April 10, 2019

ESAs published two pieces of Joint Advice in response to the requests of EC in its March 2018 FinTech Action Plan. One Joint Advice pertains to the need for legislative improvements related to Information and Communication Technology (ICT) risk management requirements in the EU financial sector. The second Joint Advice pertains to the costs and benefits of a coherent cyber resilience testing framework for significant market participants and infrastructures within the EU financial sector.

Regarding the need for legislative improvements, in developing the Joint Advice, ESAs' objective was that every relevant entity should be subject to clear general requirements on governance of ICT, including cybersecurity, to ensure the safe provision of regulated services. Guided by this objective, the proposals presented in the Advice aim to promote stronger operational resilience and harmonization in the EU financial sector by applying changes to their respective sectoral legislation. Incident reporting is highly relevant to ICT risk management and allows relevant entities and authorities to log, monitor, analyze, and respond to ICT operational, ICT security, and fraud incidents. Therefore, ESAs call for streamlining aspects of the incident reporting frameworks across the financial sector. Furthermore, ESAs suggest that a legislative solution for an appropriate oversight framework to monitor the activities of critical third-party service providers should be considered.

Regarding the costs and benefits of a coherent cyber resilience testing framework, ESAs see clear benefits of such a framework. However, there are significant differences on the maturity level of cybersecurity, across and within financial sectors. In the short-term, ESAs advise to focus on achieving a minimum level of cyber-resilience across the sectors, proportionate to the needs and characteristics of the relevant entities. Furthermore, ESAs propose to establish, on a voluntary basis, an EU-wide coherent testing framework, with other relevant authorities (taking into account the existing initiatives) and with a focus on Threat Lead Penetration Testing. In the long-term, ESAs aim to ensure a sufficient cyber maturity level of identified cross-sector entities.

To implement the proposed actions, ESAs highlight the required legal basis and explicit mandate, which is necessary for development and implementation of a coherent resilience testing framework across all financial sectors by ESAs in cooperation with other relevant authorities. EC, in the March 2018 FinTech Action Plan, had specifically requested ESAs to map, by the first quarter of 2019, the existing supervisory practices across financial sectors around ICT security and governance requirements and, where appropriate, to consider issuing guidelines aimed at supervisory convergence and enforcement of ICT risk management and mitigation requirements in the EU financial sector and, if necessary, to provide EC with technical advice on the need for legislative improvements. EC had also requested ESAs to evaluate, by the fourth quarter of 2018 (now Q1 2019), the costs and benefits of developing a coherent cyber resilience testing framework for significant market participants and infrastructures within the EU financial sector.

 

Related Links

Keywords: Europe, EU, Banking, Insurance, Securities, Fintech, Cyber Risk, ICT Risk, Operational Risk, Fintech Action Plan, Cyber Resilience, ESAs

Related Articles
News

SEC Proposes to Improve Cross-Border Application of SBS Requirements

SEC proposed a package of rule amendments and interpretive guidance to improve the framework for regulating cross-border security-based swaps (SBS) transactions and market participants.

May 24, 2019 WebPage Regulatory News
News

US Agencies Propose to Amend Regulatory Framework for Foreign Banks

US Agencies (OCC, FED, and FDIC) proposed a regulatory framework for foreign banks operating in the U.S. that would more closely match the rules for foreign banks with the risks they pose to the U.S. financial system.

May 24, 2019 WebPage Regulatory News
News

FSB to Evaluate Effects of Too-Big-To-Fail Reforms for Systemic Banks

FSB is seeking feedback as part of its evaluation of the effects of the too-big-to-fail reforms for banks.

May 23, 2019 WebPage Regulatory News
News

OSFI Revises Covered Bond Limit Calculation for Deposit Takers

OSFI is updating the covered bond limit calculation, which was last revised in December 2014.

May 23, 2019 WebPage Regulatory News
News

APRA Releases Minor Changes to Reporting Standards on SA-CCR for Banks

APRA released minor changes to the three reporting standards for the standardized approach for measuring counterparty credit risk exposures (SA-CCR).

May 22, 2019 WebPage Regulatory News
News

APRA on Industry Self-Assessments into Governance and Accountability

APRA released an information paper analyzing the self-assessments performed by 36 of the country’s largest banks, insurers, and superannuation licensees in response to the final report on the Prudential Inquiry into the Commonwealth Bank of Australia (CBA).

May 22, 2019 WebPage Regulatory News
News

PRA Consults on Maintenance of TMTP Under Solvency II

PRA published a consultation paper (CP11/19) that sets out its approach to update supervisory statement (SS6/16) on maintenance of the transitional measure on technical provisions (TMTP) under Solvency II.

May 22, 2019 WebPage Regulatory News
News

EBA Regards Regulatory Framework in Argentina to be Equivalent to EU

EBA published its opinion that the supervisory and regulatory framework applicable to credit institutions in Argentina can be regarded as equivalent to that applied in EU.

May 22, 2019 WebPage Regulatory News
News

RBNZ Reviews Restrictions on Policy for Loan to Value Ratio

RBNZ published a report on the review of the loan to ratio (LVR) restrictions as part of a wider review of the macro-prudential policy.

May 22, 2019 WebPage Regulatory News
News

APRA Proposes to Amend Guidance on Residential Mortgage Lending

APRA is consulting on revisions to the prudential practice guide APG 223 on residential mortgage lending in Australia.

May 21, 2019 WebPage Regulatory News
RESULTS 1 - 10 OF 3127