## sdnea2020007 — EXECUTIVE SUMMARY and selected chapters

## Source details

**Canonical URL:** [sdnea2020007 — EXECUTIVE SUMMARY and selected chapters](https://www.imf.org/-/media/files/publications/sdn/2020/english/sdnea2020007.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/sdn/2020/english/sdnea2020007.pdf.md)
- [Structured JSON version](/-/media/files/publications/sdn/2020/english/sdnea2020007.pdf.json)

---

### Cyber risk as a threat to financial stability — key findings
- Cyberattacks on information and communication technology systems used by financial institutions are a threat to financial stability and require additional attention.
- Attackers operate across borders, targeting large and small institutions, rich and less well-off countries alike; COVID-19 has heightened the importance of protecting digital systems and connectivity.
- Six major gaps identified: prevention, mitigation, measurement, recovery, information sharing, and capacity development.
- The IMF is participating in regulatory discussions and providing capacity development (CD) to its global membership.

Key numeric and illustrative examples preserved from source:
- In the week following the Equifax data breach announcement in 2017, Equifax lost 35 percent of its stock value; TransUnion and Experian experienced equity drops of 13 percent and 6 percent, respectively.
- On August 26, 2020, a large DDoS attack affected the New Zealand stock exchange network connectivity, prompting a market halt.
- Some studies estimate that ransomware incidents alone generate some $1 billion in illegal proceeds every year (McGuire 2018).

### Major policy pillars and priorities
- Financial Stability Analysis
  - Accelerate cyber mapping, network analysis, and stress testing to better incorporate cyber risk into financial stability analysis; current work is nascent due in part to data shortcomings.
- Regulation and Supervision
  - Enhance cross-border consistency in regulatory and supervisory approaches to reduce compliance costs and facilitate cooperation and information sharing; national frameworks diverge.
- Response and Recovery
  - Develop national and international response and recovery arrangements and resolve “who to call in a crisis” for cross-border incidents.
- Information Sharing
  - Expand sharing of threats, attacks, and responses across private and public sectors while addressing national security and data protection constraints.
- Preventing and Deterring Cyberattacks
  - Strengthen international efforts to disrupt and deter attackers; complete work on investigation and information-sharing protocols.
- Capacity Development
  - Prioritize CD in developing and emerging market economies, especially low-income countries; low-cost prevention measures and skills building are vital.

### Cyber mapping, quantitative analysis, and stress testing — findings and evidence
- Cyber Mapping
  - Purpose: identify main technologies, services, and connections among financial institutions, service providers, and FMIs to highlight systemic nodes and interdependencies.
  - Challenges: expensive, time-consuming, dynamic sector; pragmatic maps using thresholds and qualitative approaches are useful (example: Norges Bank sector map).
- Quantitative Analysis — data and modeling challenges
  - Limited availability of data on frequency and loss severity; threat landscape evolves rapidly.
  - Loss distributions have heavy tails, complicating statistical analysis.
  - Direct costs occur early and over a short period; indirect costs (declines in future revenue, lost productivity, devaluation of trade name, increased borrowing costs) occur over longer periods and are harder to attribute; insurance often does not cover many indirect costs.
- Empirical findings (preserve exact values)
  - Accenture study: average yearly cost of cybercrime for larger organizations is $13 million, a 72 percent increase over five years.
  - Aldasoro and others (2020): cyber losses remain a small portion of operational losses but can account for a significant share of total operational value at risk (VaR).
  - Bouveret (2018) Monte Carlo simulations:
    - 95 percent VaR loss estimated at $147 billion for financial institutions globally (14 percent of global net income).
    - Under a scenario where mean cyberattack frequency is set to two times its historical peak, the 95 percent VaR loss rises to $352 billion (34 percent of net income).
- Stress Testing
  - Supervisory approach: firms estimate impacts on liquidity and capital under prescribed cyber scenarios; supervisors review procedures and coverage.
  - Monetary Authority of Singapore firm-level cyber risk survey (2019 IMF FSAP):
    - On average, banks estimated losses from a direct cyberattack would amount to about 35–65 percent of quarterly net profits, depending on scenario type.
    - Estimated impacts on ratios: CAR and LCR would drop by 0.1–0.4 and 8.4–35 percent respectively.

