HKMA Expects Banks to Assess Need for Secure Tertiary Data Backup
HKMA issued a circular requesting all authorized institutions to critically assess the need for setting up a secure tertiary data backup (STDB) to counter the risk of destructive cyber-attacks. All retail banks and foreign bank branches with significant operations in Hong Kong are expected to submit a report containing the result of their assessment to HKMA by November 30, 2021. HKMA will inform institutions individually if they are required to submit the report and will provide them with details of what information needs to be covered by the report.
HKMA had invited the Hong Kong Association of Banks (HKAB) to develop guidelines on secure tertiary data backup that are appropriate for the banking landscape in Hong Kong. In response to the HKMA call, HKAB had formed an STDB Taskforce to oversee the development of the guidelines. After extensive consultation with member institutions, HKAB issued the “Secure Tertiary Data Backup Guideline” on April 30, 2021. The STDB Guideline provides guidance to banks on the factors they need to consider in deciding whether to set up an STDB and what implementation issues they need to overcome in ensuring the effectiveness of the STDB. The Guideline covers eight high-level principles grouped under the headings of Governance, Design, and Data Restoration. HKMA considers STDB an effective measure to enhance cyber resilience and data security of authorized institutions in Hong Kong. It expects all authorized institutions to critically assess the need for implementing an STDB having regard to their risk exposure and taking into account the principles stipulated in the HKAB STDB Guideline. For locally incorporated authorized institutions, the assessment report should be endorsed by the board of directors. For foreign bank branches, the assessment should be conducted under the scrutiny of their head office or regional headquarters.
Keywords: Asia Pacific, Hong Kong, Banking, Cyber Risk, Secure Tertiary Data Backup, Operational Resilience, Cyber Resilience, STDB Guideline, HKMA
Previous Article
ECB Amends Rule on Reporting of Supervisory Financial InformationRelated Articles
EBA Clarifies Use of COVID-19-Impacted Data for IRB Credit Risk Models
The European Banking Authority (EBA) published four draft principles to support supervisory efforts in assessing the representativeness of COVID-19-impacted data for banks using the internal ratings based (IRB) credit risk models.
BIS Hub Updates Work Program for 2022, Announces New Projects
The Bank for International Settlements (BIS) Innovation Hub updated its work program, announcing a set of projects across various centers.
US Senate Members Seek Details on SEC Proposed Climate Disclosure Rule
Certain members of the U.S. Senate Committee on Banking, Housing, and Urban Affairs issued a letter to the Securities and Exchange Commission (SEC)
EIOPA Consults on Review of Securitization Framework in Solvency II
The European Insurance and Occupational Pensions Authority (EIOPA) published a consultation paper on the advice on the review of the securitization prudential framework in Solvency II.
UK Authorities Issue Regulatory and Reporting Updates for Banks
The Prudential Regulation Authority (PRA) issued a statement on PRA buffer adjustment while the Bank of England (BoE) published a notice on the statistical reporting requirements for banks.
BaFin Consults on Resolvability Requirements for Resolution Planning
The Federal Financial Supervisory Authority of Germany (BaFin) proposed to amend the “Capital Investment Conduct And Organization Ordinance” and issued a draft circular on the minimum resolvability requirements for resolution planning.
EBA Consults on Certain Standards and Guidelines Under CRR and BRRD
The European Banking Authority (EBA) proposed guidelines, for the resolution authorities, on the publication of the write-down and conversion and bail-in exchange mechanic, with the comment period ending on September 07, 2022.
OJK Publishes Regulatory Updates for Financial Sector Entities
The Financial Services Authority of Indonesia (OJK) is strengthening cooperation with the Australian Prudential Regulation Authority (APRA) and the Japanese Financial Services Agency (JFSA)
EU Publishes Rules on DLT and Data Governance
The European Parliament and the Council published Regulation 2022/868 on European data governance (Data Governance Act).
EBA Publishes Phase 2 of Reporting Framework 3.2
The European Banking Authority (EBA) published phase 2 of its reporting framework 3.2. The technical package supports the implementation of the updated reporting framework by providing standard specifications