Learning Objectives:
-
Define cybersecurity governance and explain its strategic importance for central banks and financial institutions.
-
Identify the key components of an effective cybersecurity governance framework.
-
Understand the relationship between cybersecurity governance and enterprise governance.
-
Recognise the regulatory expectations for cybersecurity governance structures.
1.1 What is Cybersecurity Governance?
Cybersecurity governance refers to the arrangements a financial institution has put in place to establish, implement, and review its approach to managing cyber risks . It encompasses the systems, processes, and structures through which an organisation directs and controls its cybersecurity activities to achieve its objectives while managing cyber risks effectively.
Effective cyber governance should start with a clear and comprehensive cyber resilience framework that prioritises the security and efficiency of the financial institution’s operations, and supports financial stability objectives . The framework should be guided by a financial institution’s cyber resilience strategy, define how the institution’s cyber resilience objectives are determined, and outline its people, processes, and technology requirements for managing cyber risks and timely communication .
The Central Bank of Nigeria’s Risk-Based Cybersecurity Framework defines cybersecurity governance as the process that “sets the agenda and boundaries for cybersecurity management and controls by defining, directing, and supporting the security efforts of SFIs” . It outlines the responsibilities of the Board of Directors, Senior Management, the Chief Information Security Officer (CISO), and other relevant Risk Management Control functions .
1.2 Key Components of an Effective Cybersecurity Governance Framework
A robust cybersecurity governance framework comprises several interconnected components that work together to ensure the security and resilience of the organisation. The Central Bank of Eswatini’s Guidelines on Cybersecurity for Financial Institutions outline the basic elements that a financial institution’s cyber resilience framework should include .
Cyber Resilience Strategy: The framework should be guided by a financial institution’s cyber resilience strategy, defining how its cyber resilience objectives are determined . The strategy should align with the institution’s business goals and provide direction on how to achieve cybersecurity goals, mitigate cyber risks, and comply with all legal, contractual, statutory, and regulatory requirements .
Clearly Defined Roles and Responsibilities: It is essential that the framework is supported by clearly defined roles and responsibilities of the financial institution’s board (or equivalent) and its management . The board should ensure that cybersecurity governance is integrated into the organisational structure .
Cyber Resilience Framework: The framework should outline the institution’s people, processes, and technology requirements for managing cyber risks and timely communication, enabling the institution to collaborate with relevant stakeholders to effectively respond to and recover from cyber attacks .
Risk Tolerance and Objectives: A financial institution should have a framework that clearly articulates how it determines its cyber resilience objectives and cyber risk tolerance, as well as how it effectively identifies, mitigates, and manages its cyber risks to support its objectives . The board should endorse this framework, ensuring it is aligned with the financial institution’s formulated cyber resilience strategy .
1.3 The Relationship with Enterprise Governance
Cybersecurity governance does not operate in isolation; it must be integrated with broader enterprise governance structures. The Central Bank of Nigeria’s Framework requires that “cybersecurity governance not only aligns with Corporate and Information Technology (IT) governance but is driven by business objectives” .
This integration ensures that cybersecurity is not treated as a purely technical issue but as a strategic business concern that requires attention at the highest levels of the organisation. The board is responsible for ensuring that cybersecurity governance is integrated into the organisational structure and that cybersecurity is integrated with business functions and well managed across the institution .
Strong cyber governance is essential to a financial institution’s implementation of a systematic and proactive approach to managing the prevailing and emerging cyber threats that it faces . It also supports efforts to appropriately consider and manage cyber risks at all levels within the organisation and to provide appropriate resources and expertise to deal with these risks .
1.4 Regulatory Expectations and Best Practices
Regulators globally have established expectations for cybersecurity governance in financial institutions. The Saudi Central Bank’s Cybersecurity Framework requires entities to “develop a robust Cyber Security Governance structure that is supported with appropriate resources to oversee and control overall approach to cyber security” . The Central Bank of the UAE requires Open Finance Providers to establish an appropriate information technology (IT) governance framework that covers various aspects, including a clear structure of IT functions and the establishment of IT control and risk management policies .
The Central Bank of Eswatini emphasises that the board and management must “create a culture which recognises that staff at all levels have important responsibilities in ensuring the financial institution’s cyber resilience” . This reflects the expectation that cybersecurity is not solely the responsibility of the IT department but is a shared responsibility across the entire organisation.
Effective governance structures should include, at a minimum, an effective IT function, a robust technology risk management function, and an independent technology audit function . The board, or a committee designated by the board, should be responsible for ensuring that a sound and robust risk management framework is established and maintained to manage technology risks in a manner proportionate to all risks that the institution is exposed to .
Â