Learning Objectives:
-
Understand the importance of information sharing for cyber resilience.
-
Apply threat intelligence to strengthen cyber defences.
-
Recognise the role of cross-border coordination in cyber incident response.
-
Understand the limitations and challenges of information sharing.
8.1 The Importance of Information Sharing
Information sharing is essential for effective cyber resilience. The TNM recommendations note that significant work is required to put in place effective information-sharing networks within the financial sector and across other sectors . Information sharing enables financial institutions to better understand the threat landscape, identify emerging risks, and coordinate responses to cyber incidents.
Benefits of Information Sharing:
-
Enhanced Threat Awareness:Â Understanding the threats facing other institutions.
-
Early Warning:Â Receiving early warning of emerging threats.
-
Best Practice Sharing:Â Sharing best practices for cyber defence.
-
Coordinated Response:Â Coordinating responses to cross-sector incidents.
8.2 Information Sharing Mechanisms
The TNM identifies several information sharing mechanisms that can support cyber resilience :
-
Euro Cyber Resilience Board’s Cyber Information and Intelligence Sharing Initiative: A European initiative for cyber information sharing .
-
Financial Services Information Sharing and Analysis Center (FS-ISAC): A global information sharing network for financial institutions .
-
Connect Inform Share Project of the UK’s National Cyber Security Centre: A UK initiative for cyber information sharing .
-
National CERTs:Â National computer emergency response teams that coordinate cyber incident response.
8.3 Cross-Border Coordination
Cross-border coordination is essential for addressing cyber threats that transcend national boundaries. The TNM observes that more can be done by wholesale payments and message networks to capitalise on existing cyber security working groups and participate in information-sharing networks . It refers to the CPMI and IOSCO’s toolkit, “Reducing the Risk of Wholesale Payments Fraud Related to Endpoint Security: A Toolkit”, and the Society for Worldwide Interbank Financial Telecommunication (SWIFT)’s customer security programme .
Challenges in Cross-Border Coordination:
-
Legal and Regulatory Differences:Â Differences in legal and regulatory frameworks.
-
Data Protection:Â Data protection requirements that limit information sharing.
-
Trust:Â The need for trust between institutions and jurisdictions.
8.4 Threat Intelligence
Threat intelligence is the analysis of threat data to inform defensive strategies. The Central Bank of Eswatini’s Guidelines require financial institutions to establish a threat intelligence process to gather and analyse relevant cyber threat information and conduct a threat analysis that considers threats that could trigger extreme but plausible cyber events. The TNM recommends that central banks and supervisory agencies need to develop processes for ongoing threat intelligence-gathering and establish protocols for handling major cyber incidents .
Key Threat Intelligence Components:
-
Collection:Â Gathering threat data from multiple sources.
-
Analysis:Â Analysing threat data to identify patterns and trends.
-
Dissemination:Â Sharing threat intelligence with relevant stakeholders.
-
Action:Â Using threat intelligence to inform defensive strategies