Learning Objectives:

  • Explain the nature and significance of cyber risk in banking.

  • Describe the EU approach to cyber risk regulation.

  • Describe the US approach to cyber risk regulation.

4.1 Cyber Risk in the Banking Sector

Cyber risk is a growing concern for financial institutions globally . The number of cyberattacks in the global banking sector increased 4.2 times between 2020 and 2024 . The Basel Committee (BCBS) requires the inclusion of cyber risks in capital calculations . Key cyber risks include:

  • Data Breaches: Unauthorised access to sensitive customer data.

  • Ransomware: Malware that encrypts data and demands payment for its release.

  • Phishing: Fraudulent attempts to obtain sensitive information by disguising as a trustworthy entity.

  • Distributed Denial of Service (DDoS): Attacks that overwhelm systems to disrupt services .

4.2 The EU Approach to Cyber Risk Regulation

The EU has adopted a comprehensive approach to cyber risk regulation . Key components include:

Digital Operational Resilience Act (DORA): DORA establishes a comprehensive EU-wide regulatory framework for digital operational resilience . It imposes obligations on financial entities, including:

  • Establishing internal ICT risk management frameworks with detailed policies and procedures .

  • Conducting risk identification, management, and reporting processes .

  • Performing resilience testing, such as threat-led penetration testing for larger entities .

  • Managing ICT risks associated with third-party providers and ensuring compliance with updated contractual obligations .

NIS2 Directive: A directive on measures for a high common level of cybersecurity across the Union .

EBA Guidelines: The EBA has revised its Guidelines on ICT and security risk management to align with DORA .

4.3 The US Approach to Cyber Risk Regulation

The US approach to cyber risk regulation is more fragmented, with different agencies providing guidance and regulation:

  • FFIEC Guidelines: The Federal Financial Institutions Examination Council provides guidance on cybersecurity and technology risk management .

  • Cybersecurity Information Sharing Act (CISA): Encourages information sharing about cyber threats between the private sector and government .

  • Breach Notification Requirements: Many US states have breach notification laws, such as the California Consumer Privacy Act (CCPA) .


Â