ECB Publishes Guidance on Role of White Team in TIBER-EU Test
ECB published guidance on the roles and responsibilities of the White Team in a Threat Intelligence-Based Ethical Red Teaming (TIBER-EU) test. The guidance covers the roles and responsibilities of the White Team during the preparation, testing, and closure phases of a TIBER-EU test; the composition of the White Team; the requisite skills and experience of the White Team; and the organizational aspects of the White Team.
The TIBER-EU White Team Guidance is an integral part of the TIBER-EU Framework. The TIBER-EU framework enables European and national authorities to work with financial infrastructures and institutions to put in place a program to test and improve their resilience against sophisticated cyber attacks. TIBER-EU is an instrument for red team testing, designed for use by core financial infrastructures, whether at national or at European level, which can also be used by any type or size of entity across the financial and other sectors. TIBER-EU is designed to be adopted by the relevant authorities in any jurisdiction, on a voluntary basis and from a variety of perspectives, as a supervisory or oversight tool, for financial stability purposes, or as a catalyst. So far, ECB has published guidance on implementing the TIBER-EU Framework and Guidelines for the TIBER-EU Services Procurement Guidelines.
The White Team is the team—within the entity being tested—that is responsible for the overall planning and management of the test, in accordance with the TIBER-EU Framework. The members of the White Team are the only people within the entity being tested that know that a TIBER-EU test is taking place. The White Team must ensure that the TIBER-EU test is conducted in a controlled manner, with appropriate risk management controls in place, while maximizing the learning experience for the entity. For this, the White Team must closely cooperate with the TIBER Cyber Team (TCT) from the respective authority.
Related Link: TIBER-EU White Team Guidance (PDF)
Keywords: Europe, EU, Banking, Securities, PMI, Cyber Risk, Cyber Resilience, TIBER-EU, White Team, ECB
Previous Article
ESRB Dashboard Examines Systemic Risks in EURelated Articles
OSFI Issues Phase2 Consultation on Climate Scenario Exercise for Banks
The Office of the Superintendent of Financial Institutions (OSFI) recently announced a consultation on the second phase of the Standardized Climate Scenario Exercise (SCSE) for banks and other financial institutions it regulates in Canada.
BIS and Central Banks Experiment with GenAI to Assess Climate Risks
A recent report from the Bank for International Settlements (BIS) Innovation Hub details Project Gaia, a collaboration between the BIS Innovation Hub Eurosystem Center and certain central banks in Europe
Nearly 25% G-SIBs Commit to Adopting TNFD Nature-Related Disclosures
Nature-related risks are increasing in severity and frequency, affecting businesses, capital providers, financial systems, and economies.
Singapore to Mandate Climate Disclosures from FY2025
Singapore recently took a significant step toward turning climate ambition into action, with the introduction of mandatory climate-related disclosures for listed and large non-listed companies
SEC Finalizes Climate-Related Disclosures Rule
The U.S. Securities and Exchange Commission (SEC) has finalized the long-awaited rule that mandates climate-related disclosures for domestic and foreign publicly listed companies in the U.S.
EBA Proposes Standards Related to Standardized Credit Risk Approach
The European Banking Authority (EBA) has been taking significant steps toward implementing the Basel III framework and strengthening the regulatory framework for credit institutions in the EU
US Regulators Release Stress Test Scenarios for Banks
The U.S. regulators recently released baseline and severely adverse scenarios, along with other details, for stress testing the banks in 2024. The relevant U.S. banking regulators are the Federal Reserve Bank (FED), the Federal Deposit Insurance Corporation (FDIC), and the Office of the Comptroller of the Currency (OCC).
Asian Governments Aim for Interoperability in AI Governance Frameworks
The regulatory landscape for artificial intelligence (AI), including the generative kind, is evolving rapidly, with governments and regulators aiming to address the challenges and opportunities presented by this transformative technology.
EBA Proposes Operational Risk Standards Under Final Basel III Package
The European Union (EU) has been working on the final elements of Basel III standards, with endorsement of the Banking Package and the publication of the European Banking Authority (EBA) roadmap on Basel III implementation in December 2023.
EFRAG Proposes XBRL Taxonomy and Standard for Listed SMEs Under ESRS
The European Financial Reporting Advisory Group (EFRAG), which plays a crucial role in shaping corporate reporting standards in European Union (EU), is seeking comments, until May 21, 2024, on the Exposure Draft ESRS for listed SMEs.