## 1zafea2022004

## Source details

**Canonical URL:** [1zafea2022004](https://www.imf.org/-/media/files/publications/cr/2022/english/1zafea2022004.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2022/english/1zafea2022004.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2022/english/1zafea2022004.pdf.json)

---

### Executive summary — domestic cyber threat landscape
- Cybersecurity risk continues to grow in complexity and severity in an increasingly open and interconnected cyber and financial ecosystem.
- Digitalization is a strategic priority for the South African financial system; SIFIs have established cyber strategies, frameworks, and governance structures.
- Cybersecurity threats to financial stability increased, partly due to widespread remote working arrangements implemented in response to the global pandemic; high standards of risk management meant threats did not materialize into significant losses and/or disruptions.
- South African cybersecurity framework principles: protect, detect, respond, and recover.

### Institutional structure, cooperation, and operational platforms
- SARB: direct responsibility for financial stability; pivotal role. Prudential Authority (PA): implements regulatory framework and supervisory processes to monitor cybersecurity risk and cyber resilience by regulated entities.
- Formal committee structures involve numerous public and private stakeholders responsible for detection, escalation, coordination, response and recovery.
- Cooperative platforms and sector CERTs facilitate cooperation; SABRIC provides an interface between public and private sectors for information sharing.
- SARB is home supervisor for many banks with cross-border presence and can play a greater regional role via Community of African Banking Supervisors (CABS) cyber resilience sub-committee.

### Cybersecurity supervision, oversight, and resourcing
- Need to strengthen cybersecurity supervision and oversight and add dedicated resources.
  - Onsite examinations: should be more frequent, performed at least annually for SIFIs, with more comprehensive verification of cybersecurity risk management capabilities.
  - SARB and the PA should recruit and retain more cybersecurity risk specialists.
  - PA developed new supervisory tools (e.g., cybersecurity risk management questionnaire); next step is collecting and analyzing information prior to onsite examinations to better target supervisory work.
- Move toward a consistent, consolidated regulatory framework for cybersecurity (based on prudential standards):
  - Transition from guidance notes to fully articulated standards to strengthen application and enforceability and align cyber resilience with PA’s approach to other Pillar 1 risks.
  - Leverage Basel Committee guidance on operational risk management and operational resilience.

### Third-party vulnerabilities and vendor risk management
- Third-party service providers are integral; some exhibit high levels of concentration, low substitutability and fragilities that could amplify incidents.
- Recommended actions:
  - Continue mining mapping information for connections/dependencies/concentrations to inform potential third-party oversight.
  - Make identification of critical third parties a priority outcome of mapping.
  - Engage SIFIs on their management of third-party service providers to evaluate ongoing risk management and due diligence.
  - Prioritize third-party management in public–private forums (e.g., SABRIC).

### Financial Market Infrastructures (FMIs)
- Six systemically important FMIs subject to the PFMI: four payment systems, one CSD/SSS, one CCP.
- Payment systems of note:
  - SAMOS — RTGS owned and operated by the SARB
  - Large-value payment system within STRATE — privately operated SSS
  - BankservAfrica retail payment system — privately operated
  - SADC-RTGS — owned by SADC central banks and operated by the SARB; at least 15 SADC member countries participate
- CSD/SSS: STRATE — sole operational CSD/SSS in South Africa.
- CCP: JSE Clear — sole licensed clearing house.
- Gaps against international standards should be remediated.
- Recommendations:
  - Expedite National Payment Systems (NPS) Act into law to adopt CPMI-IOSCO PFMI and establish explicit SARB regulatory/supervisory/oversight powers to implement CPMI-IOSCO Guidance on Cyber Resilience for PS FMIs.
  - Formalize cyber resilience framework for all systemically important FMIs, particularly SAMOS, SADC-RTGS, and capital market FMIs (Strate, JSE Clear).
  - Implement metrics and maturity models (examples: operational reliability objectives, audits, management reviews, incidents, recovery time objectives, near misses, tests, exercises, intelligence).
  - Assess all FMI critical service providers against CPMI-IOSCO Assessment Methodology for Oversight Expectations Applicable to Critical Service Providers.

### Response and recovery capabilities, information sharing, and testing
- Current formal escalation processes are overly complex; supplemented by informal senior-level communications.
- SARB could lead an industry-wide crisis management exercise to test relationships across the sector.
- SARB should support an industry-wide platform to share cybersecurity threat intelligence.
- Strengthen penetration testing across the financial sector; consider regulator-led frameworks (examples: TIBER-EU and UK CBEST).

### Key recommendations (summary with implementation timing)
- Cybersecurity Risk Supervision
  - Move toward implementing a consistent, cross-sectoral regulatory framework for cybersecurity (based on prudential standards). MT
  - Strengthen cybersecurity supervision and oversight with greater supervisory intensity and frequency for SIFIs and new supervisory tools. ST
  - Strengthen bank and FMI third-party risk management through ongoing supervision and oversight. ST
  - Strengthen the PA’s resources for cybersecurity supervision with dedicated specialists. ST
  - Monitor intraday liquidity management and stress test payment system. ST
  - Help strengthen response and recovery capabilities for the financial sector, including: (i) support implementation of an industry-wide crisis management exercise, ideally hosted and/or sponsored by SARB; (ii) support implementation of an industry-wide platform designed to share cybersecurity threat intelligence; and (i) strengthen penetration testing capabilities across the financial sector. MT
- Cybersecurity Risk Oversight
  - Expedite the adoption of the revised National Payment Systems Act to establish explicit regulatory, supervisory and oversight powers for the SARB. ST
  - Formalize the cyber resilience frameworks for all systemically important FMIs with metrics for benchmarking. MT
  - Monitor the compliance of SAMOS and SADC-RTGS participants with the mandatory controls of the SWIFT Customer Security Program, and ensure self-attestations are audited. I
  - Assess all FMI critical service providers against the CPMI-IOSCO Assessment Methodology for the Oversight Expectations Applicable to Critical Service Providers. ST

*Source: EXECUTIVE SUMMARY (Technical Note), South Africa: Cybersecurity Risk Supervision and Oversight.*

### Benchmarks and international guidance used
- No binding international regulatory standards; used guidance and regulatory good practice:
  - BCBS “Principles for Operational Resilience and the revision of the Principles for the Sound Management of Operational Risk” (March 2021)
  - BCBS “Cyber resilience: Range of practices” (December 2018)
  - FSB “Stocktake of Publicly Released Cybersecurity Regulations, Guidance and Supervisory Practices”
  - World Bank Group’s “Financial Sector’s Cybersecurity: A Regulatory Digest”
  - IMF Departmental Paper on Cybersecurity Risk Supervision
  - G7 Fundamental Elements for Effective Assessment of Cybersecurity in the Financial Sector
- FMI oversight based on CPMI-IOSCO “Guidance on cyber resilience for financial market infrastructures” (June 2016).

