Learning Objectives:
-
Understand the supervisory expectations for cyber risk management in financial institutions.
-
Apply the supervisory review process to assess ICT and cyber risk.
-
Recognise the factors that influence the weight assigned to ICT and cyber risk in supervisory assessments.
-
Understand the role of offsite and onsite supervision in cyber risk oversight.
2.1 The Supervisory Review Process
Supervisory authorities assess ICT and cyber risk as part of their broader operational risk assessments. The Bank of Spain’s (BdE) approach to ICT and cyber risk supervision provides a useful model for understanding supervisory expectations . The BdE uses a structured approach that combines offsite and onsite supervision to assess the cyber risk control environment of financial institutions.
Risk Assessment Methodology:
Risk categories are defined according to the EBA taxonomy and individual risks are assessed on a 4-grade empirical scale to avoid the observed tendency to categorise most risks as medium in a 3-grade scale . Risk levels must be assessed taking into account the inherent risk, while control levels must be assessed based on indicators of effectiveness, maturity, and implementation status . This leads to a mainstream qualitative IT risk assessment where the supervisor calls the shots on residual risk level determination, based on the data collected and other information available, and decides on the course of actions depending on the outcome .
Factors Influencing Cyber Risk Weight:
The weight assigned to ICT and cyber risk within the overall operational risk assessment is determined by several factors, including:
-
The complexity of the IT architecture
-
Major projects
-
Dependency on fully digitalised services
-
Track record of incidents
It is expected that in the near future the ICT and cyber risk weight will be raised to around 50 percent in SI supervision at the SSM level, which would be more in line with current developments in the financial sector .
2.2 Offsite Supervision
Offsite supervision involves the ongoing monitoring of financial institutions through reporting and data analysis. The BdE’s approach to offsite supervision includes :
Regular Meetings: Regular discussions with management to discuss developments on cyber risk topics, follow up recommendations, review progress on improvement initiatives, validate assertions, and communicate expectations going forward .
Self-Assessments and Analysis: Validated self-assessments provide the basis for offsite analysis. The BdE took action to nudge LSIs to a more conservative approach after observing that the early self-assessments were too optimistic, providing feedback that resulted in more realistic self-assessments .
Audit Reports and Certifications: Audit reports and certifications are considered as corroborative information but are not relied on as evidence .
Surveys: The BdE administers cyber surveys to all FMIs within its remit. While in theory this is a voluntary exercise, all entities participate . Validation methods include outlier analysis, challenging less plausible assertions, and corroborating answers with information collected through other means .
2.3 Onsite Examinations
Onsite examinations provide strong assurance on the functioning of the cyber risk control environment. The BdE’s approach to onsite cyber risk examinations includes :
Risk-Based Approach: Onsite examinations are predominantly conducted at LSIs exposed to higher cyber risk typically because of size, complexity, potential for impact on others, or significant weaknesses .
Broad and Intrusive Examinations: By design, BdE’s onsite cyber risk examinations are broad and intrusive, and as a result, resource intensive and relatively infrequent . It is typical to cover a very substantial subset of cyber risk areas and there is much attention paid to obtaining first-hand evidence .
Extensive Duration: The actual onsite work can exceed two months in duration and an examination can last three to four months end-to-end, with as much as six experts participating with a varying degree of intensity across this period .
Process Regulation: The process is highly regulated and must be thoroughly documented .
Goal: The main goal of the examination is to obtain strong assurance on the functioning of the cyber risk control environment. Such assurance is based on observing the controls being executed, reviewing artifacts on past control execution, and even control effectiveness tests .
2.4 Feedback Loop
The BdE’s approach includes a feedback loop where the results of offsite supervision feed into the planning and execution of examinations, which then in turn inform the former in a feedback loop . This ensures continuous improvement in supervisory practices.