Featured Product

    APRA Expects Boards to Strengthen Ability to Oversee Cyber Resilience

    November 23, 2021

    The Australian Prudential Regulation Authority (APRA) recently completed two pilot initiatives in its 2020-2024 Cyber Security Strategy, which was published in November 2020. These pilots are a technology resilience data collection and an independent assessment of a pilot set of entities’ compliance with CPS 234, the prudential standard on information security. APRA is now publishing insights gained from the two pilots and from its supervisory activities. The insights reinforce APRA’s view that boards need to strengthen their ability to oversee cyber resilience.

    APRA expects boards to have the same level of confidence in reviewing and challenging information security issues as they do when governing other business issues. The pilot independent CPS 234 assessment involved a small sample of banking, insurance, and superannuation entities undergoing an independent assessment against the requirements of CPS 234. The results of the two pilots, together with the outcomes of recent supervisory activities, led APRA to conclude that boards need to play a more active role in: 

    • Reviewing and challenging information reported by management on cyber resilience
    • Ensuring their entities can recover from high-impact cyber-attacks (for example, ransomware)
    • Ensuring information security controls are effective across the supply chain

    APRA notes that it is ultimately the board’s responsibility to ensure that management is fully across the cyber threat they face and, where necessary, takes appropriate action to ensure its entity remains cyber resilient. Over the next couple of years, APRA will continue to roll out the CPS 234 independent assessment process for the remaining entities across the banking, superannuation and insurance industries. APRA intends to share relevant insights with industry from its data collection and other strategic initiatives on cyber security, with a view to lifting practices and enhancing cyber resilience throughout the financial sector.

     

    Related Link: APRA Insights from Pilots

     

    Keywords: Asia Pacific, Australia, Banking, Cyber Risk, CPS 234, Cyber Security Strategy, Governance, ESG, APRA

    Related Articles
    News

    EC Consults on PSD2 and Open Finance; EU Reaches Agreement on DORA

    The European Commission (EC) published a public consultation on the review of revised payment services directive (PSD2) and open finance.

    May 11, 2022 WebPage Regulatory News
    News

    EC Mandates ESAs to Propose Amendments to SFDR Technical Standards

    The European Commission (EC) has issued two letters mandating the European Supervisory Authorities (ESAs) to jointly propose amendments to the regulatory technical standards under Sustainable Finance Disclosure Regulation or SFDR.

    May 11, 2022 WebPage Regulatory News
    News

    EBA Examines Supervisory Practices, Issues Deposits Reporting Template

    The European Banking Authority (EBA) published its annual report on convergence of supervisory practices for 2021. Additionally, following a request from the European Commission (EC),

    May 11, 2022 WebPage Regulatory News
    News

    US Agency Publications Address Basel, Reporting, and CECL Developments

    The Farm Credit Administration published, in the Federal Register, the final rule on implementation of the Current Expected Credit Losses (CECL) methodology for allowances

    May 09, 2022 WebPage Regulatory News
    News

    SEC Extends Comment Period on Climate Risk Disclosures

    The U.S. Securities and Exchange Commission (SEC) looks set to intensify focus on crypto-assets and cyber risk and extended the comment period on the proposed rules to enhance and standardize climate-related disclosures for investors.

    May 09, 2022 WebPage Regulatory News
    News

    APRA Reduces Committed Liquidity Facility, Issues Other Updates

    The Australian Prudential Regulation Authority (APRA) announced reduction in the aggregate Committed Liquidity Facility and issued an update on the operational preparedness for zero and negative market interest rates.

    May 09, 2022 WebPage Regulatory News
    News

    CMF Consults on Basel Rules, Presents Roadmap to Address Climate Risks

    The Commission for the Financial Market (CMF) in Chile published capital adequacy ratios (as of February 2022, January 2022, and December 2021) for 17 banks and for the banking system.

    May 06, 2022 WebPage Regulatory News
    News

    PRA Issues Statement on NPEs and Policy on Trading Activity Wind-Down

    The Prudential Regulation Authority (PRA) issued a statement on the European Banking Authority (EBA) guidelines on management of non-performing exposures (NPEs) and forborne exposures.

    May 06, 2022 WebPage Regulatory News
    News

    EBA Updates Standards for 2023 Benchmarking of Internal Approaches

    The European Banking Authority (EBA) updated the implementing technical standards that specify the data collection for the 2023 supervisory benchmarking exercise in relation to the internal approaches used in market risk, credit risk, and IFRS 9 accounting.

    May 06, 2022 WebPage Regulatory News
    News

    EIOPA Responds to Stakeholder Views on Blockchain in Insurance

    The European Insurance and Occupational Pensions Authority (EIOPA) published a feedback statement on the responses received to the consultation on blockchain and smart contracts in insurance.

    May 06, 2022 WebPage Regulatory News
    RESULTS 1 - 10 OF 8172