Featured Product

    RBNZ to Address Cyber Risk Through Risk Management Guidance

    February 25, 2020

    RBNZ announced that it is strengthening its efforts to enhance resilience of the financial system from cyber threats, including developing risk management guidance and promoting information-sharing in collaboration with industry and other public organizations. Additionally, RBNZ published a bulletin/paper that examines the concept of cyber resilience and estimates the potential costs of cyber risk for the financial system in New Zealand. With the frequency and severity of cyber-security incidents on the rise, the paper highlights the importance of the financial sector remaining vigilant and managing cyber risks effectively.

    The paper published by RBNZ draws on two internationally recognized methods to shed more light on the potential cost that cyber risk poses to the banking and insurance sectors in New Zealand. The first method is a bottom-up approach that uses firm-specific data from abroad, which is then extrapolated to New Zealand. The second method uses top-down analysis, linking the cost of cyber incidents to GDP. The two methods produce remarkably similar results for New Zealand. The estimated average cost of cyber incidents is likely to be about NZD 104 million per annum for the banking industry and NZD 38 million for the insurance industry. To put this cost in context, it is the equivalent of 2% to 3% of annual profits for the banking and insurance sectors. According to the value-at-risk method, in any given year there is a 5% chance that the costs could rise beyond NZD 2 billion for the banking sector and more than NZD 300 million for the insurance sector, nearly equivalent to 34% (25%) of the annual net profits for banks and 25% of the annual net profits for insurers.

    The analysis presented in the paper shows that the financial cost from cyber incidents is real and has the potential to be significant. Additional costs that have not been captured by the two approaches used in this paper include the loss of confidence in the financial system, the resulting impact on innovation and the adoption of new technological developments, and the diversion of resources away from productivity enhancing investment. Furthermore the country’s cyber-security agency CERT NZ found that more than 60% of the cyber-attacks on the New Zealand organizations in 2018 targeted firms in the financial and insurance services sector. Therefore, managing cyber risk and building cyber resilience should be of importance to the financial sector as well as its regulators. 

     

    Related Links

    Keywords: Asia Pacific, New Zealand, Banking, Insurance, Cyber Risk, Cyber Resilience, Fintech, Value-at-Risk, Bottom Up Approach, Top Down Analysis, RBNZ

    Related Articles
    News

    APRA on Changes to Reporting Obligations for Banks Due to COVID-19

    APRA, in collaboration with the Reserve Bank of Australia (RBA) and the Australian Bureau of Statistics (ABS), published a letter outlining temporary changes in reporting obligations for authorized deposit-taking institutions and registered financial corporations, in response to COVID-19.

    April 01, 2020 WebPage Regulatory News
    News

    OSFI Outlines Capital Treatment for Some COVID-19 Mitigation Measures

    OSFI issued a letter outlining how federally regulated banks should treat the new capital made available to small and medium-size enterprises (SME) through the recently announced government programs.

    March 30, 2020 WebPage Regulatory News
    News

    APRA Announces Deferral of Capital Reform Implementation

    APRA announced that it is deferring the scheduled implementation of Basel III reforms in Australia by one year.

    March 30, 2020 WebPage Regulatory News
    News

    BaFin Explains Regulatory Measures to Address Impact of COVID-19

    BaFin has released new developments and important information about COVID-19 and its effects on the financial and banking system.

    March 30, 2020 WebPage Regulatory News
    News

    ECB Updates Recommendation on Dividend Distribution Policy of Banks

    ECB updated its recommendation to banks on dividend distributions.

    March 30, 2020 WebPage Regulatory News
    News

    EC Amends Implementing Standards on Supervisory Reporting Under CRR

    EC published Regulation 2020/429 that amends the Regulation 680/2014, which sets out implementing technical standards on supervisory reporting of institutions under the Capital Requirements Regulation or CRR (575/2013).

    March 30, 2020 WebPage Regulatory News
    News

    HKMA Announces Deferral of Implementation of Final Basel III Package

    HKMA announced its plans to defer the implementation of final Basel III package, inline with the timeline announced by the Group of Central Bank Governors and Heads of Supervision (GHOS).

    March 30, 2020 WebPage Regulatory News
    News

    BCBS Defers Implementation of Final Basel III Standards by One Year

    BCBS has announced deferral of the implementation date of the final Basel III standards by one year, to January 01, 2023.

    March 27, 2020 WebPage Regulatory News
    News

    EC Regulation on CCR Mitigation for Covered Bonds and Securitizations

    EC published the Delegated Regulation 2020/447 with regard to regulatory technical standards on the specification of criteria for establishing the arrangements to adequately mitigate counterparty credit risk, or CCR, associated with covered bonds and securitizations.

    March 27, 2020 WebPage Regulatory News
    News

    IFRS Publishes Statement on Its Work During the COVID-19 Crisis

    IFRS, in its statement, emphasized that it shares global concerns about the impact of COVID–19 and is supporting its stakeholders by reconsidering timelines of its meetings and publications, providing information on the application of IFRS 9 on financial instruments, and offering calendar updates on ongoing activities.

    March 27, 2020 WebPage Regulatory News
    RESULTS 1 - 10 OF 4913