The Australian Prudential Regulation Authority (APRA) recently completed two pilot initiatives in its 2020-2024 Cyber Security Strategy, which was published in November 2020. These pilots are a technology resilience data collection and an independent assessment of a pilot set of entities’ compliance with CPS 234, the prudential standard on information security. APRA is now publishing insights gained from the two pilots and from its supervisory activities. The insights reinforce APRA’s view that boards need to strengthen their ability to oversee cyber resilience.
APRA expects boards to have the same level of confidence in reviewing and challenging information security issues as they do when governing other business issues. The pilot independent CPS 234 assessment involved a small sample of banking, insurance, and superannuation entities undergoing an independent assessment against the requirements of CPS 234. The results of the two pilots, together with the outcomes of recent supervisory activities, led APRA to conclude that boards need to play a more active role in:
- Reviewing and challenging information reported by management on cyber resilience
- Ensuring their entities can recover from high-impact cyber-attacks (for example, ransomware)
- Ensuring information security controls are effective across the supply chain
APRA notes that it is ultimately the board’s responsibility to ensure that management is fully across the cyber threat they face and, where necessary, takes appropriate action to ensure its entity remains cyber resilient. Over the next couple of years, APRA will continue to roll out the CPS 234 independent assessment process for the remaining entities across the banking, superannuation and insurance industries. APRA intends to share relevant insights with industry from its data collection and other strategic initiatives on cyber security, with a view to lifting practices and enhancing cyber resilience throughout the financial sector.
Related Link: APRA Insights from Pilots
Keywords: Asia Pacific, Australia, Banking, Cyber Risk, CPS 234, Cyber Security Strategy, Governance, ESG, APRA
The European Banking Authority (EBA) has published the final templates, and the associated guidance, for collecting climate-related data for the one-off Fit-for-55 climate risk scenario analysis.
The European Banking Authority (EBA) recently published a report that recommends enhancements to the Pillar 1 framework, under the prudential rules, to capture environmental and social risks.
As a follow on from its prudential standard on the treatment of crypto-asset exposures, the Basel Committee on Banking Supervision (BCBS) proposed disclosure requirements for crypto-asset exposures of banks.
The Basel Committee on Banking Supervision (BCBS) and the European Banking Authority (EBA) have published results of the Basel III monitoring exercise.
The Prudential Regulation Authority (PRA) recently issued a few regulatory updates for banks, with the updated Basel implementation timelines being the key among them.
The U.S. Department of the Treasury has recently set out the principles for net-zero financing and investment.
The European Commission (EC) launched a stakeholder survey on the draft International Guiding Principles for organizations developing advanced artificial intelligence (AI) systems.
The finalization of the two sustainability disclosure standards—IFRS S1 and IFRS S2—is expected to be a significant step forward in the harmonization of sustainability disclosures worldwide.
Decentralized finance (DeFi) is expected to increase in prominence, finding traction in use cases such as lending, trading, and investing, without the intermediation of traditional financial institutions.
The Basel Committee on Banking Supervision (BCBS) published reports that assessed the overall implementation of the net stable funding ratio (NSFR) and the large exposures rules in the U.S.