### Overview of the South African financial system — key characteristics and magnitudes
- Banking sector assets account for 31 percent of total financial sector assets.
- Banks’ assets as a proportion of GDP: 115 percent.
- The banking sector is highly concentrated: five large banks account for more than 91 percent of banking sector assets.
- Less than 5 percent of the exposures of the six largest banks is booked abroad.
- Cross-border operations are systemically important in host countries (examples: Botswana, Lesotho, Malawi, Mauritius, Mozambique, Namibia, Swaziland, Uganda, and Zambia).
- Domestic shocks could generate outward spillovers with a significant impact on the region.

### Risk amplification and systemic propagation
- Amplifying characteristics:
  - Concentrated financial sector
  - High interconnectedness across banks, insurance, asset management, and FMIs
  - Lack of IT substitutability and concentration of third-party service providers
- Disruptions to critical financial functions (allocating credit, settlement, payments) can cause financial instability.
- Concentration of key nodes and third-party fragilities can act as transmission channels and amplifiers.

### Concentration and liquidity risk in payment systems
- Observed relatively high transaction volume and value concentration ratios in two systemically important PS, based on market share of the five largest senders of payment messages.
- A prolonged outage at a major participant could:
  - disrupt its incoming and/or outgoing payments;
  - create liquidity pressures to other direct participants;
  - disable its access to central bank intraday liquidity facilities and interbank settlement services.
- Recommendation: monitor intraday liquidity management and stress-test intraday liquidity stress scenarios (see BCBS (2013) Monitoring Tools for Intraday Liquidity Management).

### Endpoint security for wholesale payments and oversight
- Endpoint security for wholesale payments is monitored domestically; follow-ups planned with foreign central banks connected to SADC-RTGS.
- NPSD Oversight and Supervision Division receives completed SWIFT self-attestation reports for SAMOS connections; deficiencies escalate to relevant competent authority.
- NPSD plans to engage central banks through SADC-RTGS annual user group meetings regarding outstanding self-attestations.
- Industry interviews indicated banks’ size determined resource availability for cybersecurity, but insufficient information on banks’ role in completing self-attestations.

### Cybersecurity regulatory framework and implementation status
- Key instruments and powers:
  - Guidance Note 4 on cyber resilience for FMIs issued in 2017; guidance is legally-binding.
  - NPSD instructed systemically important payment systems to implement CPMI-IOSCO Guidance on Cyber Resilience for FMIs.
  - NPS Act 78 of 1998 empowered SARB; amendments in 2004 and major review in 2018 recommended explicit SARB responsibilities and adoption of PFMI.
- Implementation status:
  - FMIs implementing international guidance at different maturity levels.
  - NPSD Risk Division collaborating with Cyber and Information Security Unit to formalize cyber resilience framework for SAMOS and SADC-RTGS.
  - BankservAfrica completed self-assessments and identified remedial actions for the retail payment system.
  - STRATE plans to align with NIST and Center for Internet Security.
- Identified gaps:
  - FMI critical service provider assessments implemented inconsistently.
  - Improvements needed for assessing IT providers and other third-party service providers identified as critical.
  - In one case, external suppliers reported without identifying whether they were critical service providers.

### Supervisory arrangements, practice, and resource recommendations
- PA practices:
  - Risk-based mix of off-site and onsite analysis.
  - Cybersecurity is a subset of operational risk; supervisory cycle for SIFIs typically between one to two years for an onsite examination of operational risk.
  - For SIFIs (the five largest banks), PA undertakes a two to three-day onsite examination of operational risk; pre-visit material is requested and evaluated.
  - PA has relied mainly on supervisors with operational risk backgrounds and recently hired a cyber expert.
  - PA plans to implement an annual questionnaire for SIFIs to assess cybersecurity posture and maturity.
- Recommendations:
  - Increase supervisory intensity and frequency; conduct onsite examinations at least annual for SIFIs.
  - Use program-based cybersecurity questionnaires (e.g., CQUEST or TIBER-EU) and penetration-testing to inform onsite work.
  - Recruit additional cybersecurity risk specialists to increase onsite time.
  - Shift reliance away from independent parties’ outcomes toward more in-house onsite work.
  - Monitor SAMOS and SADC-RTGS participants’ compliance with SWIFT Customer Security Program and ensure audited self-attestations.

### Third-party dependencies, SARB cyber/market mapping, and recommendations
- FI risk-management practices for third-party dependencies:
  - Identifying and cataloguing critical vendors via full mapping of systems, infrastructures, and suppliers.
  - Self-identified maturity gap analysis.
  - SLAs in legal contracts to test and manage resilience.
  - Ongoing monitoring of vendor performance against SLAs.
  - Disaster recovery failovers tested regularly (e.g., quarterly).
- Observations:
  - Some providers show high concentration, low substitutability, and fragilities.
  - Utility providers (telecommunications and electricity) present vulnerabilities specific to South Africa.
- SARB mapping:
  - “Cyber map” identifies technologies, services, and connections between institutions and providers.
  - Mapping aims: define critical services; collect data on systematically important institutions; identify critical systems; map connections between institutions.
  - No single high-level end-to-end view currently exists; SARB contracted a service provider to develop a high-level map.
  - Mapping is dynamic and resource-intensive; qualitative approaches and thresholds for inclusion can be useful.
- Recommendations:
  - PA should press for strong bank management of third-party risks.
  - SARB/PA should mine mapping information for connections/dependencies/concentrations to inform supervision.
  - Make identification of critical third parties a priority.
  - Engage SIFIs on third-party management and prioritize third-party risk in public–private forums (e.g., SABRIC).

