Featured Product

    BIS on Impact of Increasing Use of Cloud Technology on Cyber Risk

    May 20, 2020

    BIS published a working paper that examines the drivers of cyber risk, especially in context of the cloud services. The paper highlights that the use of cloud services is associated with lower costs, especially when cyber incidents are relatively small. However, as cloud connectivity increases and cloud providers become systemically important, cloud dependence is also likely to increase tail risks. The study finds that developing technological skills helps firms mitigate the costs of cyber incidents, as does more reliance on cloud services.

    Cloud technology can reduce IT costs, improve resilience, and enable firms to scale better. However, the technology strengthens interdependence across firms that have shared exposures to similar (or even the same) cloud service providers. This technology enables firms to rent computing power and storage from service providers, which gives them flexibility in their storage costs. However, all of this comes with some risks, as it involves firms inherently placing a lot of trust in vendors of cloud technology. The presence of a market failure through information asymmetry between buyer and vendor is rather well-recognized. Often users of cloud services may not know the exact location of their data or the other sources of the data collectively stored with theirs. The financial sector experiences the highest number of cyber incidents (especially of a malicious type, privacy and lost data incidents). However, banks and insurance companies incur more limited losses relative to other sectors, likely due to the effects of regulation and higher investment in cyber security. Additionally, crypto-related activities, which are largely unregulated, are associated with higher losses. 

    Nevertheless, cloud computing can be a target for cyber criminals and could pose a concern in terms of systemic risk. Providers of cloud services, undoubtedly have some of the best cyber-security experts and ultimately provide highly secure services, but tail risks could lead to substantial losses and potentially bring the economy to a halt. Moreover, the market for cloud services is highly concentrated and there are warnings about increased homogeneity and the greater risk of single points of failure. Through shared software, hardware, and vendors, incidents could, in principle, spread more quickly, leading to higher overall costs. The impact of the use of cloud services in the case of cyber attacks can thus go both ways and clearly depends on the benefit-risk analysis. Based on this, the authors have made a hypothesis. A higher dependency on cloud technologies can alter losses from cyber events. However, the net benefit depends on the connectivity of the cyber incidents and the size of the shock.

     

    Related Links

    Keywords: International, Banking, Insurance, Securities, Cloud Computing, Cyber Risk, Systemic Risk, Operational Risk, BIS

    Featured Experts
    Related Articles
    News

    EBA Finalizes Remuneration Standards for Investment Firms in EU

    EBA finalized the two sets of draft regulatory technical standards on the identification of material risk-takers and on the classes of instruments used for remuneration under the Investment Firms Directive (IFD).

    January 21, 2021 WebPage Regulatory News
    News

    ECA Recommends Actions to Enhance Resolution Planning for Banks

    EC published, in the Official Journal of the European Union, a notification that the European Court of Auditors (ECA) has published a special report on resolution planning in the Single Resolution Mechanism.

    January 20, 2021 WebPage Regulatory News
    News

    BoE Publishes Key Elements of the 2021 Stress Testing for Banks in UK

    BoE published a scenario against which it will be stress testing banks in 2021, in addition to setting out the key elements of the 2021 stress test, guidance on the 2021 stress test, and the variable paths for the 2021 stress test.

    January 20, 2021 WebPage Regulatory News
    News

    PRA Proposes Rules on Identity Verification of Depositor Protection

    PRA published a consultation paper (CP3/21) proposes rules regarding the timing of identity verification required for eligibility of depositor protection under the Financial Services Compensation Scheme (FSCS).

    January 20, 2021 WebPage Regulatory News
    News

    FSB Publishes Work Program for 2021

    FSB published the work program for 2021, which reflects a strategic shift in priorities in the COVID-19 environment.

    January 20, 2021 WebPage Regulatory News
    News

    FCA Issues Update on Move to New Data Collection Platform

    FCA announced that 50% firms have started using the new data collection platform RegData, which is slated to replace the existing platform known Gabriel.

    January 20, 2021 WebPage Regulatory News
    News

    Bundesbank Publishes Derivation Rules for Reporting by Banks

    Bundesbank published Version 5.0 of the derivation rules for completeness check at the form level, with respect to the data quality of the European harmonized reporting system.

    January 19, 2021 WebPage Regulatory News
    News

    FED Revises Capital Planning and Stress Testing Requirements for Banks

    FED finalized a rule that updates capital planning requirements to reflect the new framework from 2019 that sorts large banks into categories, with requirements that are tailored to the risks of each category.

    January 19, 2021 WebPage Regulatory News
    News

    ECB Releases Results of Bank Lending Survey for Fourth Quarter of 2020

    ECB published results of the quarterly lending survey conducted on 143 banks in the euro area.

    January 19, 2021 WebPage Regulatory News
    News

    ESAs Publish Reporting Templates for Financial Conglomerates

    ESAs published the final draft implementing technical standards on reporting of intra-group transactions and risk concentration of financial conglomerates subject to the supplementary supervision in EU.

    January 18, 2021 WebPage Regulatory News
    RESULTS 1 - 10 OF 6484