The European Systemic Risk Board (ESRB) published a report that highlights the need for macro-prudential tools to boost cyber resilience.
The report builds on the previous work by ESRB to prevent and mitigate risks to financial stability in the event of a cyber incident, highlighting the need to boost cyber resilience. In 2022, ESRB worked within the context of a substantially heightened cyber threat environment across Europe. ESRB published a recommendation for the establishment of a pan-European systemic cyber incident coordination framework and issued an accompanying report on mitigating systemic cyber risk, which describes how this framework would facilitate an effective response to a major cyber incident. The report also complements the work of the Joint Committee of the European Supervisory Authorities (ESAs) undertaken within the framework of the Digital Operational Resilience Act (DORA), which aims to improve cyber resilience at the level of individual entities. Through this report, ESRB encourages authorities across the European Union to focus on three key areas:
- Cyber Resilience Scenario Testing (CyRST), which is an analytical tool designed to assist authorities in testing the response and recovery capacity of the financial system in severe but plausible scenarios involving a cyber incident, in evaluating the impact of these scenarios on financial and operational stability, and in identifying the areas where further work is required to mitigate cyber risk. ESRB encourages authorities to use the CyRST approach pilot system-wide as soon as possible. Such pilots can complement other analytical tools that the authorities might be using and deepen their understanding of the risks to system-wide cyber resilience.
- Systemic Impact Tolerance Objective (SITO), which is also an analytical tool developed to identify and measure the impact of cyber incidents on the financial system and to evaluate when such incidents are likely to breach tolerance levels and cause significant disruption. ESRB advocates the use of SITOs and will continue to transition from a conceptual approach to a practical basis for implementing them. ESRB will identify a key economic function where disruptions have cross-border implications and define appropriate SITOs at EU level to ensure consistency across the region/sector and authorities. ESRB recognizes that where disruptions have no or few cross-border implications, SITOs may differ across jurisdictions to reflect national specificities.
- Review of financial crisis management tools, which investigated whether these tools are sufficient for adequately responding to system-wide cyber incidents. ESRB will consider which operational policy tools are most effective in responding to a system-wide cyber incident and identify gaps across operational and financial policy tools. The report finds that the effectiveness of existing financial crisis management tools in responding to a cyber incident depends on the severity of the impact on the financial system and on how fast it spreads.
Going forward, ESRB will continue to work on an EU-wide strategy to help mitigate systemic cyber risk. ESRB will act as a hub to share progress reports and good practices and will update the conceptual approach to Cyber Resilience Scenario Testing and Systemic Impact Tolerance Objectives to integrate the experience and insights gained from pilot projects. ESRB will also analyze operational financial crisis management tools for systemic cyber crises.
Keywords: Europe, EU, Banking, Cyber Resilience, Cyber Incident, Cyber Risk, Regtech, DORA, Operational Resilience, Systemic Risk, ESRB
Across 35 years in banking, Blake has gained deep insights into the inner working of this sector. Over the last two decades, Blake has been an Operating Committee member, leading teams and executing strategies in Credit and Enterprise Risk as well as Line of Business. His focus over this time has been primarily Commercial/Corporate with particular emphasis on CRE. Blake has spent most of his career with large and mid-size banks. Blake joined Moody’s Analytics in 2021 after leading the transformation of the credit approval and reporting process at a $25 billion bank.
Previous ArticleEC Launches Regulatory Sandbox for Blockchain Projects
The finalization of the two sustainability disclosure standards—IFRS S1 and IFRS S2—is expected to be a significant step forward in the harmonization of sustainability disclosures worldwide.
Decentralized finance (DeFi) is expected to increase in prominence, finding traction in use cases such as lending, trading, and investing, without the intermediation of traditional financial institutions.
The Basel Committee on Banking Supervision (BCBS) published reports that assessed the overall implementation of the net stable funding ratio (NSFR) and the large exposures rules in the U.S.
At the global level, supervisory efforts are increasingly focused on addressing climate risks via better quality data and innovative use of technologies such as generative artificial intelligence (AI) and blockchain.
The finalization of the IFRS sustainability disclosure standards in late June 2023 has brought to the forefront the themes of the harmonization of sustainability disclosures
The European Banking Authority (EBA) recently issued several regulatory publications impacting the banking sector.
The Basel Committee on Banking Supervision (BCBS) launched a consultation on revisions to the core principles for effective banking supervision, with the comment period ending on October 06, 2023.
The U.S. banking agencies (FDIC, FED, and OCC) recently proposed rules implementing the final Basel III reforms, also known as the Basel III Endgame.
The Financial Stability Board (FSB) recently published the second annual progress report on the July 2021 roadmap to address climate-related financial risks.
The recognition of climate change as a systemic risk to the global economy has further intensified regulatory and supervisory focus on monitoring of the environmental, social, and governance (ESG) risks.