### Response and recovery capabilities — governance, coordination, and SIFI practices
- SARB established Cybersecurity Resilience Sub-committee (CRS) within the FSCF; CRS meets quarterly.
- CRS objectives: foster trust and collaboration; facilitate joint initiatives to reinforce operational resilience.
- CRS functions: threat information-sharing, collaboration across public and private stakeholders; main hub for escalation and coordination of response and recovery decisions.
- All cyber incidents must be reported to the PA; CRS provides additional cyber-focused information sharing.
- Cross-border coordination mechanisms are less developed; limited sharing with other jurisdictions though South Africa participates in CABS.
- SIFIs:
  - Strengthening internal response and recovery protocols; conduct penetration testing and in-house cyber-attack simulations.
  - Simulations updated and informed by incidents (e.g., October 2019 DDoS attack).
  - Threat-led penetration tests conducted periodically; results feed back into risk management.
  - Firms required to monitor and test disaster recovery and business continuity plans; FMIs assessed against Principle 17 of the PFMIs.
- FMIs recovery objectives:
  - Most FMIs set recovery time objectives at two hours with end-of-day settlement following disruptions, though implementation challenges exist.
  - Prolonged power outages could disrupt FMIs and interdependent entities.
  - Retail payment system recovery objectives may vary across services.
  - Near real-time retail and cross-border payments present challenges for setting clear, achievable recovery time objectives.

### Main response and recovery recommendations
- Support implementation of an industry-wide crisis management exercise, ideally hosted/sponsored by SARB.
- Support implementation of an industry-wide platform to share cybersecurity threat intelligence.
- Strengthen penetration testing capabilities across the financial sector (examples: UK CBEST, TIBER-EU frameworks).

### Notable incidents and threat patterns
- Cyber incidents growing in frequency and volume; methods relatively unchanged.
- Pandemic increased exposure via teleworking and digitalization; several banks reported material increases in cyber-attacks.
- Predominant motivation: financial enrichment; typical methods: phishing attacks; threat actors mainly organized crime.
- Focus areas: financial crime (credit card skimming, internet banking scams, card fraud, ATM fraud), extortion (ransomware, DD4BC), money laundering, spam/scam attacks (phishing, vishing, smishing, social engineering).
- Notable incident: Nedbank data breach where 1.7 million bank clients had personal details exposed due to a breach of a service provider’s IT systems.
- SABRIC currently does not record annual cyber-attack statistics for member banks; at mission time no actual incident information had been shared via CABS.

### Annex I — selected cyber lexicon (definitions)
- Cyber; Cyber Event; Cyber Incident; Cyber Resilience; Cyber Risk; Cybersecurity; Information Sharing; Penetration Testing; Threat Actor; Threat Intelligence; Vulnerability Assessment (definitions as provided in source).

### Annex II — selected international supervisory approaches
- United Kingdom: Bank of England approach to operational resilience; CBEST threat-led penetration testing; biannual SIMEX; UK cyber-stress tests (next in 2022 referenced).
- Australia (APRA): CPS 234 and related standards; data collection for baseline metrics; use of IT risk specialists and third-party experts; Cybersecurity Strategy with three primary focus areas including establishing baseline cyber controls, enabling board oversight, and rectifying weak links in the ecosystem.

*Source: EXECUTIVE SUMMARY (Technical Note), South Africa: Cybersecurity Risk Supervision and Oversight.*

### EXECUTIVE SUMMARY____________________________________________________________________________5

### EXECUTIVE SUMMARY

### The domestic cyber threat landscape
- Cybersecurity risk continues to grow both in complexity and severity and is a function of an increasingly open and interconnected cyber and financial ecosystem.
- Digitalization is a strategic priority for the South African financial system; SIFIs have made substantial investments in cyber resilience programs (examples: establishing cyber strategies, frameworks, and governance structures).
- Consistent with many jurisdictions, and partly a result of widespread remote working arrangements implemented in response to the global pandemic, cybersecurity threats to financial stability increased; however, high standards of risk management meant threats did not materialize into significant losses and/or disruptions.
- The South African cybersecurity framework is based upon four principles: protect, detect, respond, and recover.

### Institutional structure, cooperation, and operational platforms
- The South African Reserve Bank (SARB) has direct responsibility for financial stability and plays a pivotal role; the Prudential Authority (PA) implements the regulatory framework and supervisory processes to monitor cybersecurity risk and cyber resilience by regulated entities.
- Formal committee structures involve numerous public and private stakeholders with responsibilities for detection, escalation, coordination, response and recovery.
- Cooperative platforms facilitate cooperation between authorities, sector-based CERTs and public and private businesses; the South African Banking Risk Information Centre (SABRIC) provides an interface between the public and private sectors for information sharing.
- SARB is the home supervisor for many banks with cross-border presence and can play a greater regional role, building on the Community of African Banking Supervisors (CABS) cyber resilience sub-committee arrangements.

### Cybersecurity supervision, oversight, and resourcing
- There is scope to strengthen cybersecurity supervision and oversight and a need for additional dedicated resources.
  - Onsite examinations should be more frequent, performed at least annually for SIFIs, with more comprehensive verification of cybersecurity risk management capabilities.
  - SARB and the PA should commit additional resources to this area, in particular by recruiting and retaining more cybersecurity risk specialists.
  - The PA has developed new supervisory tools (such as a cybersecurity risk management questionnaire); the next step is to focus on collecting and analyzing information prior to onsite examinations to better target supervisory work.
- Move toward a consistent and consolidated regulatory framework for cybersecurity (based on prudential standards) should be a priority:
  - Guidance notes have been used historically; moving toward fully articulated standards will strengthen application and enforceability and align cyber resilience with the PA’s approach to other Pillar 1 risks (credit and market risk).
  - The Basel Committee’s guidance covering operational risk management and operational resilience provides the PA with an instrument to leverage in moving toward a regulatory framework for cyber resilience.

