Learning Objectives:

  • Understand the key global regulatory frameworks for cybersecurity in financial institutions.

  • Explain the Basel Committee’s Principles for Operational Resilience and their application to cyber risk.

  • Analyse the CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures.

  • Recognise the FATF’s recommendations on cyber-enabled fraud and virtual assets.

1.1 The Basel Committee’s Principles for Operational Resilience

The Basel Committee on Banking Supervision (BCBS) has established a comprehensive framework for operational resilience that explicitly addresses cyber risk. The BCBS’s “Principles for Operational Resilience” and “Revised Principles for the Sound Management of Operational Risk” provide the foundational standards for how financial institutions should manage operational and cyber risks . These principles are widely recognised as the global benchmark for operational resilience in the banking sector .

Core Principles:

The Principles outline the core ingredients of effective governance, including well-formulated structures and institutional mandates, taking care institutions have adequate legal powers and accountability frameworks, ensuring sufficient human, financial and technical resources, as well as implementing effective monitoring and follow-up practices . The Principles also emphasise the importance of mapping interconnections and interdependencies of critical functions to understand the full scope of operational risk .

Application to Cyber Risk:

The Basel Principles require financial institutions to:

  • Establish a comprehensive operational risk management framework that includes cyber risk.

  • Identify and map critical operations and their dependencies.

  • Develop and maintain robust recovery and resolution plans.

  • Conduct regular scenario analysis and stress testing.

  • Ensure adequate resources are allocated to operational resilience.

1.2 The CPMI-IOSCO Cyber Guidance for Financial Market Infrastructures

The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) have issued the first internationally agreed guidance on cyber resilience for financial market infrastructures (FMIs) . The Cyber Guidance aims to add momentum to and instil international consistency in the industry’s ongoing efforts to enhance FMIs’ ability to pre-empt cyber attacks, respond rapidly and effectively to them, and achieve faster and safer target recovery objectives .

Core Components:

The Cyber Guidance is supplemental to the Principles for Financial Market Infrastructures (PFMI) and primarily addresses:

  • Governance (Principle 2)

  • Framework for the comprehensive management of risks (Principle 3)

  • Settlement finality (Principle 8)

  • Operational risk (Principle 17)

  • FMI links (Principle 20)

Key Concepts:

  • Board and Senior Management Attention: Sound cyber governance is key. Board and senior management attention is critical to a successful cyber resilience strategy.

  • Recovery Capability: The ability to resume operations quickly and safely after a successful cyber attack is paramount.

  • Threat Intelligence and Testing: FMIs should make use of good-quality threat intelligence and rigorous testing.

  • Continuous Improvement: Cyber resilience requires a process of continuous improvements.

  • Collective Endeavour: Cyber resilience cannot be achieved by an FMI alone; it is a collective endeavour of the whole “ecosystem.”

  • Culture of Cyber Risk Awareness: FMIs should aim to instil a culture of cyber risk awareness.

1.3 FATF Recommendations on Cyber-Enabled Fraud and Virtual Assets

The Financial Action Task Force (FATF) has issued guidance on the intersection of cybersecurity and anti-money laundering/counter-terrorist financing (AML/CFT). The FATF’s recommendations address the risks posed by cyber-enabled fraud and the use of virtual assets for illicit purposes. The FATF’s standards on virtual assets are a critical component of the global regulatory framework for financial institutions.

Key Areas:

  • Cyber-Enabled Fraud: Requiring financial institutions to implement controls to detect and prevent cyber-enabled fraud.

  • Virtual Assets: Establishing standards for the regulation of virtual asset service providers (VASPs).

  • Information Sharing: Encouraging information sharing between financial institutions and law enforcement.

1.4 The Role of the IMF

The IMF plays a key role in promoting cybersecurity in the financial sector through its surveillance, technical assistance, and standard-setting activities. The IMF’s Financial Sector Assessment Program (FSAP) assesses cybersecurity frameworks in member countries and provides recommendations for strengthening cyber resilience . The IMF also conducts surveys on cybersecurity practices, providing valuable data for understanding global trends and challenges .