MFSA published a document that provides background on Information and Communications Technology (ICT) risk and cybersecurity, also discussing the applicable legal and regulatory framework and the work of the Supervisory ICT Risk and Cybersecurity function of MFSA. In addition, MFSA issued a circular that addresses significant credit institutions regarding the harmonization of IMAS portal of ECB Banking Supervision with the FinHub portal of MFSA. The IMAS portal allows banks directly supervised by ECB to submit information related to supervisory processes, track their status, and exchange information with supervisors.
ECB, together with the national competent authorities of the member states in the Single Supervisory Mechanism, is in the process of streamlining the manner in which information flows between regulators and the banking industry. The system development in this respect is underway. Consequently, significant Institutions licensed in terms of the Banking Act, and supervised directly by the ECB, are being required to upload information including but not limited to fit-and-proper statuses and changes in key personnel on both the IMAS portal of ECB and the FinHub portal of MFSA, for an interim period until the back-end system development has been completed and is live. The IMAS Portal has been introduced in two phases. During the phasing-in period starting on October 20, 2020 only a limited number of significant banks were able to access and use the portal. After the full go-live on January 27, 2021, all banks directly supervised by ECB can use the portal.
Additionally, the published document on ICT risk and cybersecurity explains the supervisory approach of MFSA and outlines the establishment of the Supervisory ICT Risk and Cybersecurity function at MFSA. The document highlights the key observations of the Supervisory ICT Risk and Cybersecurity function through supervisory interactions over the past year and sets out the expectations of MFSA in this regard. It also discusses the focus areas for the coming year, in view of the designation of supervisory ICT risk and cybersecurity as a cross-sectoral priority of MFSA for 2021. The Supervisory ICT Risk and Cybersecurity function will continue to support the sectoral supervisory functions to ensure that regulated entities have an adequate cybersecurity program in place designed to enhance resilience to cyber-attacks and mitigate the risks associated with such threats. In view of the ever-increasing dependency on ICT, an enhancement, in terms of breadth and depth of supervisory activities throughout the year, is to be expected. Among others, the Supervisory ICT Risk and Cybersecurity function plans to:
- Develop an ICT and Cybersecurity risk model for supervision as a process for mapping out, and prioritizing key risk areas within the industry.
- Conduct a comprehensive and cross-sectoral thematic desk-based review on ICT Risk and Cybersecurity matters, including outsourcing.
- Intensify participation and contribution in local and foreign working groups throughout 2021 and anticipates significant progress on the legislative proposals on digital operational resilience.
- Circular on IMAS Portal
- ECB IMAS Portal
- Press Release on ICT Risk
- Document on ICT Risk and Cybersecurity (PDF)
Keywords: Europe, Malta, Banking, Reporting, IMAS Portal, FinHub Portal, SSM, Technology Risk, Cyber Risk, Outsourcing Risk, ECB, MFSA
Previous ArticleFSC Korea Details Policy Measures to Support Recovery from Pandemic
The Office of the Superintendent of Financial Institutions (OSFI) published the strategic plan for 2022-2025 and the departmental plan for 2022-23.
The European Banking Authority (EBA) is consulting, until August 31, 2022, on the draft implementing technical standards specifying requirements for the information that sellers of non-performing loans (NPLs) shall provide to prospective buyers.
The European Council and the Parliament reached an agreement on the revised Directive on security of network and information systems (NIS2 Directive).
The European Banking Authority (EBA) published the final draft regulatory technical standards specifying information that crowdfunding service providers shall provide to investors on the calculation of credit scores and prices of crowdfunding offers.
The European Securities and Markets Authority (ESMA) published a paper that examines the systemic risk posed by increasing use of cloud services, along with the potential policy options to mitigate this risk.
The European Commission (EC) published a public consultation on the review of revised payment services directive (PSD2) and open finance.
The European Commission (EC) has issued two letters mandating the European Supervisory Authorities (ESAs) to jointly propose amendments to the regulatory technical standards under Sustainable Finance Disclosure Regulation or SFDR.
The European Banking Authority (EBA) published its annual report on convergence of supervisory practices for 2021. Additionally, following a request from the European Commission (EC),
The Swiss National Bank (SNB) published Version 1.2 of the reporting forms (NSFR_G and NSFR_P) on the net stable funding ratio (NSFR) of banks, along with the associated documentation.
The Farm Credit Administration published, in the Federal Register, the final rule on implementation of the Current Expected Credit Losses (CECL) methodology for allowances