Featured Product

    RBNZ to Address Cyber Risk Through Risk Management Guidance

    February 25, 2020

    RBNZ announced that it is strengthening its efforts to enhance resilience of the financial system from cyber threats, including developing risk management guidance and promoting information-sharing in collaboration with industry and other public organizations. Additionally, RBNZ published a bulletin/paper that examines the concept of cyber resilience and estimates the potential costs of cyber risk for the financial system in New Zealand. With the frequency and severity of cyber-security incidents on the rise, the paper highlights the importance of the financial sector remaining vigilant and managing cyber risks effectively.

    The paper published by RBNZ draws on two internationally recognized methods to shed more light on the potential cost that cyber risk poses to the banking and insurance sectors in New Zealand. The first method is a bottom-up approach that uses firm-specific data from abroad, which is then extrapolated to New Zealand. The second method uses top-down analysis, linking the cost of cyber incidents to GDP. The two methods produce remarkably similar results for New Zealand. The estimated average cost of cyber incidents is likely to be about NZD 104 million per annum for the banking industry and NZD 38 million for the insurance industry. To put this cost in context, it is the equivalent of 2% to 3% of annual profits for the banking and insurance sectors. According to the value-at-risk method, in any given year there is a 5% chance that the costs could rise beyond NZD 2 billion for the banking sector and more than NZD 300 million for the insurance sector, nearly equivalent to 34% (25%) of the annual net profits for banks and 25% of the annual net profits for insurers.

    The analysis presented in the paper shows that the financial cost from cyber incidents is real and has the potential to be significant. Additional costs that have not been captured by the two approaches used in this paper include the loss of confidence in the financial system, the resulting impact on innovation and the adoption of new technological developments, and the diversion of resources away from productivity enhancing investment. Furthermore the country’s cyber-security agency CERT NZ found that more than 60% of the cyber-attacks on the New Zealand organizations in 2018 targeted firms in the financial and insurance services sector. Therefore, managing cyber risk and building cyber resilience should be of importance to the financial sector as well as its regulators. 

     

    Related Links

    Keywords: Asia Pacific, New Zealand, Banking, Insurance, Cyber Risk, Cyber Resilience, Fintech, Value-at-Risk, Bottom Up Approach, Top Down Analysis, RBNZ

    Related Articles
    News

    US Agencies Finalize Interim Final Rules Issued Amid Pandemic

    US Agencies (FDIC, FED, and OCC) finalized two rules, which are either identical or substantially similar to the interim final rules in effect and issued earlier this year.

    September 29, 2020 WebPage Regulatory News
    News

    EIOPA Consults on Use of Risk Mitigation Techniques Under Solvency II

    EIOPA is consulting on a supervisory statement on the use of risk mitigation techniques by insurance and reinsurance undertakings.

    September 29, 2020 WebPage Regulatory News
    News

    APRA Proposes to Increase Transparency of Banking Data

    APRA announced that it is resuming consultation on the confidentiality of data submitted to APRA by the authorized deposit-taking institutions.

    September 29, 2020 WebPage Regulatory News
    News

    BoE and FCA Encourage Switch to SONIA in Interest Rate Swap Markets

    BoE and FCA are supporting and encouraging liquidity providers in the sterling swaps market to adopt new quoting conventions for inter-dealer trading based on SONIA, instead of LIBOR, from October 27, 2020.

    September 28, 2020 WebPage Regulatory News
    News

    Bundesbank Updates Supporting Information for SHS Reporting

    Deutsche Bundesbank published special schema files for securities holdings statistics (SHS), along with a document on the XML format description.

    September 28, 2020 WebPage Regulatory News
    News

    EC Deems UK Framework for CCPs Temporarily Equivalent to EMIR Rules

    EC adopted a decision determining, for a limited period of time, that the regulatory framework applicable to central counterparties, or CCPs, in the UK and Northern Ireland is equivalent to the requirements laid down in the European Market Infrastructure Regulation (EMIR or Regulation 648/2012).

    September 28, 2020 WebPage Regulatory News
    News

    ESMA to Recognize Three Central Counterparties from UK

    ESMA announced that it will recognize three central counterparties (CCPs) established in the UK as third-country CCPs, from January 01, 2021.

    September 28, 2020 WebPage Regulatory News
    News

    PRA Publishes Version 02.04 of PRA110 Liquidity Metric Monitor Tool

    PRA published Version 02.04 of the PRA110 liquidity metric monitoring tool (PRA110 LMM tool).

    September 28, 2020 WebPage Regulatory News
    News

    LEI ROC Confirmed as Governance Body for OTC Derivatives Identifiers

    FSB confirmed the Regulatory Oversight Committee (ROC) of the Global Legal Entity Identifier System (GLEIS) as the International Governance Body for the globally harmonized identifiers used to track over-the-counter (OTC) derivatives transactions, with effect from October 01, 2020.

    September 25, 2020 WebPage Regulatory News
    News

    FCA Consults on Regulation of International Firms in UK

    FCA is consulting on its approach to the authorization and supervision of international firms operating in UK.

    September 25, 2020 WebPage Regulatory News
    RESULTS 1 - 10 OF 5863