Featured Product

    ESRB Presents Conceptual Model for Systemic Cyber Risk

    May 14, 2020

    ESRB is presenting a conceptual model for systemic cyber risk in the financial sector. One of the goals is to provide a structured approach that can be used to describe cyber incidents, from genesis to a potential systemic event. Building on this conceptual model, future work could be undertaken to study the efficacy of individual systemic mitigants; use quantitative or data-driven methods to more accurately express each phase of amplification; or further study the interaction and measurement of impact at institutional and aggregate-system levels.

    The model aims to demonstrate the link between the crystallization of cyber risk in a firm-specific context (portraying micro-prudential concerns) and the possible ramifications for the financial system (applying a macro-prudential focus). Another aim of the model is to identify system-wide vulnerabilities and the unique characteristics of cyber incidents that can act as amplifiers, thus propagating shocks through the financial system. The aim is also to support the use of historical or theoretical scenario-based analysis to demonstrate the viability of the model and suggest system-wide interventions that could act as systemic mitigants. Although the model is geared toward disruption arising from cyber incidents, it can also be used for any source of operational disruption (although some elements of the model may be less relevant).

    To deconstruct and describe the macro-financial implications of operational and cyber risks, the systemic cyber risk model is split into four distinct phases: context, shock, amplification, and systemic event. The context phase is useful for scenario design, but is not essential for assessing systemic vulnerabilities or relevant mitigants. It is possible to adopt a cause-agnostic approach, which ignores the circumstances of disruption and focuses solely on impact. From a micro-prudential perspective, it is important to maintain a dual focus on both idiosyncratic individual vulnerabilities and Common Individual Vulnerabilities. Measuring impact is challenging and remains primarily a judgment-based, qualitative approach. Although some quantitative indicators exist, they should be used to complement and inform impact assessments.

    With regard to policy considerations arising from the model, a systemic event arising from a cyber incident is conceivable. Cyber incidents resulting in near-systemic consequences have occurred, in circumstances that can be described as “severe, but plausible.” However, a truly systemic event would require an alignment of amplifiers and a lack of effective systemic mitigants that would be “extreme, but existential” in nature. A cyber incident that causes only operational-to-operational contagion may have system-wide impact. However, the current base of evidence suggests that a systemic event requires the confidence and/or financial contagion channels to be triggered. 

     

    Related Link: Conceptual Model for Systemic Risk (PDF)

    Keywords: Europe, EU, Banking, Cyber Risk, Systemic Risk, Operational Risk, Scenario-based Analysis, Historical Event Analysis, Basel, ESRB

    Featured Experts
    Related Articles
    News

    BIS Bulletin Examines Cognitive Limits of Large Language Models

    The use cases of generative AI in the banking sector are evolving fast, with many institutions adopting the technology to enhance customer service and operational efficiency.

    January 25, 2024 WebPage Regulatory News
    News

    ECB is Conducting First Cyber Risk Stress Test for Banks

    As part of the increasing regulatory focus on operational resilience, cyber risk stress testing is also becoming a crucial aspect of ensuring bank resilience in the face of cyber threats.

    January 24, 2024 WebPage Regulatory News
    News

    EBA Continues Momentum Toward Strengthening Prudential Rules for Banks

    A few years down the road from the last global financial crisis, regulators are still issuing rules and monitoring banks to ensure that they comply with the regulations.

    January 24, 2024 WebPage Regulatory News
    News

    EU and UK Agencies Issue Updates on Final Basel III Rules

    The European Commission (EC) recently issued an update informing that the European Council and the Parliament have endorsed the Banking Package implementing the final elements of Basel III standards

    December 19, 2023 WebPage Regulatory News
    News

    Industry Agency Expects Considerable Uptake for Swiss Climate Scores

    The Swiss Federal Council recently decided to further develop the Swiss Climate Scores, which it had first launched in June 2022.

    December 18, 2023 WebPage Regulatory News
    News

    BCBS Consults on Disclosure of Climate Risks, Issues Other Updates

    The Basel Committee on Banking Supervision (BCBS) launched consultation on a Pillar 3 disclosure framework for climate-related financial risks, with the comment period ending on February 29, 2024.

    December 18, 2023 WebPage Regulatory News
    News

    US Government Moves to Regulate Development and Use of AI Models

    The U.S. President Joe Biden signed an Executive Order, dated October 30, 2023, to ensure safe, secure, and trustworthy development and use of artificial intelligence (AI).

    December 18, 2023 WebPage Regulatory News
    News

    MAS Launches Gprnt Digital Platform for ESG Reporting for SMEs

    The Monetary Authority of Singapore (MAS) launched an integrated digital platform, Gprnt, also known as “Greenprint.”

    November 29, 2023 WebPage Regulatory News
    News

    EBA Finalizes Templates for One-Off Climate Risk Scenario Analysis

    The European Banking Authority (EBA) has published the final templates, and the associated guidance, for collecting climate-related data for the one-off Fit-for-55 climate risk scenario analysis.

    November 28, 2023 WebPage Regulatory News
    News

    NGFS Publishes Phase IV Long-term Climate Scenarios for Banks

    The Network for Greening the Financial System (NGFS) published its latest set of long-term climate macro-financial scenarios (Phase IV) for assessing forward-looking climate risks.

    November 28, 2023 WebPage Regulatory News
    RESULTS 1 - 10 OF 8947