SAMA published the Financial Entities Ethical Red Teaming Framework, in an effort to address the increasing cyber risks. The framework is intended as a guide to prepare and execute controlled cyber attacks against the production environment, without exposing sensitive information, with the help of certified and experienced Red Teaming Providers. The framework aims to share intelligence and information obtained during testing to further improve cyber resilience in the financial sector in Saudi Arabia. The framework applies to all member organizations in the financial sector regulated by SAMA.
The principal objective of the framework is to provide guidance on how to conduct the red teaming activities and how to test the detection and response capabilities of a member organization against real sophisticated and advanced attacks and enhance the knowledge of the involved stakeholders. The framework consists of four phases—preparation phase, scenario phase, execution phase, and lessons learned phase. Red Teaming should not be regarded as an audit but as a simulation test that seeks to provide insight into the level of resilience and effectiveness of the implemented cyber-security controls and relevant processes. Red Teaming is not a penetration test; rather, in contrast to a penetration test (in which one or more specific information assets are tested and assessed), it focuses on replicating a targeted and realistic attack against the entire member organization and is performed in a controlled manner.
SAMA has the authority to select any member organization to perform a red teaming exercise considering its criticality and the emerging threat landscape. In addition, a member organization can rightfully conduct red teaming exercise to ensure security resilience. However, as a minimum, domestic systemically important entities will be subject to testing once every three years, in line with this framework. SAMA will maintain the framework and conduct periodic reviews to determine its effectiveness, including the extent to which it addresses the emerging cyber-security threats and risks. If applicable, SAMA will update the framework based on the outcome of the review and lessons learned.
Keywords: Middle East and Africa, Saudi Arabia, Banking, Red Teaming Framework, Cyber Risk, Cyber Testing, Operational Risk, Cyber Resilience, SAMA
The Australian Prudential Regulation Authority (APRA) found that Heritage Bank Limited had incorrectly reported capital because of weaknesses in operational risk and compliance frameworks, although the bank did not breach minimum prudential capital ratios at any point and remains well-capitalized.
The Office of the Superintendent of Financial Institutions (OSFI) released the annual report for 2020-2021.
The Australian Prudential Regulation Authority (APRA) published, along with a summary of its response to the consultation feedback, an information paper that summarizes the finalized capital framework that is in line with the internationally agreed Basel III requirements for banks.
The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) issued a consultative report focusing on access to central counterparty (CCP) clearing and client-position portability.
The Australian Prudential Regulation Authority (APRA) released the final Prudential Practice Guide on management of climate change financial risks (CPG 229) for banks, insurers, and superannuation trustees.
The European Banking Authority (EBA) Single Rulebook Question and Answer (Q&A) tool updates for this month include answers to 10 questions.
The European Commission, or EC, finalized the Implementing Regulation 2021/2017 with respect to the benchmark portfolios, reporting templates, and reporting instructions for the supervisory benchmarking of internal approaches for calculating own funds requirements.
The European Commission (EC) has adopted a package of measures related to the Capital Markets Union.
The European Council adopted its position on two proposals that are part of the digital finance package adopted by the European Commission in September 2020, with one of the proposals involving the regulation on markets in crypto-assets (MiCA) and the other involving the Digital Operational Resilience Act (DORA).
The Prudential Regulation Authority (PRA) is proposing, via the consultation paper CP21/21, to apply group provisions in the Operational Resilience Part of the PRA Rulebook (relevant for the Capital Requirements Regulation or CRR firms) to holding companies.