OSFI issued an advisory on the Technology and Cyber Security Incident Reporting. The advisory sets out the OSFI expectations for federally regulated financial institutions (FRFIs) with respect to the reporting of technology and cyber security incidents affecting FRFI operations. The advisory describes characteristics of incidents that should be reported to OSFI, in addition to the initial notification and subsequent reporting requirements. The advisory comes into effect on March 31, 2019.
In the meantime, FRFIs are expected to continue reporting any major incidents according to previous instructions communicated by their Lead Supervisors. Effective March 31, 2019, this Advisory supersedes any prior instructions for technology and cyber security incident reporting. For the purpose of this Advisory, a technology or cyber security incident is defined to have the potential to, or has been assessed to, materially impact the normal operations of a FRFI, including confidentiality, integrity, or availability of its systems and information. Technology or Cyber Security Incidents assessed by a FRFI to be of a high or critical severity level should be reported to OSFI. FRFIs include banks, trust companies, loan companies, life insurance companies, fraternal benefit societies, and property and casualty insurance companies.
Effective Date: March 31, 2019
Keywords: Americas, Canada, Banking, Insurance, Cyber Risk, Incident Reporting, Advisory, Regtech, OSFI
Previous ArticleMAS Amends Notice 122 on Asset and Liability Exposures for Insurers
The European Banking Authority (EBA) published the final draft implementing technical standards on Pillar 3 disclosures on environmental, social, and governance (ESG) risks.
The European Banking Authority (EBA) proposed to update the guidelines on the data collection exercise on high earners and the remuneration benchmarking exercise under the Capital Requirements Directive (CRD).
The Network for Greening the Financial System (NGFS) announced the appointment of Mr. Ravi Menon, the Managing Director of the Monetary Authority of Singapore (MAS), as its new Chair for a two-year term.
The China Banking and Insurance Regulatory Commission (CBIRC) issued rules on related-party transactions and outsourcing risks.
The Office of the Superintendent of Financial Institutions (OSFI) published an update on the discussion paper that intended to engage federally regulated financial institutions and other interested stakeholders in a dialog with OSFI, to proactively enhance and align assurance expectations over key regulatory returns.
The European Commission (EC) published a report summarizing responses to the targeted consultation on the supervisory convergence and the single rulebook in the European Union (EU).
The Bank of International Settlements (BIS) announced successful test integration of wholesale central bank digital currency (CBDC) settlement with commercial banks, as part of the Project Helvetia.
The European Central Bank (ECB) published its opinion on a proposal for a regulation on European green bonds, following a request from the European Parliament.
The Advisory Scientific Committee (ASC) of the European Systemic Risk Board (ESRB) published a report that explores the expected impact of digitalization on provision of financial and banking services, and proposes policy measures to address the risks stemming from digitalization.
The Hong Kong Monetary Authority (HKMA) is consulting on the draft Financial Institutions (Resolution) Ordinance (Cap. 628), or FIRO, Code of Practice chapter on liquidity and funding in resolution, until March 14, 2022.