Learning Objectives:
-
Understand the role of public-private partnerships in cyber resilience.
-
Apply public-private collaboration models to financial sector cybersecurity.
-
Recognise the importance of private sector expertise and resources.
-
Develop strategies for effective public-private partnerships.
7.1 The Role of Public-Private Partnerships
Public-private partnerships are essential for enhancing collective cyber resilience. The CPMI-IOSCO Cyber Guidance emphasises that cyber resilience cannot be achieved by a single institution alone; it is a collective endeavour of the whole “ecosystem” . The BIS has noted that a well-functioning information network among cross-sectoral market participants is crucial for cyber resilience .
The financial sector’s full dependency on ICT providers, especially cloud service providers, core banking vendors, and outsourced AI systems, requires collaboration between public and private sectors . The CPMI-IOSCO Cyber Guidance highlights the need for coordination between FMIs, their participants, and other market operators, including technology firms, in order to increase the individual and collective responses to cyber attacks .
7.2 Public-Private Collaboration Models
FS-ISAC provides a trusted space for private financial institutions to share information about cyber threats, vulnerabilities, incidents, and other threat intelligence . Employees working in operations from over three dozen central banks, regulators and supervisory entities are already members of FS-ISAC . The organisation facilitates the sharing of information on cyber threats, vulnerabilities, incidents, and other threat intelligence that could impact financial services.
The Asia Pacific Regional Intelligence and Analysis Centre, established by the Monetary Authority of Singapore in collaboration with FS-ISAC, encourages sharing and analysis of cybersecurity information between financial institutions in the region . The CERES Forum also provides a platform for central banks, regulators and supervisors to share best practices, gather feedback, and distribute threat intelligence .
7.3 Private Sector Expertise and Resources
The private sector brings valuable expertise and resources to cyber resilience efforts. The MAS and the Association of Banks in Singapore have established a joint task force to strengthen defences against AI-driven cyber threats . The task force facilitates industry sharing of AI cybersecurity use cases and experience, as well as boosts cyber defence knowledge. It will also strengthen the cybersecurity posture of financial institutions .
The Bank of England and Orpheus collaboration demonstrates how public-private partnerships can enhance supply chain security. The Bank of England achieved 70% average supplier engagement and a 25% reduction in supply chain cyber risk through a threat-led approach for predictive and actionable cyber risk management.
7.4 Strategies for Effective Public-Private Partnerships
Effective public-private partnerships require clear objectives, mutual trust, and shared benefits. Strategies include:
Building Trust: Trust is essential for effective information sharing. Partners must be confident that information will be handled confidentially and used appropriately.
Clear Objectives: Partnerships should have clear objectives and measurable outcomes.
Shared Benefits: Partnerships should provide benefits to all parties.
Regular Engagement: Regular engagement helps maintain momentum and address emerging issues.
Shared Language: A shared understanding of cyber risks and terminology is essential for effective collaboration.