### Information sharing — channels, barriers, taxonomy, and operational proposals
- Three broad channels of information sharing:
  - Private Sector Institution to Private Sector Institution: well advanced in many systems; informal (CISO networks) and formal (e.g., FS-ISAC); continuous sharing in trusted networks.
  - Private Sector Institution to Public Agency: routine incident reporting to supervisors; trusted regulator–industry relationships support exchange.
  - Public Sector to Public Sector Agencies: supervisors share incident reports and regulatory responses domestically and cross-border.
- Barriers and constraints
  - Data protection, national security frameworks, liability concerns, difficulty disentangling incident data from customer data, and reputational risk deter sharing.
  - Most reporting regimes provide some safe harbor for liability related to the incident itself but generally do not protect disclosing parties from exposure of personal information.
- Information taxonomy and templates
  - High-Level Categorization (preserved from source):
    - Information that cannot be shared: information sensitive to national defense concerns, personally identifiable information.
    - Information that could be shared: details of cyber threats in near real time and approaches to defense.
    - Information that should be shared: situational awareness, risk management practices, technical vulnerabilities, patches.
  - Benefits: a common taxonomy and standardized incident-reporting template could support a “one-stop-shop” where firms report to a home/lead supervisor that coordinates with peers, and enable two-way flows that alert firms to emerging issues.
- Convening role: central banks and supervisors can promote trusted information-sharing arrangements and leverage supervisory colleges.

### Deterrence, law enforcement, and international cooperation
- Cybercrime is global and evolving; policing, prosecution, sanctioning, and asset recovery are challenging.
- Example: Operation Taiex (March 2019) led to the arrest of the organizer behind Carbanak and Cobalt malware attacks on over 100 financial institutions; investigators found attackers operating in at least 15 countries.
- International legal frameworks and political sensitivities:
  - The 2001 Budapest Convention is the only binding multilateral agreement aimed at combating cybercrime (offenses include confidentiality/integrity/availability offenses, computer-related offenses, content-related offenses, and criminal copyright infringement).
  - In November 2019 a United Nations cybercrime resolution set up a drafting group to establish terms of reference for a new global cybercrime treaty; international constituency is divided.
- AML/CFT and proceeds:
  - Some studies estimate ransomware proceeds at about $1 billion annually.
  - Proliferation of digital currencies that, when unregulated, provide anonymity can facilitate laundering of cybercrime proceeds.
- Recommendations to deter attackers:
  - Make cyberattacks expensive and risky through seizure and confiscation of proceeds, identification and sanctioning of bad actors.
  - Success depends on effective international cooperation (information sharing and formal mutual legal assistance); without cooperation, criminals shift to noncooperating jurisdictions.

### Cyber resilience, FMIs, and third-party risk — scenarios and supervisory options
- FMIs as critical nodes
  - FMIs are highly connected, process large daily volumes, and are technology-dependent—making them key systemic cyber-risk concerns.
  - Successful attacks on FMIs could transmit shocks to participants, other FMIs, customers, and markets, including cross-border transmission.
  - Empirical evidence: Eisenbach, Kovner, and Lee (2020) find that impairment of any of the five most active US banks can affect as much as 38 percent of the network; interruptions originating in some banks with less than $10 billion in assets may be sufficient to impair a significant proportion of the system.
- FMI mitigation practices
  - Core measures: comprehensive information security policies, standards, practices, controls; CSPs expected to meet the same security standards.
  - ECB operationalization of CPMI-IOSCO guidance uses five primary risk management categories: (1) governance, (2) identification, (3) protection, (4) detection, and (5) response and recovery; three overarching components: (1) testing, (2) situational awareness, and (3) learning and evolving.
  - CSP oversight proposals include legal reviews to combine moral suasion with a regulatory backstop, broaden SWIFT Oversight Forum membership, and improve sharing of SWIFT oversight and assurance reports.
- Outsourcing and third-party concentration risks
  - Concentration in a limited number of providers raises supervision challenges; failures in a major third-party provider could have sector-wide impacts.
  - Typical supervisory policy aspects: governance, pre-outsourcing due diligence, information security, sub-outsourcing notification, operational resilience, access and audit rights, termination rights and exit strategies.
  - Proposed supervisory models for critical providers:
    - Intensive supervision akin to utilities by a dedicated agency.
    - Trusted independent certification program by an agreed third party.
    - Direct supervision by financial sector supervisory agencies.
  - Global cooperation is needed because dominant service providers are global.

