Learning Objectives:
-
Understand the role of information sharing in cyber resilience.
-
Explain the functions of the Financial Services Information Sharing and Analysis Center (FS-ISAC).
-
Apply the CERES Forum’s platform for central bank and regulator information sharing.
-
Recognise the importance of secure, trusted information sharing.
4.1 The Importance of Information Sharing
Information sharing is essential for effective cyber resilience. Financial institutions that share threat intelligence can better understand the threats they face, identify emerging risks, and coordinate responses to cyber incidents. The Central Bank of Eswatini’s Guidelines require financial institutions to participate actively in information-sharing groups and collectives, including cross-industry, cross-government and cross-border groups to gather, distribute and assess information about cyber practices, cyber threats and early warning indicators.
The CPMI-IOSCO Cyber Guidance emphasises the importance of “situational awareness” and information sharing for enhancing the collective cyber resilience of financial market infrastructures. As noted in the guidance, coordination and sharing of information between FMIs, their participants and market operators are among the principal elements which can assist a correct approach to response strategies and preventive management of malicious cyber events .
4.2 The Financial Services Information Sharing and Analysis Center (FS-ISAC)
The Financial Services Information Sharing and Analysis Center (FS-ISAC) is a non-profit organisation which aims to assure the resilience of the global financial services infrastructure . FS-ISAC provides a trusted space for private financial institutions to share information about cyber threats, vulnerabilities, incidents, and other threat intelligence .
Employees working in operations from over three dozen central banks, regulators and supervisory entities are already members of FS-ISAC . The organisation facilitates the sharing of information on cyber threats, vulnerabilities, incidents, and other threat intelligence that could impact financial services, including attacks that target central banks, regulators and supervisors themselves .
FS-ISAC operates a secure portal and processes to ensure member confidentiality . The Asia Pacific Regional Intelligence and Analysis Centre, established by the Monetary Authority of Singapore in collaboration with FS-ISAC, encourages sharing and analysis of cybersecurity information between financial institutions in the region .
4.3 The CERES Forum
The CERES (Central banks, REgulators and Supervisory entities) Forum is the first global platform bringing together central banks, regulators and supervisors to share information impacting global security and resiliency . The forum was launched in July 2018 by FS-ISAC .
The mission of the CERES Forum is to provide a trusted means for central banks, regulators and supervisors to :
-
Share best practices related to regulatory and compliance controls.
-
Gather useful feedback from industry about which controls are most effective.
-
Rapidly distribute information on cyber threats, vulnerabilities, incidents and other threat intelligence that could impact financial services, including attacks that target central banks, regulators and supervisors themselves.
The Monetary Authority of Singapore played a key role in conceptualising the CERES Forum . MAS’s Chief Cybersecurity Officer noted that “there is a pressing need to enhance situational awareness of cyber threats” and that “the CERES Forum will help us do this” . The forum is seen as timely following the decision by ASEAN finance ministers and central bank governors to facilitate information sharing on cyberthreats and incidents in the region.
4.4 Information Sharing Best Practices
Effective information sharing requires trust, confidentiality, and clear protocols. The CPMI-IOSCO Cyber Guidance highlights the importance of shared protocols and models for information exchange, with a view to preventing cybercrime, and appropriate communication frameworks . Other practices include:
Establishing Trust: Information sharing requires trust between participants. Trust is built through transparency, reliability, and confidentiality.
Clear Protocols: Clear protocols for information sharing, including what information to share, with whom, and how, are essential.
Secure Channels: Information sharing should occur through secure channels to protect confidentiality.
Timely Sharing: Information should be shared in a timely manner to be actionable.
Collaborative Analysis: Information sharing should be accompanied by collaborative analysis to identify patterns and trends.