OSFI issued an advisory on the Technology and Cyber Security Incident Reporting. The advisory sets out the OSFI expectations for federally regulated financial institutions (FRFIs) with respect to the reporting of technology and cyber security incidents affecting FRFI operations. The advisory describes characteristics of incidents that should be reported to OSFI, in addition to the initial notification and subsequent reporting requirements. The advisory comes into effect on March 31, 2019.
In the meantime, FRFIs are expected to continue reporting any major incidents according to previous instructions communicated by their Lead Supervisors. Effective March 31, 2019, this Advisory supersedes any prior instructions for technology and cyber security incident reporting. For the purpose of this Advisory, a technology or cyber security incident is defined to have the potential to, or has been assessed to, materially impact the normal operations of a FRFI, including confidentiality, integrity, or availability of its systems and information. Technology or Cyber Security Incidents assessed by a FRFI to be of a high or critical severity level should be reported to OSFI. FRFIs include banks, trust companies, loan companies, life insurance companies, fraternal benefit societies, and property and casualty insurance companies.
Effective Date: March 31, 2019
Keywords: Americas, Canada, Banking, Insurance, Cyber Risk, Incident Reporting, Advisory, Regtech, OSFI
Previous ArticleMAS Amends Notice 122 on Asset and Liability Exposures for Insurers
The Australian Prudential Regulation Authority (APRA) published a new set of frequently asked questions (FAQs) to clarify the regulatory capital treatment of investments in the overseas deposit-taking and insurance subsidiaries.
The Hong Kong Monetary Authority (HKMA) issued a circular, for all authorized institutions, to confirm its support of an information note that sets out various options available in the loan market for replacing USD LIBOR with the Secured Overnight Financing Rate (SOFR).
The tech lab of the Federal Deposit Insurance Corporation (FDIC) selected three winning teams in a tech sprint designed to explore new technologies and techniques to help banks meet the needs of unbanked consumers.
The Monetary Authority of Singapore (MAS) launched a consultation on the standards for market risk capital and the associated reporting requirements for banks incorporated in Singapore.
PRA published a "Dear CEO" letter that sets out findings of a review on the reliability of regulatory reporting and reiterates the supervisory expectations on regulatory reporting.
The Australian Prudential Regulation Authority (APRA) confirmed that its new data collection solution APRA Connect will go live on September 13, 2021.
The Federal Reserve System (FED) published a paper describing the landscape of partnerships between community banks and fintech companies.
The Federal Deposit Insurance Corporation (FDIC) has chosen four companies—Novantas Inc, Palantir Technologies Inc, PeerIQ, and S&P Global Market Intelligence LLC—to propose a pilot consisting of testing new reporting and analytical tools with a small group of FDIC-supervised institutions on a voluntary basis.
The Prudential Regulatory Authority (PRA), via the consultation paper CP18/21, proposed changes to the applicable requirements on the identification of material risk-takers for the purposes of the remuneration regime.
The Joint Committee of European Supervisory Authorities (ESAs) published its second 2021 joint risk assessment report for the financial sector.