RBNZ to Address Cyber Risk Through Risk Management Guidance
RBNZ announced that it is strengthening its efforts to enhance resilience of the financial system from cyber threats, including developing risk management guidance and promoting information-sharing in collaboration with industry and other public organizations. Additionally, RBNZ published a bulletin/paper that examines the concept of cyber resilience and estimates the potential costs of cyber risk for the financial system in New Zealand. With the frequency and severity of cyber-security incidents on the rise, the paper highlights the importance of the financial sector remaining vigilant and managing cyber risks effectively.
The paper published by RBNZ draws on two internationally recognized methods to shed more light on the potential cost that cyber risk poses to the banking and insurance sectors in New Zealand. The first method is a bottom-up approach that uses firm-specific data from abroad, which is then extrapolated to New Zealand. The second method uses top-down analysis, linking the cost of cyber incidents to GDP. The two methods produce remarkably similar results for New Zealand. The estimated average cost of cyber incidents is likely to be about NZD 104 million per annum for the banking industry and NZD 38 million for the insurance industry. To put this cost in context, it is the equivalent of 2% to 3% of annual profits for the banking and insurance sectors. According to the value-at-risk method, in any given year there is a 5% chance that the costs could rise beyond NZD 2 billion for the banking sector and more than NZD 300 million for the insurance sector, nearly equivalent to 34% (25%) of the annual net profits for banks and 25% of the annual net profits for insurers.
The analysis presented in the paper shows that the financial cost from cyber incidents is real and has the potential to be significant. Additional costs that have not been captured by the two approaches used in this paper include the loss of confidence in the financial system, the resulting impact on innovation and the adoption of new technological developments, and the diversion of resources away from productivity enhancing investment. Furthermore the country’s cyber-security agency CERT NZ found that more than 60% of the cyber-attacks on the New Zealand organizations in 2018 targeted firms in the financial and insurance services sector. Therefore, managing cyber risk and building cyber resilience should be of importance to the financial sector as well as its regulators.
Related Links
Keywords: Asia Pacific, New Zealand, Banking, Insurance, Cyber Risk, Cyber Resilience, Fintech, Value-at-Risk, Bottom Up Approach, Top Down Analysis, RBNZ
Previous Article
MAS Amends Regulation on Reporting of Derivatives ContractsRelated Articles
EC Adopts Financial Reporting Changes Arising from Benchmark Reforms
EC published Regulation 2021/25 that addresses amendments related to the financial reporting consequences of replacement of the existing interest rate benchmarks with alternative reference rates.
BIS Bulletin Examines Key Elements of Policy Response to Cyber Risk
BIS published a bulletin, or a note, that examines the cyber threat landscape in the context of the pandemic and discusses policies to reduce risks to financial stability.
HMT Updates List of Post-Brexit Equivalence Decisions in UK
HM Treasury, also known as HMT, has updated the table containing the list of the equivalence decisions that came into effect in UK at the end of the transition period of its withdrawal from EU.
EBA Issues Erratum for Technical Package on Reporting Framework 3.0
EBA published an erratum for technical package on phase 1 of the reporting framework 3.0.
APRA Publishes FAQ on Measurement of Credit Risk Weighted Assets
APRA updated a frequently asked question (FAQ), for authorized deposit-taking institutions, on the measurement of credit risk weighted assets.
EBA Publishes Risk Dashboard for Third Quarter of 2020
EBA published the quarterly risk dashboard, along with the results of the Risk Assessment Questionnaire survey among 60 banks and 15 market analysts.
ECB Analysis Shows Privacy as Biggest Concern in Use of Digital Euro
ECB concluded the public consultation on the introduction of a digital euro in EU.
ECB Finalizes Guide on Supervisory Approach to Bank Consolidation
ECB published a guide that sets out the supervisory approach to consolidation in the banking sector.
SRB Chair Outlines Work Priorities for 2021
The SRB Chair Elke König published an article setting out work priorities for 2021.
FDIC Selects Companies to Compete in Final Phase of Tech Sprint
FDIC has selected 11 technology companies—including BearingPoint, Fed Reporter, Inc, and S&P Global Market Intelligence, LLC—for inclusion in the third and final phase of the rapid prototyping competition.