March 09, 2018

Sabine Lautenschläger and Benoît Cœuré of ECB spoke about cyber resilience at the first meeting of the Euro Cyber Resilience Board for pan-European Financial Infrastructures in Frankfurt. Ms. Lautenschläger highlights that “ECB Banking Supervision takes cyber resilience very seriously” and discussed the ECB progress so far, along with its plans for the future. Mr. Cœuré also discussed the future course of the high-level cyber resilience forum for pan-European financial market infrastructures, critical service providers, and competent authorities.

With respect to the work done so far, Ms. Lautenschläger highlighted that ECB has conducted thematic reviews on cyber risk and outsourcing, a stocktake on how IT risks are supervised outside the euro area, and quite a few on-site inspections into IT and cyber risks, using state-of-the-art methods. ECB has also set up a reporting framework for cyber incidents. Drawing on the EBA guidelines, ECB has developed comprehensive IT risk self-assessments for the banks it supervises, including an extensive section on IT and cyber security. The results of these assessments will feed into the Supervisory Review and Evaluation Process, in which ECB will also challenge the information provided by banks. The review will give a better idea of the overall IT risk landscape in the banking industry and will help to identify blind spots early on and define areas for further investigation; this will eventually feed into the plans for 2019. In addition, the review will help to compare banks and partially anonymized feedback could then be shared with them. She concludes, “While cybercrime may have an aura of mystery and power, cyber resilience is quite the opposite: it calls for vigilance and diligence, day in, day out.”

Additionally, Benoît Cœuré of ECB said that, within the Eurosystem, there has been close collaboration on implementing the Eurosystem oversight cyber resilience strategy for financial market infrastructures, in line with CPMI-IOSCO’s guidance on this topic. He explained the goals and objectives of the Euro Cyber Resilience Board (ECRB) for pan-European Financial Infrastructures and highlighted that ECRB will have no formal powers to impose binding measures and will not make supervisory judgments. The ECRB will be chaired by ECB, which will be closely involved together with national central banks and observers from the relevant European public authorities. He also outlined the two recent activities of ECB:

  • First, a cyber resilience survey, developed under the Eurosystem oversight cyber resilience strategy, was conducted across more than 75 payment systems, central securities depositories, and central counterparties throughout Europe. The survey highlighted a number of very pertinent issues for discussion, such as cyber governance, training and awareness, and cyber incident response.
  • Second, the Eurosystem is finalizing the main elements of the European Threat Intelligence-Based Ethical Red-Teaming (TIBER-EU) Framework. This is an interesting concept that is expected to raise the level of cyber resilience in Europe and enable cross-border, cross-authority testing, which has not been done before.

 

Related Links

Keywords: Europe, EU, Banking, PMI, Cyber Risk, Banking Supervision, ECB

Related Articles
News

BIS Report Discusses Regulatory Issues Related to Big Techs in Finance

BIS has pre-released a chapter of the BIS Annual Economic Report; this chapter focuses on the risks and opportunities presented by large technology firms (big techs) in the financial services sector.

June 23, 2019 WebPage Regulatory News
News

IOSCO Report Examines Liquidity in Corporate Bond Markets

IOSCO published a report that examines the factors affecting liquidity, under stressed conditions, in the secondary corporate bond markets.

June 21, 2019 WebPage Regulatory News
News

FED Publishes Results of the 2019 Stress Tests for Banks

FED published a report presenting results of the Dodd-Frank Act Stress Test (DFAST) exercise for 2019.

June 21, 2019 WebPage Regulatory News
News

BCBS Report Examines Global Pillar 2 Supervisory Review Practices

BCBS published a report that examines the Pillar 2 supervisory review practices and approaches in Basel member jurisdictions.

June 21, 2019 WebPage Regulatory News
News

IASB Publishes Work Plan and Meeting Updates for June 2019

IASB published an updated work plan and a summary of its June meeting, which presents preliminary decisions of the Board.

June 21, 2019 WebPage Regulatory News
News

HKMA Publishes Banking Exposure Limits Code Under Banking Ordinance

HKMA issued a circular to all authorized institutions informing that the Banking (Exposure Limits) Code has been published in the Gazette on June 21, 2019.

June 21, 2019 WebPage Regulatory News
News

OSFI Proposes Guideline on Internal Model Oversight for Insurers

OSFI proposed the draft guideline E-25 on the internal model oversight framework for federally regulated property and casualty (P&C) insurance companies.

June 21, 2019 WebPage Regulatory News
News

EBA Single Rulebook Q&A: Third Update for June 2019

Under the Single Rulebook question and answer (Q&A) updates for this week, EBA published one answer regarding the calculation of institution-specific countercyclical capital buffer rates.

June 21, 2019 WebPage Regulatory News
News

BCBS Publishes Summary of the Meeting in June 2019

BCBS published a summary of its June meeting in Basel.

June 20, 2019 WebPage Regulatory News
News

OCC Bulletin on Risk Management Guidance for Home Mortgage Lending

OCC published Bulletin 2019-28 on risk management guidance for higher-loan-to-value (LTV) lending activities in communities targeted for revitalization.

June 19, 2019 WebPage Regulatory News
RESULTS 1 - 10 OF 3298