### Cyber resilience in emerging market and developing economy countries — needs and capacity gaps
- Challenges and scale of shortage (preserve exact figures and phrasing)
  - Global cybersecurity skill shortage: more than 4 million unfilled positions globally in 2019, up from just less than 3 million in 2018; per capita shortage most acute in low- and middle-income countries.
  - Limited budgets for advanced cybersecurity technologies and less competitive salary structures reduce capacity; risk that attackers target smaller, more vulnerable nations as advanced economies harden defenses.
- Consequences
  - Successful cyberattacks can have profound effects on financial sector functioning and financing of the real economy; developing economies are less able to weather prolonged outages, risking broader confidence damage.
- Support and initiatives
  - Existing programs and assistance include SWIFT Customer Security Program, Carnegie Endowment toolkit, UK Foreign and Commonwealth Office crisis-management exercises, Bank of France workshops, IMF/World Bank/IDB capacity development and workshops.
  - IMF activities: work with financial supervisors in low-income countries, incorporation of cyber risk into financial sector surveillance, analytical tool development, technical assistance, annual workshop for supervisors in low-income countries launched in 2017, regional technical assistance centers, bilateral technical assistance, incorporation of cyber stress testing and cyber risk supervision into the FSAP (pilot supervision exercise in Norway in 2020).
  - Need for expanded technical assistance and support for formal education and professional certification in cybersecurity.

### Priority policy recommendations (preserve phrasing and content)
- Improving Cyber Risk Analysis and Integration into Financial Stability Analysis
  - Use cyber mapping, stress testing, and improved quantification of potential impacts to enhance analysis and resource allocation.
- Greater Consistency in Regulatory Frameworks
  - Develop and promote greater consistency in national cybersecurity regulatory frameworks; build on the FSB cyber lexicon and effective practices to reduce compliance burdens and improve cooperation.
- Enhancing Operational Resilience, Response, and Recovery
  - Require institutions to develop and test response and recovery procedures; national authorities should develop clear crisis protocols and test them regularly; develop regional and international cross-border crisis-management protocols and exercises.
- Strengthening Information Sharing
  - Identify and address obstacles to cyber-related information exchange; agree on what, when, how, and with whom to share; support trusted sharing platforms and adopt a commonly agreed international template built on a clear lexicon.
- Intensify Defense against Cyberattacks
  - Build domestic investigative and enforcement capabilities, enhance cross-border coordination, intensify law enforcement cooperation, and improve AML/CFT implementation to prevent laundering of cybercrime proceeds and facilitate recovery.

*Source: sdnea2020007 (IMF staff), "EXECUTIVE SUMMARY" and selected chapters on cyber risk, information sharing, FMIs, outsourcing, and capacity building.*

### EXECUTIVE SUMMARY __________________________________________________________________________ 5

### sdnea2020007 - EXECUTIVE SUMMARY

### EXECUTIVE SUMMARY
- Cyberattacks on information and communication technology systems used by financial institutions are a threat to financial stability and require additional attention.
- Attackers operate across borders, targeting large and small institutions, rich and less well-off countries alike; COVID-19 has heightened the importance of protecting digital systems and connectivity.
- The note identifies six major gaps that, if addressed, could considerably reduce cyber risk and help safeguard global financial stability; these gaps build on the need for greater prevention, mitigation, measurement, and recovery.
- The IMF is participating in regulatory discussions and providing capacity development (CD) to its global membership.