### Third-party vulnerabilities and vendor risk management
- Third-party service providers are integral to SIFIs; some exhibit high levels of concentration, low substitutability and fragilities which could act as amplifiers in the event of a cyber incident.
- Recommended actions:
  - Continue to mine information from mapping for connections/dependencies/concentrations and use that to inform next steps (potential third-party oversight, etc.).
  - Make identification of critical third parties a priority outcome of the mapping exercise.
  - Engage with SIFIs on their management of third-party service providers, evaluating ongoing risk management standards and due diligence to understand operational resilience.
  - Prioritize management of third parties during forums for private and public sector cooperation (e.g., SABRIC and others).

### Financial Market Infrastructures (FMIs)
- FMIs recognize the importance of cyber resilience but gaps against international standards should be remediated.
- Expedite the National Payment Systems (NPS) Act into law to formally adopt the CPMI-IOSCO Principles for Financial Market Infrastructures (PFMI) and establish explicit regulatory, supervisory, and oversight powers for the SARB; this would form the basis for implementing the CPMI-IOSCO Guidance on Cyber Resilience for PS FMIs.
- Formalize a cyber resilience framework for all systemically important FMIs, particularly:
  - the real-time gross settlement system,
  - regional cross-border transfer system, and
  - capital market FMIs (Strate, JSE Clear).
- Implement metrics and maturity models to allow FMIs to benchmark and assess cyber resilience maturity against predefined criteria (examples: operational reliability objectives, audits, management reviews, incidents, recovery time objectives, near misses, tests, exercises, and intelligence).
- Assess all FMI critical service providers, in addition to messaging providers, against the CPMI-IOSCO Assessment Methodology for the Oversight Expectations Applicable to Critical Service Providers.

### Response and recovery capabilities, information sharing, and testing
- Current formal escalation processes for cyber incidents appear overly complex, though supplemented by informal senior-level communications networks.
- SARB could sponsor or lead an industry-wide crisis management exercise to test and deepen formal and informal relationships across the sector.
- SARB should support implementation of an industry-wide platform designed to share cybersecurity threat intelligence.
- Strengthen penetration testing capabilities across the financial sector by engaging with regulated entities to ensure penetration testing is robust; consider regulator-led penetration testing frameworks (examples referenced: TIBER-EU and UK CBEST).

### Key recommendations (Table 1) — Recommendations and Authority Responsible for Implementation; Time
- Cybersecurity Risk Supervision
  - Move toward implementing a consistent, cross-sectoral regulatory framework for cybersecurity (based on prudential standards). MT
  - Strengthen cybersecurity supervision and oversight with greater supervisory intensity and frequency for SIFIs and new supervisory tools. ST
  - Strengthen bank and FMI third-party risk management through ongoing supervision and oversight. ST
  - Strengthen the PA’s resources for cybersecurity supervision with dedicated specialists. ST
  - Monitor intraday liquidity management and stress test payment system. ST
  - Help strengthen response and recovery capabilities for the financial sector, including: (i) support implementation of an industry-wide crisis management exercise, ideally hosted and/or sponsored by SARB as a way to further deepen formal and informal relationships across the sector; (ii) support implementation of an industry-wide platform designed to share cybersecurity threat intelligence; and (i) strengthen penetration testing capabilities across the financial sector. MT
- Cybersecurity Risk Oversight
  - Expedite the adoption of the revised National Payment Systems Act to establish explicit regulatory, supervisory and oversight powers for the SARB. ST
  - Formalize the cyber resilience frameworks for all systemically important FMIs with metrics for benchmarking. MT
  - Monitor the compliance of SAMOS and SADC-RTGS participants with the mandatory controls of the SWIFT Customer Security Program, and ensure self-attestations are audited. I
  - Assess all FMI critical service providers against the CPMI-IOSCO Assessment Methodology for the Oversight Expectations Applicable to Critical Service Providers. ST

*Source: EXECUTIVE SUMMARY (Technical Note), South Africa: Cybersecurity Risk Supervision and Oversight.*

### 4.      The basis for the review of the South African cybersecurity risk supervisory and

### 4.      The basis for the review of the South African cybersecurity risk supervisory and oversight approach

### Benchmarks and international guidance used
- No binding international regulatory standards on cybersecurity risk; guidance material and regulatory good practice were used as the basis of the Note.
- Benchmarks used for cybersecurity risk supervision of financial institutions (FIs):
  - BCBS’s “Principles for Operational Resilience and the revision of the Principles for the Sound Management of Operational Risk” (both March 2021)
  - BCBS “Cyber resilience: Range of practices” (December 2018)
  - FSB “Stocktake of Publicly Released Cybersecurity Regulations, Guidance and Supervisory Practices”
  - World Bank Group’s “Financial Sector’s Cybersecurity: A Regulatory Digest”
  - IMF Departmental Paper on Cybersecurity Risk Supervision
  - G7 Fundamental Elements for Effective Assessment of Cybersecurity in the Financial Sector
- Oversight of cybersecurity risk in FMIs based on CPMI-IOSCO “Guidance on cyber resilience for financial market infrastructures” (June 2016).

### A. Overview of the South African Financial System — key characteristics and magnitudes
- Banking sector assets account for 31 percent of total financial sector assets.
- Banks’ assets as a proportion of GDP: 115 percent.
- The banking sector is highly concentrated: five large banks account for more than 91 percent of banking sector assets.
- Less than 5 percent of the exposures of the six largest banks is booked abroad.
- Cross-border operations are systemically important in many host countries (examples listed: Botswana, Lesotho, Malawi, Mauritius, Mozambique, Namibia, Swaziland, Uganda, and Zambia).
- Domestic shocks could generate outward spillovers with a significant impact on the region.

### Systemically important FMIs (PFMI subject)
- Six systemically important FMIs subject to the PFMI:
  - Four payment systems (PS)
  - One central securities depository (CSD)/securities settlement system (SSS)
  - One central counterparty (CCP)
- ZAR is a CLS-eligible currency operated by an FMI located in a foreign jurisdiction.
- Payment systems identified:
  - South African Multiple Option Settlement (SAMOS) — RTGS owned and operated by the SARB
  - Large-value payment system within STRATE — privately operated SSS
  - BankservAfrica retail payment system — privately operated by BankservAfrica
  - South African Development Community RTGS (SADC-RTGS) — owned by SADC central banks and operated by the SARB; at least 15 SADC member countries participate
- CSD/SSS: STRATE — sole operational CSD/SSS in South Africa (equities, bonds, money market)
- CCP: JSE Clear — sole licensed clearing house; settlement authority for exchange-traded equities and clearing house for exchange-traded derivatives
- No trade repositories.

