Banks need to remember that they are the ones regulators hold accountable for data security related to their customers' private financial information, but most often their vendors are the ones responsible for the breach. Without contract terms that require the vendor to notify the bank of a breach in a timely manner, it may be difficult for the bank to meet its legal obligations for notifying its customers of the breach.
Without a contract term requiring prompt notice, "it is not uncommon for the bank to be notified by its vendor of a breach months after the breach has occurred," Thomas Walker, a lawyer at Jones Walker who works on bank vendor contracts, told American Banker.
