Featured Product

    ESRB Publishes Report on Systemic Cyberattacks

    February 19, 2020

    ESRB published a report that explores systemic implications of cyber incidents, such as cyberattacks. The report summarizes the latest estimates of the costs of cyber incidents and shows that a cyber incident could evolve into a systemic cyber crisis that threatens financial stability. It also describes when an incident might turn into a “systemic cyber incident” that could threaten financial stability. Finally, the report outlines policy areas that merit further exploration, with the ESRB announcing that it intends to explore some of the potential systemic mitigants in its future work.

    The report highlights that cyber risk is characterized by three features that, when combined, make it fundamentally different from other sources of operational risk: the speed of its propagation, the scale of its propagation, and the potential intent of perpetrators. ESRB has developed an analytical framework to assess how cyber risk can become a source of systemic risk to the financial system. The four stages of this conceptual model (context, shock, amplification, systemic event) facilitate a systematic analysis of how a cyber incident can grow from operational disruption into a systemic crisis. The framework could assist in analyzing systemic vulnerabilities that amplify the shock of a cyber incident and in understanding at which point a cyber incident may become systemic. ESRB also surveyed its membership to form a view on common individual vulnerabilities across ESRB jurisdictions. Combining these elements, ESRB has considered a number of historical and hypothetical scenarios. It used these scenarios to try to understand the distinction between severe operational disruption to the financial system and a systemic crisis.

    The ESRB analysis illustrates how a cyber incident could, under certain circumstances, rapidly escalate from an operational outage to a liquidity crisis. Standard-setting bodies, national and international authorities, and industry groups are combining their efforts to mitigate cyber risks. To further mitigate the risk of a systemic cyber incident materializing, more work is required to address system vulnerabilities and reduce the potential for widespread disruption through amplification channels. The scenario analysis in this report reveals that the loss of confidence in the financial system plays a key role in a cyber incident developing into a systemic crisis. The following are a number of policy areas that merit further exploration:

    • Given the speed and scale at which such a cyber incident may unfold, rapid coordination between stakeholders and a consistent and clear communication from authorities may be required to shore up confidence. Different ongoing workstreams could be leveraged to achieve this goal.
    • Effective restoration of key economic functions requires planning, including agreeing on a clear division of tasks between industry and authorities and between (technical) incident management and (financial) consequence management. This may also include reflections on central bank emergency communications, interventions, or assistance when a cyber crisis becomes a financial stability crisis.
    • Cyber-equivalent of capital buffers is preparedness and resilience. Thus, the operationalization of systemic resilience mechanisms such as data vaulting, among other things, merits further exploration. This is of particular importance as many recovery and resolution plans are contingent on the essential data being available or recoverable.

    ESRB intends to explore some of the potential systemic mitigants in future work. Taking stock of the findings in this report, ESRB intends to leverage its broad institutional composition and network to evaluate the costs and benefits of different systemic mitigants going forward.


    Related Links

    Keywords: Europe, EU, Banking, Insurance, Securities, Cyber Risk, Systemic Risk, Operational Risk, Financial Stability, ESRB

    Featured Experts
    Related Articles

    EBA Finalizes Templates for One-Off Climate Risk Scenario Analysis

    The European Banking Authority (EBA) has published the final templates, and the associated guidance, for collecting climate-related data for the one-off Fit-for-55 climate risk scenario analysis.

    November 28, 2023 WebPage Regulatory News

    EBA Mulls Inclusion of Environmental & Social Risks to Pillar 1 Rules

    The European Banking Authority (EBA) recently published a report that recommends enhancements to the Pillar 1 framework, under the prudential rules, to capture environmental and social risks.

    October 31, 2023 WebPage Regulatory News

    BCBS Consults on Disclosure of Crypto-Asset Exposures of Banks

    As a follow on from its prudential standard on the treatment of crypto-asset exposures, the Basel Committee on Banking Supervision (BCBS) proposed disclosure requirements for crypto-asset exposures of banks.

    October 19, 2023 WebPage Regulatory News

    BCBS and EBA Publish Results of Basel III Monitoring Exercise

    The Basel Committee on Banking Supervision (BCBS) and the European Banking Authority (EBA) have published results of the Basel III monitoring exercise.

    October 18, 2023 WebPage Regulatory News

    PRA Updates Timeline for Final Basel III Rules, Issues Other Updates

    The Prudential Regulation Authority (PRA) recently issued a few regulatory updates for banks, with the updated Basel implementation timelines being the key among them.

    October 18, 2023 WebPage Regulatory News

    US Treasury Sets Out Principles for Net-Zero Financing

    The U.S. Department of the Treasury has recently set out the principles for net-zero financing and investment.

    October 17, 2023 WebPage Regulatory News

    EC Launches Survey on G7 Principles on Generative AI

    The European Commission (EC) launched a stakeholder survey on the draft International Guiding Principles for organizations developing advanced artificial intelligence (AI) systems.

    October 14, 2023 WebPage Regulatory News

    ISSB Sustainability Standards Expected to Become Global Baseline

    The finalization of the two sustainability disclosure standards—IFRS S1 and IFRS S2—is expected to be a significant step forward in the harmonization of sustainability disclosures worldwide.

    September 18, 2023 WebPage Regulatory News

    IOSCO, BIS, and FSB to Intensify Focus on Decentralized Finance

    Decentralized finance (DeFi) is expected to increase in prominence, finding traction in use cases such as lending, trading, and investing, without the intermediation of traditional financial institutions.

    September 18, 2023 WebPage Regulatory News

    BCBS Assesses NSFR and Large Exposures Rules in US

    The Basel Committee on Banking Supervision (BCBS) published reports that assessed the overall implementation of the net stable funding ratio (NSFR) and the large exposures rules in the U.S.

    September 14, 2023 WebPage Regulatory News
    RESULTS 1 - 10 OF 8938