### Risk amplification and implications for financial stability
- Characteristics that could amplify financial instability in the event of a cyber incident:
  - Concentrated financial sector
  - High level of interconnectedness across banks, insurance, asset management, and FMIs
  - Lack of IT substitutability and concentration of third-party service providers
- Disruptions to critical financial functions (allocating credit, settlement, payments) can cause financial instability.
- Necessity to strengthen FIs’ ability to absorb operational risk-related events such as cyber incidents which could cause significant disruptions in financial markets.
- Concentration of key nodes and third-party service provider fragilities can act as transmission channels and amplifiers to financial instability.

### B. Institutional structure for cyber resilience — roles and coordination
- Primary public sector agencies leading cyber resilience for the financial sector:
  - South African Reserve Bank (SARB): overseeing financial system stability, provision of liquidity assistance, oversight of national payment system (NPS)
  - Prudential Authority (PA): consolidated prudential supervision (banks, insurance, capital market infrastructures (MIs))
- SARB practices:
  - Compiles a risk assessment matrix (RAM) that serves the Financial Stability Oversight Committee; cybersecurity risks featured as systemic risk in the RAM for the past two years.
  - Oversight and supervisory process of payment systems and FMIs based on global standards; risk-based and proportionate to systemic risks.
  - Established Cybersecurity Resilience Sub-committee (CRS) as part of the Financial Sector Contingency Forum (FSCF); CRS meets quarterly.
  - Member of CERES (program of FS-ISAC); uses OSINT and subscription feeds for threat information and intelligence.
- PA practices:
  - Cyber is a subset of operational risk within PA remit; responsible for prudential regulation and supervision of banks, insurance companies and MIs.
  - Monitors policies, processes, and practices related to cybersecurity risk and cyber resilience; relies on internal/external audits and external cyber experts.
  - Conducts on- and off-site reviews including questionnaires, surveys, data center walk-throughs, and industry trend analysis.
- Other institutional roles:
  - FSCA: conduct supervision of CSD/SSS, CCPs and trade repositories.
  - FSRA (Financial Sector Regulation Act 9 of 2017) defines PA, FSCA, and Financial Intelligence Centre (FIC) as financial sector regulators; SARB assumes oversight function.
  - PASA: Payment System Management Body under NPS Act; self-regulatory body developing PCH agreements, clearing rules, service level agreements, policies and position papers aligned with NPS legislation.
- Domestic cooperation:
  - Well-established mechanisms and MOUs between SARB and PA; formal mechanisms for domestic sharing of information, coordination of activities, and tailored protocols for cybersecurity risks.
  - Cooperation platforms between authorities, sector CERTs, and public/private businesses established to detect and manage cyber-attacks and support financial stability.
- International cooperation:
  - Malware information-sharing platform (MISP) driven by SABRIC and maintained by the CERT-EU (France).
  - South Africa is a member of the Community of African Banking Supervisors (CABS); a CABS cyber-resilience subcommittee recently established.
- SABRIC (private sector) role:
  - Connects private sector with public sector structures; intends to share information once MISP proof of concept is operational (includes commercial banks and insurers).
  - Performs global research and early detection of emerging trends; contributes to a data pool to assist members.

### Threat landscape — observed patterns and notable incidents
- Cyber incidents continue to grow in frequency and volume; methods used by threat actors have remained relatively unchanged recently.
- Covid-19 pandemic increased exposure due to teleworking and increased reliance on digitalization; several banks reported material increases in cyber-attacks.
- Motivation and methods:
  - Predominant motivation: financial enrichment.
  - Typical methods: phishing attacks; threat actors mainly organized crime.
  - Focus areas: financial crime (credit card skimming, internet banking scams, card fraud, ATM fraud), extortion (ransomware, DD4BC), money laundering, spam/scam attacks on employees and customers (phishing, vishing, smishing, social engineering).
  - Some successful ransomware attacks reported.
- Notable incident: Nedbank data breach where 1.7 million bank clients had personal details exposed due to a breach of one of their service provider’s IT systems.
- SABRIC currently does not record annual statistics on cyber-attacks on member banks (capability envisaged to include insurers and FMIs); at time of mission no actual incident information had been shared via CABS mechanism.

### Transmission channels and systemic risk propagation
- Three main channels through which cyber-attacks can impact FI systems and data; security controls need to protect:
  - Integrity — guard against illicit alterations or destruction of information; assure non-repudiation and authenticity.
  - Confidentiality — guarantee restrictions on information access; secure privacy and proprietary information (e.g., data breaches).
  - Availability — preserve timely and dependable access and use of information against ISP outages or DDoS attacks.
- Financial interconnectedness and operational dependencies as contagion channels:
  - Dependence on a few key IT service providers exhibiting high concentration and low substitutability can amplify instability.
  - Disruption at one FI or FMI can lead to cascading disruptions at others, weakening confidence in the financial system.
- FMI interdependencies:
  - Connections include SAMOS to CLS and foreign RTGS systems to SADC-RTGS.
  - Interdependencies with settlement banks (commercial banks), liquidity providers (domestic banks providing ZAR committed liquidity facilities for CLS), and service providers (messaging, IT, third-party service providers).
  - Non-essential services and utilities (telecommunications, water, electricity, gas) can also impact FMI operations.
  - South African FMIs make interdependencies transparent and disclose responses to the CPMI-IOSCO Disclosure Framework for FMIs.
  - South Africa participates in implementation monitoring of the PFMI, including self-assessments and peer reviews.

