General Information & Client Service
  • Americas: +1.212.553.1653
  • Asia: +852.3551.3077
  • China: +86.10.6319.6580
  • EMEA: +44.20.7772.5454
  • Japan: +81.3.5408.4100
Media Relations
  • New York: +1.212.553.0376
  • London: +44.20.7772.5456
  • Hong Kong: +852.3758.1350
  • Tokyo: +813.5408.4110
  • Sydney: +61.2.9270.8141
  • Mexico City: +001.888.779.5833
  • Buenos Aires: +0800.666.3506
  • São Paulo: +0800.891.2518
August 07, 2018

ECB published the Services Procurement Guidelines, which are referred to in, and are an integral part of, the Threat Intelligence-Based Ethical Red Teaming (TIBER-EU) framework. The guidelines set out in detail the different elements of TIBER-EU procurement. TIBER-EU framework enables European and national authorities to work with financial infrastructures and institutions to put in place a program to test and improve their resilience against sophisticated cyber attacks. Due to the sensitive nature of TIBER-EU tests, entities need to carefully select threat intelligence and red teaming providers that can provide an appropriate level of professional expertise and support for conducting the test.

The first part of the document sets out the requirements and standards that must be met by threat intelligence providers to deliver recognized TIBER-EU tests and offers guiding principles and selection criteria for entities, as they look to procure services from prospective providers. Then, the document sets out the requirements and standards that must be met by red teaming providers to deliver recognized TIBER-EU tests and offer guiding principles and selection criteria for entities, as they look to procure services from prospective providers. Next, it provides guidance to authorities that are looking to implement TIBER-EU at the national and European levels, with regard to procurement. Annex 1 provides a list of certifications that staff members and providers may be, depending on the case, required to possess. Annexes 2-5 provide questions that entities could use when considering prospective providers and agreement checklists to assist the procurement functions during their procurement process.

The guidelines are directed at authorities responsible for the adoption, implementation, and management of the TIBER-EU Framework at national and European levels; entities looking to undertake TIBER-EU tests; organizations interested in providing cyber threat intelligence services under TIBER-EU; organizations interested in providing red team testing services under TIBER-EU; and accreditation and certification providers. As the TIBER-EU Framework is implemented across EU, the TIBER-EU Knowledge Center (TKC) will monitor the evolution of the threat intelligence and red team testing market and update the requirements, if necessary. TKC will undertake this task by closely liaising with the authorities that adopt the TIBER-EU Framework, the entities that undertake the tests, and the threat intelligence/red teaming providers that deliver the tests.


Related Link: Guidelines (PDF)

Keywords: Europe, EU, Banking, Insurance, Securities, PMI, Cyber Risk, TIBER-EU, Cyber Resilience, Procurement Services Guidelines, ECB

Related Insights

PRA Delays Final Direction on Reporting of Private Securitizations

PRA and FCA have delayed the issuance of final direction, including the final template, on reporting of private securitizations, from January 15, 2019 to the end of January 2019.

January 15, 2019 WebPage Regulatory News

BCBS Finalizes Market Risk Capital Framework and Work Program for 2019

BCBS published the final framework for market risk capital requirements and its work program for 2019. Also published was an explanatory note to provide a non-technical description of the overall market risk framework, the changes that have been incorporated into in this version of the framework and impact of the framework.

January 14, 2019 WebPage Regulatory News

EBA Single Rulebook Q&A: First Update for January 2019

EBA published answers to 13 questions under the Single Rulebook question and answer (Q&A) updates for this week.

January 11, 2019 WebPage Regulatory News

PRA Proposes to Amend Supervisory Statement on Credit Risk Mitigation

PRA published the consultation paper CP1/19 that is proposing changes to the supervisory statement (SS17/13) on credit risk mitigation.

January 10, 2019 WebPage Regulatory News

FASB Issues Q&A on Estimating Credit Loss Reserves

FASB issued a question-and-answer (Q&A) document that addresses particular issues related to the weighted average remaining maturity (WARM) method for estimating the allowance for credit losses.

January 10, 2019 WebPage Regulatory News

FED Updates Reporting and Supplemental Instructions for Form FR Y-9C

FED published the updated reporting instructions and supplemental instructions for the FR Y-9C reporting form. The reporting frequency for FR Y-9C is quarterly, as of the last calendar day of the quarter.

January 09, 2019 WebPage Regulatory News

PRA Updates Policy on Liquidity Reporting Under FSA047/048 and PRA110

PRA published the policy statement PS1/19 that provides feedback to responses to the consultation paper CP22/18 titled "Liquidity reporting: FSA047 and FSA048" and the proposal in CP16/18, which intended to correct the level of consolidation of the PRA110 reporting requirements.

January 08, 2019 WebPage Regulatory News

FED Proposes to Amend Company-Run Stress Testing Requirements

FED proposed to modify company-run stress testing requirements to conform with the Economic Growth, Regulatory Relief, and Consumer Protection (EGRRCP) Act.

January 08, 2019 WebPage Regulatory News

ESMA RTS on Supervisory Cooperation Under Securitization Regulation

ESMA issued the final regulatory technical standards (RTS) for cooperation between competent authorities and ESAs under the Securitization Regulation (2017/2402).

January 08, 2019 WebPage Regulatory News

ESAs Publish Joint Report on Regulatory Sandboxes and Innovation Hubs

ESAs published a joint report providing a comparative analysis of the innovation facilitators (that is, regulatory sandboxes and innovation hubs) established to date within the EU.

January 07, 2019 WebPage Regulatory News
RESULTS 1 - 10 OF 2461