FCA published a report on insights on the cyber resilience practices in the financial industry. The report presents examples of the cyber security practices that firms have shared with FCA. FCA hopes that these practices and experiences will help firms when considering where to prioritize their efforts in increasing cyber resilience.
Since 2017, FCA has brought together over 175 firms across different financial sectors to share information and ideas from their cyber experiences. FCA runs the Cyber Coordination Groups (CCGs) with industry to help improve cyber-security practices among members of the CCGs and their sectors. Over the last year, the groups have been discussing and sharing practices in the areas of Governance, Identification, Protection, Detection, Situational Awareness, Response and Recovery, and Testing. FCA has collated the examples shared by firms and set out those it considers to be beneficial for a wider audience under each of these themes:
- Putting good governance in place
- Identifying what needs to be protected
- Protecting assets appropriately
- Using good detection systems
- Being aware of emerging threats and issues
- Being ready to respond and recover
- Testing and refining defenses
The insights in this publication may be relevant for small and medium-size firms. However, FCA encourages all firms to consider whether these insights may be useful to them. FCA warns that this document should not be considered as FCA guidance, as it does not set out the FCA expectations about what systems and controls firms should have in place to comply with its regulatory requirements. However, many of the shared examples support existing guidance from the National Cyber Security Center.
Keywords: Europe, UK, Banking, Securities, Insurance, Cyber Resilience, Cyber Risk, Cyber Security, Regtech, FCA
HM Treasury announced that the new Financial Services Bill has been introduced in the Parliament.
PRA published the consultation paper CP17/20 to propose changes to certain rules, supervisory statements, and statements of policy to implement elements of the Capital Requirements Directive (CRD5).
US Agencies adopted a final rule that applies to advanced approaches banking organizations and aims to reduce interconnectedness in the financial system as well as to reduce contagion risks associated with the failure of a global systemically important bank (G-SIB).
US Agencies (FDIC, FED, and OCC) adopted a final rule that implements the net stable funding ratio (NSFR) for certain large banking organizations.
FSB finalized the toolkit of effective practices to assist financial institutions in their cyber incident response and recovery activities.
ECB published eleventh issue of the Macroprudential Bulletin, which provides insight into the ongoing work of ECB in the field of macro-prudential policy.
HM Treasury issued a call for evidence seeking views to reform the prudential regulatory regime—also known as Solvency II—of the insurance sector in UK.
ESRB responded to the EC consultation on review of Solvency II regime.
HM Treasury launched a consultation on Phase II of the Future Regulatory Framework Review, with the comment period ending on January 19, 2021.
EC adopted the work program for 2021.