## CYBER RISK: A GROWING CONCERN FOR MACROFINANCIAL STABILITY

## Source details

**Canonical URL:** [CYBER RISK: A GROWING CONCERN FOR MACROFINANCIAL STABILITY](https://www.imf.org/-/media/files/publications/gfsr/2024/april/english/ch3sum.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/gfsr/2024/april/english/ch3sum.pdf.md)
- [Structured JSON version](/-/media/files/publications/gfsr/2024/april/english/ch3sum.pdf.json)

---

### Key findings on incidence and losses
- Cyber-related incidents, in particular those with a malicious intent, have become much more frequent over the past two decades, and especially since 2020.
- While cyber incidents have thus far not been systemic, the risk of extreme direct losses—at least as large as $2.5 billion—to firms from such incidents has increased.
- Indirect losses from cyber incidents are also significant and tend to be substantially larger than the reported direct losses by firms.
- Nearly one-fifth of all incidents affect financial firms, underscoring the sector’s high exposure to cyber risks.

### Drivers of cyber risk
- Digitalization and geopolitical tensions significantly raise the risk of cyber incidents.
- More developed cyber legislation and better cyber governance at firms could help mitigate cyber incident risk.

### Financial sector vulnerabilities and transmission channels
- High market concentration and low substitutability for critical services (for example, payment services and custody banking) increase the potential for disruptive effects when financial firms are hit.
- Operations of financial firms often depend on common third-party IT providers, raising the risk of common shocks and spillovers across institutions.
- A severe cyber incident at a financial institution could undermine trust in the financial system and, in extreme cases, lead to market selloffs or runs on banks.
- Empirical analysis indicates modest and somewhat persistent deposit outflows from smaller US banks after a cyberattack, although no significant cyber runs have occurred to date.

### Gaps in policy, supervision, and resilience
- Surveyed central banks and supervisory authorities in emerging market and developing economies often report insufficient cybersecurity policy frameworks.
- Reporting of cyber incidents is currently insufficient for effective monitoring of cyber risks.

### Policy recommendations and resilience measures
- Develop an adequate national cybersecurity strategy.
- Establish appropriate regulatory and supervisory frameworks for cyber resilience in the financial sector.
- Build a capable cybersecurity workforce.
- Strengthen domestic and international information-sharing arrangements.
- Strengthen reporting requirements for cyber incidents to improve monitoring.
- Ensure supervisors hold board members responsible for managing financial-firm cybersecurity, promoting a conducive risk culture, cyber hygiene, and cyber training and awareness.
- Require financial firms to develop and test response and recovery procedures to limit potential disruptions.
- National authorities should develop effective response protocols and crisis management frameworks.

### IMF engagement
- The IMF helps member countries strengthen their cybersecurity frameworks through Financial Sector Assessment Programs and capacity-building initiatives.

*Source: Chapter 3 summary, ch3sum.pdf*

---


_Source: https://www.imf.org/-/media/files/publications/gfsr/2024/april/english/ch3sum.pdf_
