Â
Learning Objectives:
-
Explain the nature and significance of cyber risk in banking.
-
Describe the EU approach to cyber risk regulation.
-
Describe the US approach to cyber risk regulation.
4.1 Cyber Risk in the Banking Sector
Cyber risk is a growing concern for financial institutions globally . The number of cyberattacks in the global banking sector increased 4.2 times between 2020 and 2024 . The Basel Committee (BCBS) requires the inclusion of cyber risks in capital calculations . Key cyber risks include:
-
Data Breaches:Â Unauthorised access to sensitive customer data.
-
Ransomware:Â Malware that encrypts data and demands payment for its release.
-
Phishing:Â Fraudulent attempts to obtain sensitive information by disguising as a trustworthy entity.
-
Distributed Denial of Service (DDoS): Attacks that overwhelm systems to disrupt services .
4.2 The EU Approach to Cyber Risk Regulation
The EU has adopted a comprehensive approach to cyber risk regulation . Key components include:
Digital Operational Resilience Act (DORA): DORA establishes a comprehensive EU-wide regulatory framework for digital operational resilience . It imposes obligations on financial entities, including:
-
Establishing internal ICT risk management frameworks with detailed policies and procedures .
-
Conducting risk identification, management, and reporting processes .
-
Performing resilience testing, such as threat-led penetration testing for larger entities .
-
Managing ICT risks associated with third-party providers and ensuring compliance with updated contractual obligations .
NIS2 Directive: A directive on measures for a high common level of cybersecurity across the Union .
EBA Guidelines:Â The EBA has revised its Guidelines on ICT and security risk management to align with DORAÂ .
4.3 The US Approach to Cyber Risk Regulation
The US approach to cyber risk regulation is more fragmented, with different agencies providing guidance and regulation:
-
FFIEC Guidelines: The Federal Financial Institutions Examination Council provides guidance on cybersecurity and technology risk management .
-
Cybersecurity Information Sharing Act (CISA): Encourages information sharing about cyber threats between the private sector and government .
-
Breach Notification Requirements:Â Many US states have breach notification laws, such as the California Consumer Privacy Act (CCPA)Â .
Â