Key pillars to address the gaps:
- Financial Stability Analysis: Better incorporation of cyber risk through mapping key financial and technology interconnections (cyber mapping), network analysis, and stress testing; work is nascent due in part to data shortcomings and must be accelerated.
- Regulation and Supervision: Enhanced consistency in regulatory and supervisory approaches to reduce compliance costs and build a platform for stronger cross-border cooperation and information sharing; national frameworks diverge.
- Response and Recovery: Focus on response and recovery capabilities so cyberattacks do not become financial stability events; crisis preparation and cross-border “who to call in a crisis” arrangements remain unresolved.
- Information Sharing: Greater sharing of threats, attacks, and responses across private and public sectors is needed; barriers include national security concerns and data protection laws.
- Preventing Cyberattacks: Strengthened international efforts to disrupt and deter attackers are required; current work on investigation and information-sharing protocols is positive but unfinished.
- Capacity Development: Priority for developing and emerging market economies, especially low-income countries; the COVID-19 crisis underscores the role of connectivity and the need for low-cost prevention measures.

### CYBER RISK AS A THREAT TO FINANCIAL STABILITY
#### A. Growing Risk
- Attacks are rising globally; financial services continue to be the most targeted industry.
- Cybercrime has become more widespread due to low prosecution risk and availability of easy-to-use attack tools and support services.
- Hacking tools have evolved to be usable by relatively low-skilled attackers at a fraction of previous cost (see Figure 1).
- The number of cyber incidents and data breaches has sharply increased (see Figure 2).
- Cyber threats have become more sophisticated, typically spanning several jurisdictions and making investigation and prosecution harder; operations have been industrialized with markets for hacking services and vulnerability exchanges.
- While most attacks are financially motivated, rising geopolitical tensions increase disruption-motivated incidents; data corruption (“data poisoning”) and the use of machine learning/AI heighten risks to confidence and decision-making.
- Notable numeric examples preserved in source:
  - In the week following the Equifax data breach announcement in 2017, Equifax lost 35 percent of its stock value; TransUnion and Experian experienced equity drops of 13 percent and 6 percent, respectively.
  - On August 26, 2020, a large DDoS attack affected the New Zealand stock exchange network connectivity, prompting a market halt.

#### B. From Cyberattack to Financial Stability Risk
- Cyber risk transmits to financial stability primarily via:
  - Loss of confidence: lengthy outages and compromised data integrity can reduce willingness to lend or extend liquidity.
  - Lack of substitutability: loss of a key service provider (often one or two large institutions or FMIs) without easy substitutes can disrupt the sector.
  - Interconnectedness: bilateral transactions, trading, settlement, clearing platforms, central bank and payment systems links can propagate outages into liquidity and solvency pressures.
- Technology interconnectedness (common hardware/software, cloud providers) increases contagion risk, including cross-border contagion.
- Most successful attacks affect one institution with limited damage, but sufficiently forceful or spreading attacks could become systemic.

### ENHANCING CYBERSECURITY IN THE FINANCIAL SYSTEM
- Mitigating cyber risk is a key public policy objective: digitalization elevates cyber risk to a priority for CEOs and public authorities because individual firms may underinvest relative to system-wide interests.
- Areas needing further work, with emphasis on official sector roles:
  - Financial Stability Analysis and Cyber Risk: accelerate cyber mapping, network analysis, and stress testing despite data limitations.
  - Regulation and Supervision: pursue greater cross-border convergence in regulatory and supervisory practices to address cross-border risk and promote common approaches.
  - Response and Recovery: develop national and international response and recovery arrangements; address unresolved crisis coordination and support developing economies.
  - Information Sharing: create globally agreed templates using a common taxonomy, increase use of shared platforms, and expand trusted networks while working within national security and data protection constraints.
  - Deterrence and Disruption: enhance international efforts to disrupt and deter attackers and complete work on investigation and information-sharing protocols.
  - Capacity Development: prioritize CD in developing and emerging market economies to strengthen financial stability and support financial and technological inclusion; low-income countries are particularly vulnerable.

