FCA published a report on insights on the cyber resilience practices in the financial industry. The report presents examples of the cyber security practices that firms have shared with FCA. FCA hopes that these practices and experiences will help firms when considering where to prioritize their efforts in increasing cyber resilience.
Since 2017, FCA has brought together over 175 firms across different financial sectors to share information and ideas from their cyber experiences. FCA runs the Cyber Coordination Groups (CCGs) with industry to help improve cyber-security practices among members of the CCGs and their sectors. Over the last year, the groups have been discussing and sharing practices in the areas of Governance, Identification, Protection, Detection, Situational Awareness, Response and Recovery, and Testing. FCA has collated the examples shared by firms and set out those it considers to be beneficial for a wider audience under each of these themes:
- Putting good governance in place
- Identifying what needs to be protected
- Protecting assets appropriately
- Using good detection systems
- Being aware of emerging threats and issues
- Being ready to respond and recover
- Testing and refining defenses
The insights in this publication may be relevant for small and medium-size firms. However, FCA encourages all firms to consider whether these insights may be useful to them. FCA warns that this document should not be considered as FCA guidance, as it does not set out the FCA expectations about what systems and controls firms should have in place to comply with its regulatory requirements. However, many of the shared examples support existing guidance from the National Cyber Security Center.
Keywords: Europe, UK, Banking, Securities, Insurance, Cyber Resilience, Cyber Risk, Cyber Security, Regtech, FCA
ECB published a decision allowing the euro area banks under its direct supervision to exclude certain central bank exposures from the leverage ratio.
ESAs launched a survey seeking feedback on the presentational aspects of product templates under the Sustainable Finance Disclosure Regulation (SFDR or Regulation 2019/2088).
ECB published input of the European System of Central Banks (ESCB) into the EBA feasibility report on reducing the reporting burden for banks in EU.
ECB finalized the guide on assessment methodology for the internal model method for calculating exposure to counterparty credit risk (CCR) and the advanced method for own funds requirements for credit valuation adjustment (A-CVA) risk.
EBA published an Opinion addressed to EC to raise awareness about the opportunity to clarify certain issues related to the definition of credit institution in the upcoming review of the Capital Requirements Directive and Regulation (CRD and CRR).
APRA is consulting on updates to ARS 210.0, the reporting standard that sets out requirements for provision of information on liquidity and funding of an authorized deposit-taking institution.
FED released hypothetical scenarios for a second round of stress tests for banks.
FED is proposing to temporarily revise the capital assessments and stress testing reports (FR Y-14A/Q/M) to implement the changes necessary to conduct stressed analysis in connection with the re-submission of capital plans, using data as of June 30, 2020.
FED adopted a proposal to extend for three years, with revision, the information collection under the market risk capital rule (FR 4201; OMB No. 7100-0314).
EBA published a voluntary online survey seeking input from credit institutions on their practices and future plans for Pillar 3 disclosures on the environmental, social, and governance (ESG) risks.