*International Monetary Fund — Chapter 4: The basis for the review of the South African cybersecurity risk supervisory and oversight approach*

### 22.      High concentration of transactions in PS  could pose liquidity risks in a cyber  incident.

### 22.      High concentration of transactions in PS  could pose liquidity risks in a cyber  incident.

### Concentration and liquidity risk observations
- The mission observed relatively high transaction volume and value concentration ratios in two systemically important PS, based on the market share of the five largest senders of payment messages.
- A prolonged outage caused by a cyber incident at a major participant (bank) in the payment system could:
  - disrupt its incoming and/or outgoing payments;
  - create liquidity pressures to other direct participants;
  - disable its access to central bank intraday liquidity facilities and interbank settlement services.
- Recommendation arising: monitor intraday liquidity management and stress-test intraday liquidity stress scenarios (see BCBS (2013) Monitoring Tools for Intraday Liquidity Management).

### Endpoint security for wholesale payments and oversight
- Endpoint security for wholesale payments is monitored domestically; follow-ups are planned with foreign central banks connected to the SADC-RTGS.
- The SARB’s NPSD Oversight and Supervision Division receives completed self-attestation reports from SWIFT to help ensure customer security for connection to SAMOS.
- If deficiencies are identified, an escalation process is made to the relevant competent authority.
- The NPSD plans to engage relevant central banks through the SADC-RTGS annual user group meetings to obtain views on outstanding self-attestations by banks in the region.
- Mission observation: industry interviews indicated banks’ size determined resource availability to address cybersecurity issues, but there was insufficient information to observe banks’ role in completing self-attestations.

### Cybersecurity regulatory framework and major recommendations
- Key regulatory instruments and powers:
  - Guidance Note 4 on cyber resilience for FMIs was issued to the banking industry in 2017; the guidance is legally-binding.
  - NPSD instructed all systemically important payment systems to implement and comply with the CPMI-IOSCO Guidance on Cyber Resilience for FMIs.
  - The NPS Act 78 of 1998 empowered the SARB to manage, administer, operate, regulate, and supervise payment, clearing, and settlement systems. Amendments in 2004 and a major review in 2018 further recommended explicit SARB responsibilities and adoption of the PFMI.
  - SARB published a position paper and supporting information paper expressing commitment to adopting the PFMI as of September 2013.
- Implementation status:
  - FMIs have started to implement international guidance for cyber resilience and are at different levels of maturity.
  - SARB’s NPSD Risk Division is collaborating with the Cyber and Information Security Unit to formalize a cyber resilience framework for SAMOS and SADC-RTGS.
  - BankservAfrica completed self-assessments and identified remedial actions for the retail payment system.
  - STRATE plans to align its cyber resilience framework with NIST and the Center for Internet Security.
- Identified gaps:
  - FMI critical service provider assessments have been implemented inconsistently across FMIs.
  - Improvements needed for assessment of information technology providers and other third-party service providers identified as critical service providers.
  - In one case, multiple external suppliers and vendors were reported without identifying if they were critical service providers to the FMI.
- Main mission recommendations:
  - PA should move toward a consistent regulatory framework (based on prudential standards) for cyber regulation rather than relying primarily on guidance notes.
  - Expedite revised National Payment System Act to establish explicit regulatory, supervisory and oversight powers for the SARB, to formally adopt PFMI and CPMI-IOSCO Guidance on Cyber Resilience for FMIs, and to identify and oversee critical service providers to systemically important PS.
  - Formalize cyber resilience frameworks for all systemically important FMIs (SAMOS, SADC-RTGS, STRATE, and JSE Clear) with metrics and maturity models for benchmarking (e.g., operational reliability objectives, recovery time objectives, tests, exercises, audits).
  - Assess all FMI critical service providers (beyond messaging providers) against the CPMI-IOSCO Assessment Methodology for the Oversight Expectations Applicable to Critical Service Providers and consider ratings in annual self-attestations; ensure external audits against acceptable national or international standards.

### Supervisory arrangements, practice, and resource recommendations
- PA supervisory approach:
  - The PA implements a risk-based approach to supervising cybersecurity risk, employing a mix of off-site and onsite analysis.
  - The PA conducts detailed institution specific assessments of SIFI’s business continuity plans (BCPs) with focus on operational resilience.
  - Cybersecurity risk supervision is a subset of operational risk supervision; the supervisory cycle for SIFIs is typically between one to two years for an onsite examination of operational risk.
  - For SIFIs (the five largest banks), the PA will undertake a two to three-day onsite examination of operational risk; pre-visit material is requested and evaluated.
  - Cybersecurity will be covered in all operational risk onsite examinations for SIFIs and will include a dedicated session with bank management.
  - The PA has relied mainly on supervisors with an operational risk background and recently hired a cyber expert to complement the team.
  - The PA plans to implement an annual questionnaire for SIFIs designed to assess cybersecurity posture and maturity, leveraging global best practice.
- Main supervisory recommendations:
  - Strengthen cybersecurity supervision and oversight with greater supervisory intensity and more onsite examinations.
  - Use a program-based cybersecurity questionnaire (e.g., CQUEST or TIBER-EU) and penetration-testing (firm’s own or regulator-led) to inform onsite examinations in advance.
  - Recruit additional cybersecurity risk specialists to allow more time during on-sites, with onsite examinations at least annual for SIFIs.
  - Shift reliance away from outcomes of independent parties toward more onsite work by in-house risk specialists.
  - Monitor compliance of SAMOS and SADC-RTGS participants with the mandatory controls of the SWIFT Customer Security Program and ensure self-attestations are audited; require cooperation among relevant FMI and banking authorities to exchange SWIFT CSP compliance information.

### Third-party vulnerabilities, vendor risk management, and identified FMIs
- Role of third-party service providers:
  - Vendors common across the entire financial sector: PASA, Visa/Mastercard, SWIFT messaging network, credit bureaus, utility providers (telecommunication and electricity).
  - Vendors specific to particular FIs: software and hardware providers, internet service providers, etc.
- SARB-identified payment FMIs considered SIPS in terms of PFMI criteria:
  - South African Multiple Option Settlement (SAMOS) — RTGS system owned and operated by the SARB.
  - Retail payment system clearing retail transactions excluding the card stream — owned and operated by BankservAfrica.
  - Large value payment system clearing delivery and payment legs of equities, bonds, and money market transactions — owned and operated by Strate (Pty) Limited.
  - CLS system — settles foreign exchange transactions in designated currencies, including the ZAR — owned and operated by CLS Bank International.
  - SADC-RTGS system — settles cross-border transfers that require immediate settlement — owned by SADC central banks and operated by the SARB.

