Learning Objectives:
-
Understand the systematic approach to cyber risk assessment.
-
Identify the key steps in the risk assessment process: identification, analysis, evaluation, and treatment.
-
Apply risk assessment methodologies to central bank operations.
-
Recognise the importance of regular and event-driven risk assessments.
2.1 The Cyber Risk Assessment Process
Cyber risk assessment is a systematic process for identifying, analysing, and evaluating cyber risks. The Central Bank of Nigeria’s Risk-Based Cybersecurity Framework requires SFIs to conduct risk assessments to identify threats and vulnerabilities associated with the confidentiality, integrity, and availability of their information assets to determine their cyber risk exposure .
The risk assessment process typically includes the following steps:
Risk Identification: Identifying threats and vulnerabilities associated with the confidentiality, integrity, and availability of information assets. This includes identifying internal and external threats, vulnerabilities in systems and processes, and the potential impact of a successful attack .
Risk Assessment: Evaluating the risk to operations and considering the probability of occurrence of such risks. The risk assessment process must be conducted annually and whenever major changes (such as an acquisition, merger or deployment of new technology) occur .
Risk Measurement: Quantifying the financial impact of cybersecurity risks through the risk measurement process .
Risk Mitigation/Treatment: Implementing risk mitigation and control measures consistent with the criticality of information assets. Risk treatment options such as risk reduction, acceptance, avoidance, transfer and management of residual risk should be selected based on the outcome of the risk assessment .
Risk Monitoring and Reporting: An independent risk management function is to be established and become responsible for assessing, measuring, monitoring and reporting the risks associated with IT infrastructure and services .
2.2 Risk Identification
Risk identification is the first step in the risk assessment process. The Central Bank of Nigeria’s Framework requires SFIs to identify threats and vulnerabilities associated with the confidentiality, integrity and availability of their information assets to determine their cyber risk exposure .
Types of Threats:
-
External Threats: Cybercriminals, state-sponsored actors, hacktivists, and natural disasters.
-
Internal Threats: Malicious insiders, negligent employees, and system failures.
-
Technical Threats: Malware, ransomware, phishing, and denial of service attacks.
Types of Vulnerabilities:
-
Technical Vulnerabilities: Software flaws, misconfigurations, and weak encryption.
-
Process Vulnerabilities: Weak controls, inadequate segregation of duties, and lack of oversight.
-
Human Vulnerabilities: Lack of awareness, poor training, and social engineering susceptibility.
2.3 Risk Analysis and Evaluation
Risk analysis involves assessing the likelihood and impact of identified risks. The Central Bank of Nigeria’s Framework requires SFIs to evaluate the risk to their operations and consider the probability of occurrence of such risks .
Risk Analysis Methodologies:
Qualitative Risk Analysis: Risk is assessed using descriptive scales (e.g., low, medium, high) for likelihood and impact. This approach is useful for initial risk assessment and for risks that are difficult to quantify.
Quantitative Risk Analysis: Risk is assessed using numerical values for likelihood and impact, often expressed in financial terms. This approach is useful for prioritising risks and making investment decisions.
Scenario Analysis: Developing and evaluating scenarios of potential risk events. This approach is useful for understanding the potential impact of emerging risks.
2.4 Risk Treatment
Risk treatment involves selecting and implementing measures to modify risk. The Central Bank of Nigeria’s Framework requires SFIs to implement risk mitigation and control measures consistent with the criticality of information assets .
Risk Treatment Options:
-
Risk Reduction: Implementing controls to reduce the likelihood or impact of the risk.
-
Risk Acceptance: Accepting the risk when the cost of mitigation exceeds the potential impact.
-
Risk Avoidance: Eliminating the risk by ceasing the activity that creates it.
-
Risk Transfer: Transferring the risk to a third party (e.g., through insurance).
-
Residual Risk Management: Managing the risk that remains after controls have been implemented.