RBNZ announced that it is strengthening its efforts to enhance resilience of the financial system from cyber threats, including developing risk management guidance and promoting information-sharing in collaboration with industry and other public organizations. Additionally, RBNZ published a bulletin/paper that examines the concept of cyber resilience and estimates the potential costs of cyber risk for the financial system in New Zealand. With the frequency and severity of cyber-security incidents on the rise, the paper highlights the importance of the financial sector remaining vigilant and managing cyber risks effectively.
The paper published by RBNZ draws on two internationally recognized methods to shed more light on the potential cost that cyber risk poses to the banking and insurance sectors in New Zealand. The first method is a bottom-up approach that uses firm-specific data from abroad, which is then extrapolated to New Zealand. The second method uses top-down analysis, linking the cost of cyber incidents to GDP. The two methods produce remarkably similar results for New Zealand. The estimated average cost of cyber incidents is likely to be about NZD 104 million per annum for the banking industry and NZD 38 million for the insurance industry. To put this cost in context, it is the equivalent of 2% to 3% of annual profits for the banking and insurance sectors. According to the value-at-risk method, in any given year there is a 5% chance that the costs could rise beyond NZD 2 billion for the banking sector and more than NZD 300 million for the insurance sector, nearly equivalent to 34% (25%) of the annual net profits for banks and 25% of the annual net profits for insurers.
The analysis presented in the paper shows that the financial cost from cyber incidents is real and has the potential to be significant. Additional costs that have not been captured by the two approaches used in this paper include the loss of confidence in the financial system, the resulting impact on innovation and the adoption of new technological developments, and the diversion of resources away from productivity enhancing investment. Furthermore the country’s cyber-security agency CERT NZ found that more than 60% of the cyber-attacks on the New Zealand organizations in 2018 targeted firms in the financial and insurance services sector. Therefore, managing cyber risk and building cyber resilience should be of importance to the financial sector as well as its regulators.
Keywords: Asia Pacific, New Zealand, Banking, Insurance, Cyber Risk, Cyber Resilience, Fintech, Value-at-Risk, Bottom Up Approach, Top Down Analysis, RBNZ
Previous ArticleMAS Amends Regulation on Reporting of Derivatives Contracts
The European Commission (EC) published the Delegated Regulation 2022/786 with regard to the liquidity coverage requirements for credit institutions under the Capital Requirements Regulation (CRR).
The European Banking Authority (EBA) published the final draft regulatory technical standards specifying the criteria to identify shadow banking entities for the purposes of reporting large exposures.
The European Insurance and Occupational Pensions Authority (EIOPA) published a report assessing insurers' exposure to physical climate change risks
The Network for Greening the Financial System (NGFS) published two reports to aid central banks and regulators in their oversight of the financial sector and in their central bank operations
The European Commission (EC) published the results of a public consultation, held in October 2021, on the review of the Web Accessibility Directive.
The Monetary Authority of Singapore (MAS) and the SC-STS are jointly consulting, until June 10, 2022, on setting adjustment spreads for the conversion of legacy SOR contracts to SORA reference rate.
The Office of the Superintendent of Financial Institutions (OSFI) published the strategic plan for 2022-2025 and the departmental plan for 2022-23.
The European Banking Authority (EBA) is consulting, until August 31, 2022, on the draft implementing technical standards specifying requirements for the information that sellers of non-performing loans (NPLs) shall provide to prospective buyers.
The European Council and the Parliament reached an agreement on the revised Directive on security of network and information systems (NIS2 Directive).
The European Banking Authority (EBA) published the final draft regulatory technical standards specifying information that crowdfunding service providers shall provide to investors on the calculation of credit scores and prices of crowdfunding offers.