Featured Product

    HKMA Enhances Cybersecurity Fortification Initiative

    November 03, 2020

    HKMA launched an upgraded Cybersecurity Fortification Initiative (CFI) 2.0, following industry consultation. Changes have been made to reflect the latest developments in overseas cyber practices, with substantial efforts to be made to encourage cyber threat intelligence sharing across the industry. The initiative is underpinned by three pillars: the Cyber Resilience Assessment Framework (C-RAF), the Professional Development Program (PDP), and the Cyber Intelligence Sharing Platform (CISP). The upgraded initiative will come into effect January 01, 2021 and will be implemented through a phased approach.

    HKMA recently completed a review of the Cybersecurity Fortification Initiative, which was launched in 2016 to raise enhance cyber resilience of the banking system in Hong Kong. The results of the review show that the banking industry is strongly supportive of the Cybersecurity Fortification Initiative. More than 90% of banks found the C-RAF useful, especially in identifying previously unrecognized gaps. All the banks found iCAST helpful in preparing for cyber-attacks. Taking into account the industry feedback during the review, the Cybersecurity Fortification Initiative has been further enhanced to streamline the cyber resilience assessment process. CFI 2.0 has been developed after extensive consultation with the banking industry. Many of the comments received during the consultation have been taken on board. Moreover, recent international sound practices on cyber incident response and recovery have been incorporated into the enhanced control principles under C-RAF. Another enhancement to C-RAF is the introduction of Blue team requirements for Intelligence-led Cyber Attack Simulation Testing (iCAST) to measure the effectiveness of detection, response, and recovery functions of authorized institutions. More flexibility will be allowed for authorized institutions to leverage the results of similar cyber resilience assessments performed by their banking groups or headquarters HKMA has also put forward a series of recommendations to the Hong Kong Association of Banks to make the CISP more user-friendly. 

    HKMA plans to adopt a phased approach to the implementation of C-RAF 2.0. Authorized institutions will be divided into three groups similar to those adopted for C-RAF 1.0. Group 1 will cover all major retail banks, selected foreign bank branches, and new authorized institutions that have not undertaken the C-RAF assessments before. The remaining entities will be included in Group 2 or 3, depending on their scale of operation and cyber-risk profile. HKMA will inform authorized institutions individually of their assigned grouping. The timeline for completing the Inherent Risk Assessment and Maturity Assessment is end of September 2021 for Group 1, end of June 2022 for Group 2, and end of March 2023 for Group 3. For iCAST (applicable to authorized institutions with inherent risk level assessed to be “medium” or “high”), the timelines are end of June 2022 for Group 1, end of March 2023 for Group 2, and end of December 2023 for Group 3.

     

    Keywords: Asia Pacific, Hong Kong, Banking, CFI, C-RAF, Cyber Risk, CFI 2.0, iCAST, HKMA

    Related Articles
    News

    HKMA Finalizes Policy Modules on Group-Wide Approach and Remuneration

    The Hong Kong Monetary Authority (HKMA) revised the Supervisory Policy Manual module CG-5 that sets out guidelines on a sound remuneration system for authorized institutions.

    July 29, 2021 WebPage Regulatory News
    News

    EBA Guide to Monitor Threshold for Intermediate Parent Undertakings

    The European Banking Authority (EBA) published the final guidelines on the monitoring of the threshold and other procedural aspects on the establishment of intermediate parent undertakings in European Union (EU), as laid down in the Capital Requirements Directive (CRD).

    July 28, 2021 WebPage Regulatory News
    News

    PRA Finalizes Approach to Supervision of International Banks

    In a recent Market Notice, the Bank of England (BoE) confirmed that green gilts will have equivalent eligibility to existing gilts in its market operations.

    July 26, 2021 WebPage Regulatory News
    News

    FCA Issues PS21/9 on Implementation of Investment Firms Regime

    The Financial Conduct Authority (FCA) published the policy statement PS21/9 on implementation of the Investment Firms Prudential Regime.

    July 26, 2021 WebPage Regulatory News
    News

    EBA Proposes Regulatory Standards to Identify Shadow Banking Entities

    The European Banking Authority (EBA) proposed regulatory technical standards that set out criteria for identifying shadow banking entities for the purpose of reporting large exposures.

    July 26, 2021 WebPage Regulatory News
    News

    IOSCO Proposes Recommendations on ESG Ratings and Data Providers

    The Board of the International Organization of Securities Commissions (IOSCO) proposed a set of recommendations on the environmental, social, and governance (ESG) ratings and data providers.

    July 26, 2021 WebPage Regulatory News
    News

    ESMA Group Issues Recommendations on RFR Switch in Interdealer Market

    The European Securities and Markets Authority (ESMA) published recommendations from the Working Group on Euro Risk-Free Rates (RFR) on the switch to risk-free rates in the interdealer market.

    July 26, 2021 WebPage Regulatory News
    News

    ECB Study Assesses Impact of Basel III Finalization Package

    The European Central Bank (ECB) published a paper as well as an article in the July Macroprudential Bulletin, both of which offer insights on the assessment of the impact of Basel III finalization package on the euro area.

    July 26, 2021 WebPage Regulatory News
    News

    ISDA Finds FRTB Results in Higher Capital Charges for Carbon Trading

    The International Swaps and Derivatives Association (ISDA) published a paper that explores the impact of the Fundamental Review of the Trading Book (FRTB) on the trading of carbon certificates.

    July 26, 2021 WebPage Regulatory News
    News

    PRA Updates Remuneration Policy Statement Templates and Tables

    The Prudential Regulation Authority (PRA) published the remuneration policy self-assessment templates and tables on strengthening accountability.

    July 26, 2021 WebPage Regulatory News
    RESULTS 1 - 10 OF 7307