Featured Product

    Dubai FSA Publishes Key Findings from Review of Cyber Risk Frameworks

    June 24, 2020

    Dubai FSA published the key findings from its thematic review on the cyber risk management frameworks of firms operating in the Dubai International Financial Center. The review, which was launched in July 2019, assessed cyber risk governance frameworks, cyber hygiene practices, and incident-preparedness programs of firms authorized by Dubai FSA. The review found that a significant number of firms had either not implemented a comprehensive cyber risk management framework or performed only a limited cyber risk assessment.

    The review shows that a significant number of firms perform only a limited cyber risk assessment. In many instances, neither the board nor senior management oversight of cyber risk management was sufficient. This was especially prevalent where firms outsourced their IT infrastructure and cyber security functions to an IT service provider. This was also evident in the fact that there was a lack of senior management review of cyber security audits, reviews, and tests. Only half of all firms have a due diligence process to assess whether third-party service providers meet the cyber security requirements and even fewer firms periodically test whether third-party service providers satisfy the cyber security requirements. 

    The majority of firms have implemented some form of a cyber incident response plan to respond to, and limit the consequences of, a cyber incident. However, in many cases, the cyber response procedures are addressed in general terms as components of the business continuity plan and are not tailored specifically to cyber threats. Less than half of all firms have implemented a crisis management communication plan that addresses external stakeholders while more than half of firms’ cyber incident response plans do not include a formal requirement for periodically testing the response to a cyber incident. Where firms do have a periodic testing requirement, it was identified that a significant number of firms have not tested any component of their cyber incident response plans in the past year. The published report summarizes such key findings and observations, along with the expectations of Dubai FSA and examples of best practices of cyber risk management. 

    The review was undertaken in two phases, with the first phase consisting of a questionnaire seeking high-level information on the cyber security practices of each authorized firm and the second phase consisting of desk-based reviews and onsite visits to selected firms representing a range of business models and financial services activities. Although not part of this review, the new remote working protocols established in 2020 also bring new cyber risk vulnerabilities that need to be addressed by the financial services industry. According to Mr. Bryan Stirewalt, the Chief Executive of the Dubai FSA, enhancement of the cyber resilience of regulated population is one of the key priorities of Dubai FSA, which has steadily increased the supervisory focus on cyber risk and is constantly engaging with firms in the Dubai International Financial Center to ensure they have sufficient safeguards in place to shield against and to respond to and recover from cyber incidents. The focus of Dubia FSA also includes support for development of industry-level guidance on cyber risk management practices. 

     

    Related Links

    Keywords: Middle East and Africa, UAE, Dubai, Banking, Cyber Risk, DIFC, Operational Risk, Cyber Testing, Outsourcing Arrangements, Third-Party Arrangements, Dubai FSA

    Related Articles
    News

    PRA and FPC Finalize Changes to Leverage Ratio Framework in UK

    The Prudential Regulation Authority (PRA) published the final policy statement PS21/21 on the leverage ratio framework in the UK. PS21/21, which sets out the final policy of both the Financial Policy Committee (FPC) and PRA

    October 08, 2021 WebPage Regulatory News
    News

    CFPB Proposes Rule on Small Business Lending Data Collection

    The Consumer Financial Protection Bureau (CFPB) proposed to amend Regulation B to implement changes to the Equal Credit Opportunity Act (ECOA) under Section 1071 of the Dodd-Frank Act.

    October 08, 2021 WebPage Regulatory News
    News

    PRA Decides to Maintain O-SII Buffers for Another Year

    The Prudential Regulation Authority (PRA) decided to maintain, at the 2019 levels, the buffer rates for the Other Systemically Important Institutions (O-SII) for another year, with no new rates to be set until December 2023.

    October 08, 2021 WebPage Regulatory News
    News

    FSB Report Assesses Implementation of Recommendations on Stablecoins

    The Financial Stability Board (FSB) published a progress report on implementation of its high-level recommendations for the regulation, supervision, and oversight of global stablecoin arrangements.

    October 07, 2021 WebPage Regulatory News
    News

    APRA Updates Loan Serviceability Expectations for Home Lending

    In a letter to the authorized deposit taking institutions, the Australian Prudential Regulation Authority (APRA) announced an increase in the minimum interest rate buffer it expects banks to use when assessing the serviceability of home loan applications.

    October 06, 2021 WebPage Regulatory News
    News

    CPMI and IOSCO Consult on Guidance on Stablecoin Arrangements

    The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) are consulting on the preliminary guidance that clarifies that stablecoin arrangements should observe international standards for payment, clearing, and settlement systems.

    October 06, 2021 WebPage Regulatory News
    News

    EBA and EIOPA Set Out Work Priorities for 2022

    The European Banking Authority (EBA) and the European Insurance and Occupational Pensions Authority (EIOPA) have set out their respective work priorities for 2022.

    October 05, 2021 WebPage Regulatory News
    News

    MFSA Issues Reporting Updates and Guidance for Banks

    The Malta Financial Services Authority (MFSA) updated the guidelines on supervisory reporting requirements under the reporting framework 3.0, in addition to the reporting module on leverage under the common reporting (COREP) framework.

    October 05, 2021 WebPage Regulatory News
    News

    EC Publishes Decision on List of Equivalent Third Countries Under CRR

    The European Commission (EC) published the Implementing Decision 2021/1753 on the equivalence of supervisory and regulatory requirements of certain third countries and territories for the purposes of the treatment of exposures, in accordance with the Capital Requirements Regulation or CRR (575/2013).

    October 04, 2021 WebPage Regulatory News
    News

    EC Rule on Contractual Recognition of Write-Down and Conversion Powers

    EC published the Implementing Regulation 2021/1751, which lays down implementing technical standards on uniform formats and templates for notification of determination of the impracticability of including contractual recognition of write-down and conversion powers.

    October 04, 2021 WebPage Regulatory News
    RESULTS 1 - 10 OF 7552