HKMA issued a circular requesting all authorized institutions to critically assess the need for setting up a secure tertiary data backup (STDB) to counter the risk of destructive cyber-attacks. All retail banks and foreign bank branches with significant operations in Hong Kong are expected to submit a report containing the result of their assessment to HKMA by November 30, 2021. HKMA will inform institutions individually if they are required to submit the report and will provide them with details of what information needs to be covered by the report.
HKMA had invited the Hong Kong Association of Banks (HKAB) to develop guidelines on secure tertiary data backup that are appropriate for the banking landscape in Hong Kong. In response to the HKMA call, HKAB had formed an STDB Taskforce to oversee the development of the guidelines. After extensive consultation with member institutions, HKAB issued the “Secure Tertiary Data Backup Guideline” on April 30, 2021. The STDB Guideline provides guidance to banks on the factors they need to consider in deciding whether to set up an STDB and what implementation issues they need to overcome in ensuring the effectiveness of the STDB. The Guideline covers eight high-level principles grouped under the headings of Governance, Design, and Data Restoration. HKMA considers STDB an effective measure to enhance cyber resilience and data security of authorized institutions in Hong Kong. It expects all authorized institutions to critically assess the need for implementing an STDB having regard to their risk exposure and taking into account the principles stipulated in the HKAB STDB Guideline. For locally incorporated authorized institutions, the assessment report should be endorsed by the board of directors. For foreign bank branches, the assessment should be conducted under the scrutiny of their head office or regional headquarters.
Keywords: Asia Pacific, Hong Kong, Banking, Cyber Risk, Secure Tertiary Data Backup, Operational Resilience, Cyber Resilience, STDB Guideline, HKMA
Previous ArticleECB Amends Rule on Reporting of Supervisory Financial Information
The Board of Governors of the Federal Reserve System (FED) published the final rule that amends Regulation I to reduce the quarterly reporting burden for member banks by automating the application process for adjusting their subscriptions to the Federal Reserve Bank capital stock, except in the context of mergers.
The European Banking Authority (EBA) published its assessment of risks through the quarterly Risk Dashboard and the results of the Autumn edition of the Risk Assessment Questionnaire (RAQ).
The Malta Financial Services Authority (MFSA) updated the guidelines on supervisory reporting requirements under the reporting framework 3.0.
The Hong Kong Monetary Authority (HKMA) published a circular, along with the reporting form and instructions, for self-assessment, by authorized institutions, of compliance with the Code of Banking Practice 2021.
The Financial Conduct Authority (FCA) decided to register European DataWarehouse Ltd and SecRep Limited as securitization repositories under the UK Securitization Regulation, with effect from January 17, 2022.
The European Commission (EC) published the Delegated Regulation 2022/25, which supplements the Investment Firms Regulation (IFR or Regulation 2019/2033) with respect to the regulatory technical standards specifying the methods for measuring the K-factors referred to in Article 15 of the IFR.
The Bank of International Settlements (BIS) published a paper that assesses the ways in which platform-based business models can affect financial inclusion, competition, financial stability and consumer protection.
The Central Bank of Egypt (CBE) published a circular with instructions on emergency liquidity assistance to banks that are unable to meet their liquidity requirements.
The European Supervisory Authorities (ESAs) published the list of identified financial conglomerates for 2021.
The Australian Prudential Regulation Authority (APRA) updated the list of authorized deposit-taking institutions, granting license to Barclays Bank PLC and Crédit Agricole Corporate and Investment Bank to operate as foreign authorized deposit-taking institutions under the Banking Act 1959.