*Source: 1zafea2022004 - 22.      High concentration of transactions in PS  could pose liquidity risks in a cyber  incident.*

### 42.      To manage dependencies on third-party service providers, FIs have implemented an

### 1zafea2022004 - 42.      To manage dependencies on third-party service providers, FIs have implemented an

### Third-Party Dependencies and FI Risk Management
- FIs have implemented an enterprise-wide approach to governance and risk management to manage dependencies on third-party service providers.
- Risk management practices employed by FIs include:
  - Identifying and cataloguing all critical vendors, via full mapping of systems, infrastructures, and suppliers;
  - Implementing self-identified maturity gap analysis;
  - Service level agreements (SLAs) in legal contracts to test and manage resilience of critical service providers;
  - Ongoing monitoring and measuring of the performance of vendors against SLA’s;
  - Disaster recovery failovers tested regularly (e.g., quarterly).

- Observations specific to South Africa:
  - Some third-party providers exhibit high levels of concentration, low substitutability, and fragilities which could amplify effects in the event of a cyber incident.
  - Management of third-party service providers is a priority where the FI lacks leverage to negotiate with large global ICT service providers.
  - Utility service providers present vulnerabilities and fragilities specific to South Africa, in particular telecommunications and electricity.

### Cyber Mapping and Market/Payments Mapping by SARB
- The SARB undertook an integrated mapping initiative to map the markets and payments systems to provide insights into cyber resilience.
- A “cyber map” identifies the main technologies, services, and connections between financial sector institutions, service providers, and in-house or third-party systems.
- Mapping aims (fourfold):
  - Defining the critical services executed by the financial sector;
  - Collecting data on systematically important institutions;
  - Identifying the critical system used to carry out the critical services; and
  - Mapping the connections between the institutions.

- Current status and challenges:
  - There is currently no single high-level view of the end-to-end South African financial sector vis a vis financial and cyber networks.
  - SARB contracted a service provider to develop a high-level map for the national payment and market systems.
  - The dynamism and complexity of the financial sector and technologies can make cyber mapping challenging; mapping can be expensive and time-consuming to build in detail.
  - Mapping exercises that do not aspire to completeness and apply thresholds for inclusion, as well as qualitative approaches, have proved useful.
  - The initial mapping exercise was still in development at the SARB and PA with next steps to be determined.
  - Comparative examples: other national authorities map fundamental functions and then sectoral agencies add detail; maps are used to inform supervision and financial stability analysis.

### Main Findings and Recommendations Pertaining to Third-Party Vulnerabilities
- Recommendation: the PA should press for strong bank management of risks associated with third parties; understanding financial and ICT connections between SIFIs is valuable for supervision and understanding transmission channels for risks to financial stability.
- Four observations:
  - First, the SARB/PA should keep mining the information gained from mapping, overlaid with information already known, for connections/ dependencies/ concentrations and use that to inform their next steps (third-party oversight, etc.).
  - Second, make identification of critical third parties a priority outcome of the mapping exercise.
  - Third, engage with SIFIs on their management of third-party service providers, evaluating the ongoing risk management standards and due diligence to understand their standards of operational resilience.
  - Fourth, prioritize discussion of third-party risk during forums for private and public sector cooperation, e.g., SABRIC and others.

### Response and Recovery Capabilities: Governance and Coordination
- The SARB plays a pivotal role in the response and recovery framework.
- SARB established the Cybersecurity Resilience Sub-committee (CRS), a sub-committee of the Financial Sector Contingency Forum (FSCF).
- Primary objectives of the CRS:
  - Fostering trust and collaboration; and
  - Facilitating joint initiatives reinforcing the operational resilience of the financial sector.

- CRS functions and participants:
  - CRS is a key mechanism for threat information-sharing and collaboration between public and private sector stakeholders.
  - CRS meets quarterly to discuss cybersecurity matters within the financial sector.
  - Participants include the PA (as regulator), SARB, national financial structures and associations, commercial banks and insurers.
  - All cyber incidents need to be reported to the PA; the CRS adds an additional layer of information sharing specifically related to cyber.
  - Local banking industry collaboration occurs through SABRIC and the National Cybersecurity Hub for intelligence gathering and knowledge sharing.
  - CRS is the main hub for escalation of cyber incidents and for coordinating response and recovery decisions.
  - The structure for coordination and escalation contains several committees between the FSCF and the Government.
  - In the event a cyber incident is designated systemic, there is a potential short-cut for the FCFS to escalate cyber incidents to the FSOC/ Government/ Governor.

- Cross-border coordination:
  - Mechanisms and processes for cross-border coordination and cooperation are less developed.
  - Plans underway to facilitate information sharing cross-border, but currently no or limited sharing of information with other jurisdictions.
  - South Africa is a member of the CABS established to assist regulators with sharing of information or discussion of critical matters impacting the African continent.
  - Processes and protocols to encourage cyber resilience remain at early stages, such as cybersecurity crisis management exercises.

### SIFIs’ Internal Response and Recovery Practices
- SIFIs are strengthening internal response and recovery protocols to maintain critical business functions during disruptions, for example through penetration testing.
- SIFIs have made recovery and response capabilities a main priority in risk management frameworks and conduct in-house cyber-attack simulations as part of crisis management exercises.
- Simulations and crisis exercises are continually updated and informed by incidents (such as the October 2019 industry-wide DDoS attack on internet infrastructure).
- Threat-led penetration tests are typically conducted on a periodic basis with results feeding back into cybersecurity risk management frameworks.
- Each institution has independent responsibility for ensuring acceptable risk in their own business, including secure and stable operating solutions, backups, emergency solutions, and contributing to robust financial infrastructure.
- Assessment of business continuity management of FIs and FMIs are done as part of the PA’s risk assessment and on-site inspections, and through oversight assessments against Principle 17 of the PFMIs.
- Firms are required to monitor and test capabilities regularly such as disaster recovery and business continuity plans and more sophisticated risk management such as penetration testing.