- The note emphasizes a scaled and coordinated global approach to reduce overall threat and to particularly benefit lower-income countries.

*Source: sdnea2020007 - EXECUTIVE SUMMARY, International Monetary Fund.*

### 12. Further improving the identification of major sources of system-wide cyber risk and

### 12. Further improving the identification of major sources of system-wide cyber risk and the potential impact on financial stability

### Cyber Mapping
- Purpose: identify main technologies, services, and connections between financial sector institutions, service providers, and in-house or third-party systems to highlight key financial and technological connections (including FMIs).
- Benefits:
  - Identifies systemic institutions, service providers, and technology providers and their relationships in the financial system.
  - Provides a valuable reference for supervisors to identify key vulnerabilities and allocate resources.
- Examples and practice:
  - Norges Bank produced a map of the Norwegian financial sector setting out fundamental functions; sectoral agencies added detail to inform supervision and financial stability analysis.
- Challenges and pragmatic approaches:
  - Mapping can be expensive and time-consuming; the dynamism and complexity of the financial sector make it challenging.
  - Mapping exercises that do not aspire to completeness and that apply thresholds for inclusion, as well as qualitative approaches, have proved useful.

### Quantitative Analysis
- Motivation: accurate quantitative estimates of potential losses could inform firm risk management and financial stability analysis, but producing reliable estimates is difficult.
- Data and modeling challenges:
  - Limited availability of data on frequency and loss severity of cyberattacks.
  - Rapidly evolving nature of cyberattacks and the threat landscape complicates forecasting future losses.
  - Loss distributions are characterized by heavy tails, complicating formal statistical analysis.
  - The new operational risk framework of the Basel Committee could motivate more banks to collect operational risk data, including on cyber risk.
- Cost composition and measurement issues:
  - Total costs of cyber incidents include direct and indirect elements; indirect costs typically account for the majority.
  - Direct costs are incurred early and over a relatively short time period; indirect costs occur over a longer time period and are more difficult to attribute and quantify (declines in future revenue, lost productivity, devaluation of trade name, increased borrowing costs, etc.).
  - Insurance does not cover many indirect costs.
- Empirical findings:
  - Accenture study: average yearly cost of cybercrime for larger organizations is $13 million, a 72 percent increase over five years.
  - Aldasoro and others (2020): losses from cyberattacks are still only a small portion of operational losses, but can account for a significant share of total operational value at risk (VaR).
  - Bouveret (2018) Monte Carlo simulations:
    - 95 percent VaR loss estimated at $147 billion for financial institutions globally (14 percent of global net income).
    - Under a scenario where mean cyberattack frequency is set to two times its historical peak, the 95 percent VaR loss rises to $352 billion (34 percent of net income).

### Stress Testing
- Approach: financial institutions estimate the impact of cyberattacks on liquidity and capital under prescribed scenarios; supervisors review procedures and coverage against cybersecurity risk.
- Extensions:
  - Cyber risk scenarios can be included in stress testing and network analysis of FMIs.
  - Exercises encourage firms to develop better risk management practices.
- Case example and quantitative results:
  - Monetary Authority of Singapore firm-level cyber risk survey (2019 IMF FSAP):
    - On average, banks estimated losses from a direct cyberattack would amount to about 35–65 percent of quarterly net profits, depending on scenario type.
    - Estimated impacts on ratios: CAR and LCR would drop by 0.1–0.4 and 8.4–35 percent respectively.

### Regulatory and Supervisory Frameworks
- Role: regulation and supervision set consistent minimum standards to strengthen resilience and deliver public policy objectives (good cyber hygiene, expectations for risk management practices, incident reporting, response and recovery protocols, internal governance).
- Progress and fragmentation:
  - Good progress in strengthening regulatory requirements, but fragmentation within and across borders causes inefficiencies.
  - National requirements typically incorporate internationally recognized technical standards, but transposition differences into national frameworks complicate compliance.
  - Fragmented control environments raise compliance costs, especially for international financial institutions and entities active across financial industries.
- Harmonization efforts:
  - G7, FSB, and CPMI-IOSCO have published high-level principles.
  - Basel Committee is working on additional principles on operational resilience.
  - Guidelines have formed the basis for national standards in larger jurisdictions; many other jurisdictions have yet to finalize drafting and implementation due to lack of technical capacity and experience.

