Featured Product

    CPMI-IOSCO Report Assesses Cyber Risk at Financial Infrastructures

    November 29, 2022

    The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) published a Level 3 assessment report on cyber resilience of financial market infrastructures. The review is intended to understand how and to what degree the guidance on cyber resilience for financial market infrastructures, which was published in June 2016, has been used by financial market infrastructures.

    The Level 3 assessment report reviews the state of cyber resilience (as of February 2021) at 37 financial market infrastructures from 29 jurisdictions during 2020–22. The assessment was focused on the implementation of Principles 2 (Governance), 3 (Comprehensive framework for the management of risks), and 17 (Operational risk), in addition to the relevant key considerations of the principles for financial market infrastructures. The assessment focused on key components of the cyber resilience framework. Recognizing the challenges exacerbated by the increased remote working arrangements and the use of personal devices, the report outlines key measures implemented or being implemented to address potentially heightened cyber risks. The Level 3 assessment covered all types of financial market infrastructures, including systemically important payment systems, central securities depositories, securities settlement systems, central counterparties, and trade repositories.

    The assessment report found that there was a reasonably high adoption of the Cyber Guidance, with a significant majority of financial market infrastructures indicating that they had adopted or referred to parts of the Cyber Guidance when designing their cyber resilience frameworks. The assessment report highlights five concerns, including one serious issue of concern. The serious issue of concern relates to a small number of financial market infrastructures that have not yet developed their cyber response and recovery plans to meet the criteria that critical information technology systems can resume operations within two hours following disruptive events, even in the case of extreme but plausible scenarios. Additionally, the four issues of concern relate to

    • shortcomings in established response and recovery plans for meeting the two-hour recovery time objective under extreme cyber-attack scenario
    • lack of cyber resilience testing after a significant system change
    • lack of comprehensive scenario-based testing
    • inadequate involvement of relevant stakeholders in testing of their responses.

    Considering their aggregate impact, the serious issues of concern seem to pose clear challenges for cyber resilience of financial market infrastructures. The CPMI and IOSCO has urged the relevant financial market infrastructures and their relevant supervisory authorities to address these issues with the highest priority.


    Related Links


    Keywords: International, Banking, Securities, Financial Market Infrastructure, Cyber Risk, Regtech, Systemic Risk, Cyber Guidance, Cyber Resilience Framework, Operational Resilience, Basel, CPMI, IOSCO

    Featured Experts
    Related Articles

    OSFI Finalizes on Climate Risk Guideline, Issues Other Updates

    The Office of the Superintendent of Financial Institutions (OSFI) is seeking comments, until May 31, 2023, on the draft guideline on culture and behavior risk, with final guideline expected by the end of 2023.

    March 12, 2023 WebPage Regulatory News

    BIS Paper Examines Impact of Greenhouse Gas Emissions on Lending

    BIS issued a paper that investigates the effect of the greenhouse gas, or GHG, emissions of firms on bank loans using bank–firm matched data of Japanese listed firms from 2006 to 2018.

    March 03, 2023 WebPage Regulatory News

    HMT Mulls Alignment of Ring-Fencing and Resolution Regimes for Banks

    The HM Treasury (HMT) is seeking evidence, until May 07, 2023, on practicalities of aligning the ring-fencing and the banking resolution regimes for banks.

    March 02, 2023 WebPage Regulatory News

    BCBS Report Examines Impact of Basel III Framework for Banks

    The Basel Committee on Banking Supervision (BCBS) published results of the Basel III monitoring exercise based on the June 30, 2022 data.

    February 28, 2023 WebPage Regulatory News

    PRA Consults on Prudential Rules for "Simpler-Regime" Firms

    Among the recent regulatory updates from UK authorities, a key development is the first-phase consultation, from the Prudential Regulation Authority (PRA), on simplifications to the prudential framework that would apply to the simpler-regime firms.

    February 28, 2023 WebPage Regulatory News

    DNB Publishes Multiple Reporting Updates for Banks

    DNB, the central bank of Netherlands, updated the list of additional reporting requests and published additional data quality checks and XBRL-Formula linkbase documents for the first quarter of 2023.

    February 28, 2023 WebPage Regulatory News

    NBB Sets Out Climate Risk Expectations, Issues Reporting Updates

    The National Bank of Belgium (NBB) published a communication on climate-related and environmental risks, issued an update on XBRL reporting

    February 24, 2023 WebPage Regulatory News

    EBA Updates Address Securitization Standards and DGS Guidelines

    The European Banking Authority (EBA) published the final draft of the regulatory technical standards that set out conditions for assessment of homogeneity of the underlying exposures in simple, transparent, and standardized (STS) securitizations.

    February 21, 2023 WebPage Regulatory News

    FSB Publishes Letter to G20, Sets Out Work Priorities for 2023

    The Financial Stability Board (FSB) published a letter intended for the G20 Finance Ministers and Central Bank Governors, highlighting the work that FSB will take forward under the Indian G20 Presidency in 2023

    February 20, 2023 WebPage Regulatory News

    ISSB Standards May Become Effective from January 2024

    The International Organization of Securities Commissions (IOSCO) welcomed the confirmation statement by the International Sustainability Standards Board (ISSB) setting out its progress in the development of its first sustainability-related corporate disclosure standards.

    February 17, 2023 WebPage Regulatory News
    RESULTS 1 - 10 OF 8792