RBNZ announced that it is strengthening its efforts to enhance resilience of the financial system from cyber threats, including developing risk management guidance and promoting information-sharing in collaboration with industry and other public organizations. Additionally, RBNZ published a bulletin/paper that examines the concept of cyber resilience and estimates the potential costs of cyber risk for the financial system in New Zealand. With the frequency and severity of cyber-security incidents on the rise, the paper highlights the importance of the financial sector remaining vigilant and managing cyber risks effectively.
The paper published by RBNZ draws on two internationally recognized methods to shed more light on the potential cost that cyber risk poses to the banking and insurance sectors in New Zealand. The first method is a bottom-up approach that uses firm-specific data from abroad, which is then extrapolated to New Zealand. The second method uses top-down analysis, linking the cost of cyber incidents to GDP. The two methods produce remarkably similar results for New Zealand. The estimated average cost of cyber incidents is likely to be about NZD 104 million per annum for the banking industry and NZD 38 million for the insurance industry. To put this cost in context, it is the equivalent of 2% to 3% of annual profits for the banking and insurance sectors. According to the value-at-risk method, in any given year there is a 5% chance that the costs could rise beyond NZD 2 billion for the banking sector and more than NZD 300 million for the insurance sector, nearly equivalent to 34% (25%) of the annual net profits for banks and 25% of the annual net profits for insurers.
The analysis presented in the paper shows that the financial cost from cyber incidents is real and has the potential to be significant. Additional costs that have not been captured by the two approaches used in this paper include the loss of confidence in the financial system, the resulting impact on innovation and the adoption of new technological developments, and the diversion of resources away from productivity enhancing investment. Furthermore the country’s cyber-security agency CERT NZ found that more than 60% of the cyber-attacks on the New Zealand organizations in 2018 targeted firms in the financial and insurance services sector. Therefore, managing cyber risk and building cyber resilience should be of importance to the financial sector as well as its regulators.
Keywords: Asia Pacific, New Zealand, Banking, Insurance, Cyber Risk, Cyber Resilience, Fintech, Value-at-Risk, Bottom Up Approach, Top Down Analysis, RBNZ
Previous ArticleMAS Amends Regulation on Reporting of Derivatives Contracts
In a recent Market Notice, the Bank of England (BoE) confirmed that green gilts will have equivalent eligibility to existing gilts in its market operations.
The Financial Conduct Authority (FCA) published the policy statement PS21/9 on implementation of the Investment Firms Prudential Regime.
The European Banking Authority (EBA) proposed regulatory technical standards that set out criteria for identifying shadow banking entities for the purpose of reporting large exposures.
The Board of the International Organization of Securities Commissions (IOSCO) proposed a set of recommendations on the environmental, social, and governance (ESG) ratings and data providers.
The European Commission (EC) announced plans to defer the application of 13 regulatory technical standards under the Sustainable Finance Disclosure Regulation (2019/2088) by six months, from January 01, 2022 to July 01, 2022.
The European Insurance and Occupational Pensions Authority (EIOPA) proposed to amend the supervisory statement on supervision of run-off undertakings that are subject to Solvency II regulation.
The Bank of England (BoE) published a consultation paper on approach to setting minimum requirement for own funds and eligible liabilities (MREL), an operational guide on executing bail-in, and a statement from the Deputy Governor Dave Ramsden.
The European Banking Authority (EBA) is seeking preliminary input on standardization of the proportionality assessment methodology for credit institutions and investment firms.
Certain regulatory authorities in the US are extending period for completion of the review of certain residential mortgage provisions and for publication of notice disclosing the determination of this review until December 20, 2021.
The Prudential Regulation Authority (PRA) published the policy statement PS18/21, which introduces an amendment in the definition of "higher paid material risk taker" in the Remuneration Part of the PRA Rulebook.