### Response and Recovery — Cyber Resilience
- Concept: cyber resilience is an organization’s ability to continue to carry out its mission by anticipating and adapting to cyber threats and other relevant changes and by withstanding, containing, and rapidly recovering from cyber incidents.
- Shifts in focus:
  - Movement from assumptions that attacks can be repelled toward pragmatic containment and continuity of operations.
  - Emphasis on maintaining critical business functions during disruptions to reduce incentives for attackers.
- Supervisory role:
  - Supervisors developing protocols that take an industry-wide view of critical financial services to ensure operations are maintained or can recover quickly.
  - Supervisors uniquely positioned to identify and observe incidents across institutions, share information broadly, and restore public confidence.
- Cross-border coordination:
  - Strengthening cross-border aspects of response and recovery arrangements is a top priority because financial institutions are connected across borders and recovery may rely on actions in other jurisdictions.
  - Very little infrastructure currently exists to allow necessary cooperation and information sharing internationally.
- Exercises:
  - Cybersecurity exercises and red-teaming are effective resilience assessment tools to test prevention, detection, mitigation, response, and recovery capabilities and to identify gaps in operational resilience and information sharing.

### Cyber Resilience in Emerging Market and Developing Economy Countries (Box summary)
- Challenges:
  - High-profile attacks have occurred in developing and emerging economies (Bangladesh Bank, banks in Chile, malware attack on Boleto Bancário in Brazil).
  - Global cybersecurity skill shortage: more than 4 million unfilled positions globally in 2019, up from just less than 3 million in 2018; per capita shortage most acute in low- and middle-income countries.
  - Limited budgets for advanced cybersecurity technologies and less competitive salary structures reduce capacity.
  - Risk that attackers may target small and vulnerable nations as advanced economies become more resilient.
- Consequences:
  - Successful cyberattacks can have profound effects on financial sector functioning and financing of the real economy; developing economies are less able to weather prolonged outages, risking broader confidence damage.
- Support and initiatives:
  - International programs and technical assistance (SWIFT Customer Security Program, Carnegie Endowment toolkit, UK Foreign and Commonwealth Office crisis-management exercises, Bank of France workshops, IMF/World Bank/IDB capacity development and workshops).
  - Need for expanded technical assistance and support for formal education and professional certification in cybersecurity.

### Information Sharing
- Importance: pooling information enhances situational awareness, helps detect new risks, builds better responses, and reduces collection costs for participants.
- Barriers:
  - Significant barriers to sharing include regulatory barriers and concerns about liability, especially across borders.
  - Information silos can be exploited by attackers operating across jurisdictions.
- Types of information sharing:
  - Threat Intelligence Information: source and nature of threats, targeted groups, technologies, intentions, high-frequency alerts, risk analytics, indicators, threat assessments, and analysis; typically shared on a continuous basis between trusted sources.
  - Incident Reporting: information on success of incidents, how they were addressed, and may include loss information; supervisors usually require reporting with an account of how the institution is managing the situation.
  - Good Practices: how incidents are reported and analyzed, responses taken, consequences, and resilience-building practices at institution and supervisor levels.
  - Defense Techniques: technical-level information on how an attack was prevented or contained.

*Source: IMF staff, "Further improving the identification of major sources of system-wide cyber risk and the potential impact on financial stability," SDN EA 2020.*

### 29. There are three broad channels of information sharing within the financial sector, and

### sdnea2020007 - 29. There are three broad channels of information sharing within the financial sector, and

### Channels of information sharing (levels of maturity)
- Private Sector Institution to Private Sector Institution
  - Well advanced in many financial systems, including among large global institutions.
  - Can be informal (personal relationships between chief information security officers) or formal (multilateral platforms such as the Financial Services Information Sharing and Analysis Center (FS-ISAC)).
  - Information is typically shared on a continuous basis in a trusted network and is highly valuable to risk managers.
- Private Sector Institution to Public Agency
  - Private financial institutions typically provide incident reports to their supervisors.
  - Routine protocols for regulatory reporting and trusted relationships between supervisors and institutions support this exchange.
- Public Sector to Public Sector Agencies
  - Financial supervisors may share incident reports and regulatory responses with other domestic agencies or with cross-border peers (examples include sharing between home and host supervisors).

