Â
Learning Objectives:
-
Understand the importance of integrating cybersecurity into enterprise risk management.
-
Identify the key elements of cyber risk integration into ERM.
-
Recognise the role of risk appetite in cyber risk management.
-
Understand regulatory expectations for cyber risk integration.
4.1 The Case for Integration
Cybersecurity should not be treated as a standalone IT issue but as an integral component of enterprise risk management. The Central Bank of Nigeria’s Framework requires that Senior Management incorporate cyber-risk management in the ERM framework and governance requirements to ensure consistent management of risk across the institution .
The Central Bank of Eswatini’s Guidelines emphasise that cyber is more than just ICT. The strategies and measures in a financial institution’s cyber resilience framework should not be restricted to securing the viability of its information technology operations alone, but should also cover people and processes . The framework should, in addition, include timely communication to enable the institution to collaborate with relevant stakeholders to effectively respond to and recover from cyber attacks .
4.2 Key Elements of Cyber Risk Integration
Risk Appetite: The Board shall ensure that the cybersecurity risk appetite is defined in the institution’s Enterprise-wide Risk Management (ERM) framework . This provides a clear statement of the level of cyber risk the institution is willing to accept.
Risk Identification: Senior Management shall drive cyber risk management processes to ensure adherence to cybersecurity risk appetite . This includes identifying, assessing, and managing cyber risks consistently across the organisation.
Risk Assessment: Entities should execute comprehensive IT and cyber security risk assessments covering infrastructure, network, applications, and systems and the controls implemented to address the identified risks . The identified risks should be documented in a central register, and periodically monitored and reviewed .
Risk Reporting: Quarterly reports to the Board should include the status of compliance with Board-approved cyber risk thresholds . This ensures that risk appetite breaches are identified and addressed promptly.
4.3 Governance and Oversight
The integration of cybersecurity into ERM requires appropriate governance and oversight structures. The Central Bank of Nigeria’s Framework requires that cybersecurity governance not only aligns with Corporate and Information Technology (IT) governance but is driven by business objectives .
The board should ensure that cybersecurity management processes are conducted in line with business requirements, applicable laws, and regulations while ensuring security targets are defined and met across the institution . Senior Management provides central oversight for the cybersecurity programme, assigns responsibilities, and ensures the effectiveness of the cybersecurity management processes .
4.4 Regulatory Expectations
Regulators have established clear expectations for cyber risk integration. The Saudi Central Bank’s Cybersecurity Framework requires entities to develop a robust Cyber Security Governance structure that is supported with appropriate resources to oversee and control the overall approach to cyber security . This includes incorporating cyber security requirements in new and/or existing business operating models, including evaluation of cyber security and fraud risks that could target business operating models .
The Central Bank of the UAE requires Open Finance Providers to establish an appropriate information technology (IT) governance framework . IT governance must cover various aspects, including a clear structure of IT functions and the establishment of IT control and risk management policies, and at a minimum, must include an effective IT function, a robust technology risk management function, and an independent technology audit function ..