department of Legal Affairs is due 30 days later on October 15, and the 15-day good-cause extension would run to October 30.

Compare HIPAA, where the 60-day clock starts at determination: Operation PAR detected the intrusion on day one and needed 365 more days to determine PHI was involved. NCUA and Florida set their trigger one step earlier, at belief: the forensic answer arrives late, and a deadline conditioned on it is not a deadline.

So the evidence that starts your clock is evidence you did not generate: a leak-site post, a broker's message, a reporter's call. Leak sites routinely publish before the victim says anything — and under 748.1(c), the attacker setting the disclosure schedule is setting the regulatory one.

The practice: decide who calls it, before there is anything to call

The 72 hours are not investigation time. They are decision time, and the decision is binary: does what we know meet "reasonably believes"?

Name the decider in writing. One role — not a committee, not "the incident response team" — authorized to say the standard is met, plus a named alternate. Write down what they need to say yes: the listing, whether the named domain is yours, whether your telemetry is consistent with it. A Sarasota vendor took 155 days against a 45-day deadline because discovery was never defined in advance. At 72 hours there is far less room.

Drill the egress question, not the incident. Given a listing naming you at 09:00, how long until you can say whether data left, from which system, and in what volume? If the answer is weeks, the gap is telemetry — egress and data-access logging retained long enough to cover a window you do not control — and 72 hours is not enough time to build it.

Both cost something. Pre-authorizing one person means you will sometimes notify on an incident that turns out to be nothing, and that notification is permanent and lands with your examiner. Useful log retention is a storage line competing against clearer returns.

When you cannot close the telemetry gap in time, notify anyway. 748.1(c) asks for notification of the occurrence, by email or telephone; it does not ask you to characterize the incident, nor condition the deadline on your having done so. A notice saying what you know and what you do not is compliant. A complete one filed on day five is not.

What to check this week

  • Who is authorized to decide that "reasonably believes" is met, and who decides when they are unreachable?
  • Do you hold your NCUA-designated point of contact and channel today, or would you look it up inside the 72 hours?
  • For a listing posted at 09:00 today: how long until you can answer "did anything leave, and from where"?
  • Do your egress and data-access logs retain longer than the gap between an intrusion and the post announcing it?

Insight has said nothing publicly as of September 16, and may well have nothing to say. The clock above is the one every federally insured credit union in Florida is on the moment someone else publishes its name.


North InfoSec runs AI-assisted penetration testing and security assessments, including the egress and data-access telemetry review described above. northinfosec.com

← All articles