### Legal, security, and reputational constraints on sharing
- Data protection and national security frameworks often limit what can be shared.
- Most reporting regimes provide some form of safe harbor for liability related to the incident itself, but generally do not protect the disclosing party from exposure of personal information.
- Difficulty disentangling incident information from customer data can leave residual liability.
- Information revealing institutional vulnerabilities or national security–related material is sensitive and raises legal, security, and practical considerations that constrain:
  - sharing between institutions,
  - sharing between financial institutions and national authorities,
  - international cooperation between national authorities.
- Financial institutions may fear reputational risk from disclosure of successful cyberattacks and thus be reluctant to share.

### Information taxonomy and templates for cybersecurity sharing
- Purpose: develop a structured approach to information and intelligence sharing to answer “why share, what to share, who to share with, how to share, and when to share.”
- High-Level Categorization of Information (Table 1)
  - Information that cannot be shared
    - Information sensitive to national defense concerns—e.g., cyber warfare related
    - Personally identifiable information
  - Information that could be shared
    - Details of cyber threats in near real time and approaches to defense; intelligence sharing
  - Information that should be shared
    - Situational awareness, risk management practices, technical vulnerabilities, patches, etc.
- Benefits of a common taxonomy and standardized incident-reporting template:
  - Support a one-stop-shop mechanism where firms report incidents to their “home” or “lead” supervisor or authority, which coordinates with other supervisors and authorities.
  - Facilitate two-way information flow so supervisors alert institutions to emerging issues, threats, or counterthreat measures.
  - Could draw on the FSB’s cyber lexicon and the high-level categorization in the note.
- Convening role for central banks and supervisors:
  - Where trusted networks are absent, central banks and supervisors can help promote information-sharing arrangements.
  - Supervisory colleges can be leveraged to share information and build trust.

### Examples of trusted networks and international arrangements
- FS-ISAC developed the CERES Forum for central banks, regulators, and supervisory authorities to receive timely, targeted information; tools and resources about cybersecurity threats; and threat mitigation strategies.
- International arrangements include initiatives for SWIFT and the Euro Cyber Resilience Board for pan-European Financial Infrastructures (ECRB) Cyber Information and Intelligence Sharing Initiative.
- Trusted networks enhance quantitative financial stability analysis and stress testing by enabling use of existing data consortia platforms.

### Deterring cyber threats: law enforcement and international cooperation
- Cyberattacks are global and rapidly evolving, posing challenges to policing, prosecution, sanctioning, and asset recovery.
- Example: Operation Taiex in March 2019 led to the arrest of the organizer behind the Carbanak and Cobalt malware attacks on over 100 financial institutions worldwide; investigators found attackers operating in at least 15 countries.
- International legal frameworks and political sensitivities:
  - The 2001 Budapest Convention is the only binding multilateral agreement aimed at combating cybercrime; offenses include (1) offenses against the confidentiality, integrity, and availability of computer data and systems; (2) computer-related offenses; (3) content-related offenses; and (4) criminal copyright infringement.
  - In November 2019 a United Nations cybercrime resolution set up a drafting group to establish terms of reference for a new global cybercrime treaty; international constituency is divided over fears of criminalizing ordinary online activities.
- Scale of criminal proceeds and AML/CFT implications:
  - Some studies estimate that ransomware incidents alone generate some $1 billion in illegal proceeds every year (McGuire 2018).
  - Proliferation of digital currencies that, when unregulated, provide anonymity makes it easier to generate and launder proceeds of cybercrime.
  - Effective implementation of comprehensive AML/CFT frameworks is crucial: private sector firms should identify customers, maintain relevant records, monitor transactions, and report suspicious transactions to relevant authorities to prevent and combat cybercrime and laundering of proceeds.
- Recommendations for deterrence:
  - Make cyberattacks expensive and risky through seizure and confiscation of proceeds, identification and sanctioning of bad actors.
  - Success depends on effective international cooperation (information sharing and formal mutual legal assistance); without cooperation, cybercriminals shift to noncooperating jurisdictions.

