The Australian Prudential Regulation Authority (APRA) recently completed two pilot initiatives in its 2020-2024 Cyber Security Strategy, which was published in November 2020. These pilots are a technology resilience data collection and an independent assessment of a pilot set of entities’ compliance with CPS 234, the prudential standard on information security. APRA is now publishing insights gained from the two pilots and from its supervisory activities. The insights reinforce APRA’s view that boards need to strengthen their ability to oversee cyber resilience.
APRA expects boards to have the same level of confidence in reviewing and challenging information security issues as they do when governing other business issues. The pilot independent CPS 234 assessment involved a small sample of banking, insurance, and superannuation entities undergoing an independent assessment against the requirements of CPS 234. The results of the two pilots, together with the outcomes of recent supervisory activities, led APRA to conclude that boards need to play a more active role in:
- Reviewing and challenging information reported by management on cyber resilience
- Ensuring their entities can recover from high-impact cyber-attacks (for example, ransomware)
- Ensuring information security controls are effective across the supply chain
APRA notes that it is ultimately the board’s responsibility to ensure that management is fully across the cyber threat they face and, where necessary, takes appropriate action to ensure its entity remains cyber resilient. Over the next couple of years, APRA will continue to roll out the CPS 234 independent assessment process for the remaining entities across the banking, superannuation and insurance industries. APRA intends to share relevant insights with industry from its data collection and other strategic initiatives on cyber security, with a view to lifting practices and enhancing cyber resilience throughout the financial sector.
Related Link: APRA Insights from Pilots
Keywords: Asia Pacific, Australia, Banking, Cyber Risk, CPS 234, Cyber Security Strategy, Governance, ESG, APRA
Previous ArticleEIOPA Publishes Report on Use of Capital Add-Ons Under Solvency II
The Bank for International Settlements (BIS) published a paper that studies impact of fintech lending on credit access for small businesses in U.S.
The Prudential Regulation Authority (PRA) issued the policy statement PS8/22 to amend the Own Funds and Eligible Liabilities (CRR) Part of the PRA Rulebook and update the supervisory statement SS7/13 titled "Definition of capital (CRR firms).
The European Banking Authority (EBA) launched the EU-wide transparency exercise for 2022, with results of the exercise expected to be published at the beginning of December, along with the annual Risk Assessment Report.
The Single Resolution Board (SRB) welcomed the adoption of the review of the Capital Requirements Regulation, or CRR, also known as the "CRR quick-fix."
The European Commission (EC) recently adopted the Delegated Regulation 2022/1622, which sets out the regulatory technical standards to specify the countries that constitute advanced economies for the purpose of specifying risk-weights for the sensitivities to equity.
The European Banking Authority (EBA) published the final draft regulatory technical standards specifying and, where relevant, calibrating the minimum performance-related triggers for simple.
The European Central Bank (ECB) is undertaking the integrated reporting framework (IReF) project to integrate statistical requirements for banks into a standardized reporting framework that would be applicable across the euro area and adopted by authorities in other EU member states.
The European Banking Authority (EBA) has been awarded the top European Standard for its environmental performance under the European Eco-Management and Audit Scheme (EMAS).
The Monetary Authority of Singapore (MAS) set out the Financial Services Industry Transformation Map 2025 and, in collaboration with the SGX Group, launched ESGenome.
The Basel Committee on Banking Supervision met, shortly after a gathering of the Group of Central Bank Governors and Heads of Supervision (GHOS), the oversight body of BCBS.