Learning Objectives:
-
Understand the strategic rationale for international cooperation in cyber resilience.
-
Analyse the interconnected and borderless nature of cyber threats to the financial system.
-
Recognise the need for collective action to address systemic cyber risks.
-
Identify the key drivers of international cooperation in the financial sector.
1.1 The Borderless Nature of Cyber Threats
Cyber threats are inherently borderless. A cyberattack originating in one jurisdiction can rapidly affect institutions and systems across multiple countries. As the Monetary Authority of Singapore (MAS) Managing Director has noted, “Cyber risks and digital fraud are key transnational threats confronting our region and call for closer collaboration to combat these risks” . The interconnectedness of financial systems means that a successful attack on one institution can have cascading effects across the global financial ecosystem, threatening financial stability and public confidence.
The interconnected nature of financial systems creates complex interdependencies. Financial Market Infrastructures (FMIs) are linked across borders, and participants in these systems are often multinational. A cyber incident affecting a critical FMI in one country can disrupt payment and settlement systems in other countries, creating systemic risk. The CPMI-IOSCO Guidance on cyber resilience for FMIs emphasises that “cyber resilience cannot be achieved by an FMI alone; it is a collective endeavour of the whole ‘ecosystem’” .
1.2 The Need for Collective Action
The financial sector’s full dependency on ICT providers, especially cloud service providers, core banking vendors, and outsourced AI systems, has become a key driver of ICT-related risks. The complexity of modern supply chains, combined with growing reliance on open-source software and its downstream dependencies, has created what has been described as a “perfect storm” for systemic cyber risk. A breach at one vendor can cascade across dozens of organisations simultaneously.
The FSB has noted that “a major cyber-incident, if not properly contained, could seriously disrupt financial systems, including critical financial infrastructure, leading to broader financial stability implications” . The systemic nature of cyber threats requires a systemic response, involving cooperation between financial institutions, central banks, regulators, and international bodies.
1.3 Key Drivers of International Cooperation
Several factors drive international cooperation in cyber resilience:
Shared Threat Landscape: Cyber threats are global, and financial institutions in different jurisdictions face similar risks. Sharing information about threats and vulnerabilities helps all institutions improve their defences.
Systemic Interconnectedness: The interconnectedness of financial systems means that a weakness in one jurisdiction can affect others. Cooperation helps address vulnerabilities before they become systemic.
Regulatory Convergence: International cooperation promotes regulatory convergence, reducing the burden on multinational financial institutions and ensuring a level playing field.
Resource Efficiency: Cooperation allows institutions to pool resources and expertise, avoiding duplication of effort and achieving economies of scale.
Trust and Confidence: International cooperation builds trust between jurisdictions and enhances public confidence in the global financial system.
1.4 The Role of International Bodies
Several international bodies facilitate cooperation in cyber resilience:
-
Bank for International Settlements (BIS): Hosts the Cyber Resilience Coordination Centre (CRCC) and provides a forum for central bank collaboration .
-
Financial Stability Board (FSB): Promotes international financial stability and coordinates regulatory responses to systemic risks .
-
G7 Cyber Expert Group (CEG): Coordinates cybersecurity policy and strategy across G7 jurisdictions .
-
Committee on Payments and Market Infrastructures (CPMI): Develops standards for payment and settlement systems, including cyber resilience guidance .
-
Financial Action Task Force (FATF): Addresses the intersection of cybersecurity and anti-money laundering/counter-terrorist financing.