Current geopolitical tensions have reinforced the need to counter the risk of cyber attacks globally. The number of such attacks has grown over the past two years, threatening not only individual institutions, but also broader financial stability. Financial institutions and regulatory authorities have taken great steps in strengthening their supervisory and regulatory practices around cyber security. This includes timely and accurate information on cyber incidents.
Yet requirements and practices for cyber incident reporting differ significantly across jurisdictions. This challenges globally active financial institutions’ ability to respond to an incident efficiently, to minimize the harm and recover operations as quickly as possible. To support effective incident response and recovery, the G20 asked the Financial Stability Board (FSB) to explore how to achieve greater convergence in cyber incident reporting.
The proposals in the FSB’s consultative document, published this week, could greatly reduce operational challenges faced by financial institutions reporting to multiple authorities, and foster better communication of critical episodes between authorities. Directed at financial authorities and financial institutions, they recommend greater convergence among cyber incident reporting frameworks, and aim to address some of the operational challenges associated with incident reporting – particularly during the early stages of a cyber incident, when confidence may be low about the cause and impact of the incident.
The use of a common language is essential for greater convergence in cyber incident reporting. Importantly, a common definition and understanding for what constitutes a ‘cyber incident’ is needed to avoid the over-reporting of incidents that are not meaningful for financial authorities or financial stability. The FSB has updated its 2018 Cyber Lexicon, to establish common terminologies. The Lexicon focuses on the core terms necessary to support the FSB’s efforts to ensure a common understanding of relevant cyber security terminology across sectors and facilitate information exchange as appropriate. Those terms also support work by the FSB and its members to assess and monitor the risks to financial stability of different cyber risk scenarios, and to provide guidance related to cyber resilience, including identifying effective practices.
The FSB proposals also include the concept of a common Format for Incident Reporting Exchange (Fire). Fire provides a set of common data elements that have been identified across member jurisdictions. This framework aims to be truly transformational while remaining flexible to a range of implementation practices. This will allow authorities to decide the extent to which they wish to adopt Fire – if at all – based on their own individual needs. And while the potential costs are high, the benefits of its adoption will be higher.
The use of a common language is essential for greater convergence in cyber incident reporting
Giuseppe Siani, FSB
Fire can help reduce the operational burden on financial institutions that have to report to multiple financial authorities. For example, in the event of a cyber incident that triggers reporting requirements, one global systemically important financial institution (G-Sib) has to, within the first 72 hours, verbally contact five or more authorities, issue between seven and 13 written notifications, complete and submit 12 to 14 initial incident report forms and enter details into between five and nine online reporting portals.
Each report has a different communication format, style and timeframe, and needs to be reviewed by incident responders during the most critical initial investigation time. Sufficiently broad adoption of Fire would lead to further convergence in incident reporting and save resources through the introduction of automation, thereby generating further efficiencies.
Change can be expensive, however. There may be implementation costs involved in altering existing regulatory policies and rules, as well as one-off costs related to the investment in – and migration to – new technology systems. Those costs may be less palatable than the current recurring overhead of operational challenges. One of our next steps will be to understand the feasibility of taking Fire beyond this initial concept stage and what preconditions would be necessary before commencing its development. We are conducting a public consultation, which ends on December 31, 2022, and hope to hear further from industry on these points.
Giuseppe Siani is chair of the FSB’s working group on cyber incident reporting and head of the directorate general for financial supervision and regulation at Banca d’Italia
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@waterstechnology.com or view our subscription options here: http://subscriptions.waterstechnology.com/subscribe
You are currently unable to print this content. Please contact info@waterstechnology.com to find out more.
You are currently unable to copy this content. Please contact info@waterstechnology.com to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@waterstechnology.com
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@waterstechnology.com
More on Emerging Technologies
This Week: Startup Skyfire launches payment network for AI agents; State Street; SteelEye and more
A summary of the latest financial technology news.
Waters Wavelength Podcast: Standard Chartered’s Brian O’Neill
Brian O’Neill from Standard Chartered joins the podcast to discuss cloud strategy, costs, and resiliency.
SS&C builds data mesh to unite acquired platforms
The vendor is using GenAI and APIs as part of the ongoing project.
Chevron’s absence leaves questions for elusive AI regulation in US
The US Supreme Court’s decision to overturn the Chevron deference presents unique considerations for potential AI rules.
Reading the bones: Citi, BNY, Morgan Stanley invest in AI, alt data, & private markets
Investment arms at large US banks are taken with emerging technologies such as generative AI, alternative and unstructured data, and private markets as they look to partner with, acquire, and invest in leading startups.
Startup helps buy-side firms retain ‘control’ over analytics
ExeQution Analytics provides a structured and flexible analytics framework based on the q programming language that can be integrated with kdb+ platforms.
The IMD Wrap: With Bloomberg’s headset app, you’ll never look at data the same way again
Max recently wrote about new developments being added to Bloomberg Pro for Vision. Today he gives a more personal perspective on the new technology.
LSEG unveils Workspace Teams, other products of Microsoft deal
The exchange revealed new developments in the ongoing Workspace/Teams collaboration as it works with Big Tech to improve trader workflows.