- FMIs recovery objectives and challenges:
  - FMIs have largely set recovery time objectives at two hours with end-of-day settlement following disruptive events, but actual experiences present implementation challenges.
  - Prolonged power outages could disrupt FMIs and/or entities interdependent with the FMI (such as other FMIs, settlement banks, liquidity providers, service providers).
  - Most SIPS closely align with the two hours recovery time objective; this varies for the retail payment system where multiple time objectives could be set by banks for different payment and settlement services.
  - As payments increasingly move towards near real-time environments for retail transactions and cross-border for both retail and large-value payments, setting clear and achievable recovery time objectives in the context of fast-moving cyber incidents presents a challenge, especially where settlements must be achieved by end-of-day.

### Main Findings and Recommendations Pertaining to Response and Recovery Capabilities
- The mission recommends strengthening response and recovery capabilities including information sharing.
- Three observations:
  - First, support implementation of an industry-wide crisis management exercise, ideally hosted and/or sponsored by SARB to deepen formal and informal relationships across the sector.
  - Second, support implementation of an industry-wide platform designed to share cybersecurity threat intelligence.
  - Third, strengthen penetration testing capabilities across the financial sector (such as a UK CBEST or TIBER-EU threat-led penetration testing framework for testing firms’ cyber resilience).

### Annex I — Commonly Used Terminology in Cyber (Cyber Lexicon) (selected definitions)
- Cyber: Relating to, within, or through the medium of the interconnected information infrastructure of interactions among persons, processes, data, and information systems.
- Cyber Event: Any observable occurrence in an information system. Cyber events sometimes provide indication that a cyber incident is occurring.
- Cyber Incident: A cyber event that (i) jeopardizes the cybersecurity of an information system or the information the system processes, stores or transmits; or (ii) violates the security policies, security procedures or acceptable use policies, whether resulting from malicious activity or not.
- Cyber Resilience: The ability of an organization to continue to carry out its mission by anticipating and adapting to cyber threats and other relevant changes in the environment and by withstanding, containing and rapidly recovering from cyber incidents.
- Cyber Risk: The combination of the probability of cyber incidents occurring and their impact.
- Cybersecurity: Preservation of confidentiality, integrity, and availability of information and/or information systems through the cyber medium. In addition, other properties, such as authenticity, accountability, non-repudiation, and reliability can also be involved.
- Information Sharing: An exchange of data, information and/or knowledge that can be used to manage risks or respond to events.
- Penetration Testing: A test methodology in which assessors, using all available documentation (e.g., system design, source code, manuals) and working under specific constraints, attempt to circumvent the security features of an information system or interconnected information infrastructure.
- Threat Actor: A person or element that has the power to carry out a threat. An individual, a group or an organization believed to be operating with malicious intent.
- Threat Intelligence: Threat information that has been aggregated, transformed, analyzed, interpreted or enriched to provide the necessary context for decision-making processes.
- Vulnerability Assessment: Systematic examination of an information system, and its controls and processes, to determine the adequacy of security measures, identify security deficiencies, provide data from which to predict the effectiveness of proposed security measures and confirm the adequacy of such measures after implementation.

### Annex II — Overview of Approaches to Cybersecurity Risk Supervision and Operational Resilience (selected country approaches)
- United Kingdom: Bank of England’s Approach to Operational Resilience
  - Firms must identify important business services, set tolerances for disruption—‘impact tolerances’ including time limits within which they will need to resume delivery, and invest to build resilience to stay within these tolerances in severe but plausible scenarios.
  - Operational resilience defined as ability to prevent, adapt, respond to, recover, and learn from operational disruptions; cyber resilience is a key component.
  - CBEST: a threat-led penetration testing framework combining ethical hackers with the latest threat intelligence; UK flagship testing program now well into its second cycle.
  - Prudential Regulation Authority (PRA) assesses reductions in likelihood of operational incidents, ability to limit losses in severe disruption, and sufficiency of capital to mitigate impact when operational risks crystallize.
  - The Financial Policy Committee developed a cyber-stress test to assess response and ability to restore functioning after an incident; the UK's next cyber stress test will be in 2022 and will involve a scenario where data integrity has been compromised within the end-to-end retail payments chain.
  - Biannual sector-wide simulation exercise (SIMEX) validates sector response framework against severe but plausible sector-wide operational incidents.

- Australian Prudential Regulation Authority (APRA)
  - APRA ensures regulated institutions are resilient to cyber-attacks through prevention, detection and response capabilities; data collection drives supervisory process and informs baseline metrics.
  - CPS 234: legally binding minimum standard to ensure resilience against information security incidents by maintaining an information security capability commensurate with vulnerabilities and threats; objective to minimize likelihood and impact of incidents on confidentiality, integrity or availability of information assets, including those managed by related parties or third parties.
  - Other standards include CPS231 Outsourcing; CPS 232 Business Continuity Management; CPS 235 Managing Data Risk.
  - APRA uses IT risk specialists to complement line supervisors and engages third party experts for deeper assessments; coordinates with Council of Financial Regulators’ Cybersecurity Working Group and Australian Federal Government.
  - APRA issued a Cybersecurity Strategy building on previous initiatives; Strategy informed by consultation with Department of Home Affairs, Treasury, ASIC, and Reserve Bank of Australia; designed to complement Australia’s Cybersecurity Strategy 2025.
  - Strategy’s three primary focus areas:
    - First priority: establish a baseline of cyber controls by reinforcing non-negotiable cyber practices, facilitating better sharing of cyber information and enabling more effective incident response processes.
    - Second priority: enable boards and executives of financial institutions to oversee and direct correction of cyber exposures.
    - Third priority: rectify weak links within the broader financial ecosystem and supply chain by fostering maturation of provider cyber-assessment and assurance and harmonizing regulation and supervision of cyber across the financial system.
  - APRA implemented a one-off tripartite independent cybersecurity review across all regulated industries. Starting 2022, APRA will ask boards to engage an external audit firm to conduct a thorough review of their CPS 234 compliance and report back to both APRA and the board.

*Source: 1zafea2022004 - Extracts from IMF country report chapter on South Africa cyber resilience and supervisory practices.*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2022/english/1zafea2022004.pdf_