### International and institutional initiatives (Box 2 summary)
- International standard-setting bodies working on common language and approaches include the FSB, BCBS, CPMI, IOSCO, and the G7.
  - Outputs include the FSB Cyber Lexicon (FSB 2018), Cyber Incident Response and Recovery toolkit (FSB 2020), BCBS Cyber Resilience Range of Practices (BIS 2018), CPMI/IOSCO principles for FMIs (CPSS 2012), and associated guidance on cyber resilience (BIS CPMI and IOSCO 2016).
- International financial institutions (World Bank, Inter-American Development Bank, IMF) focus on capacity development.
  - IMF activities include work with financial supervisors in low-income countries, incorporation of cyber risk into financial sector surveillance, analytical tool development, and technical assistance.
  - An annual workshop for supervisors in low-income countries was launched in 2017.
  - Regional technical assistance centers provide region-specific workshops; bilateral technical assistance focuses on improving national regulatory and supervisory frameworks.
  - Incorporation of cyber stress testing and cyber risk supervision into the FSAP is under way; a pilot supervision exercise as part of an FSAP was completed in Norway in 2020.
- Private and nonprofit organizations supporting information sharing and standards include Global Cyber Alliance, Cyber Defence Alliance, Financial Services Information Sharing and Analysis Center, and the Cyber Risk Institute.

### Priority areas for future work (findings and policy recommendations)
- Improving Cyber Risk Analysis and Integration into Financial Stability Analysis
  - Use of tools such as cyber mapping, stress testing, and improvements to quantification of potential impacts would enhance financial stability analysis and resource allocation.
- Greater Consistency in Regulatory Frameworks
  - Financial supervisors could develop and promote greater consistency in national cybersecurity regulatory frameworks.
  - Building on the FSB cyber lexicon and effective practices, international standard setters could improve consistency to enhance information sharing, cooperation in response and recovery, and reduce compliance burden.
  - Outreach, capacity development, and public-private partnerships could promote broad use of international standards.
- Enhancing Operational Resilience, Response, and Recovery
  - Require financial institutions to develop and test response and recovery procedures to ensure operational continuity during major incidents.
  - National authorities should develop clear and effective response protocols for crisis scenarios with system-wide spillovers and test them regularly.
  - Develop and regularly test regional and international protocols for cross-border crisis management (e.g., national and international cyber crisis exercises).
- Strengthening Information Sharing
  - Identify and address obstacles to exchanging cybersecurity-related information cooperatively between financial institutions and supervisors.
  - Agree on what to share, when to share, how to share, and who to share with.
  - Central banks, policymakers, and supervisors should encourage and support institutions in establishing and using trusted information-sharing platforms.
  - Adopt a commonly agreed and internationally used template for information sharing built on a clear lexicon to reduce barriers.
- Intensify the Defense against Cyberattacks
  - Build strong domestic investigative and enforcement capabilities and enhance cross-border coordination.
  - Intensify law enforcement cooperation and reduce information-sharing barriers.
  - More effective implementation of AML/CFT frameworks will strengthen prevention, support law enforcement, facilitate recovery of proceeds, and reduce opportunities for cybercrimes.

*Source: sdnea2020007 (IMF PDF chapter content).*

### 44. Building skills, resources, and operational capacity in all countries would have a global

### 44. Building skills, resources, and operational capacity in all countries would have a global

### Global impact and policy role
- Cyber risk affects both advanced economies and low-income countries; countries that fall behind in their ability to resist and respond to attacks will suffer disproportionately as other countries build stronger defenses.
- Attacks on countries strongly linked to the global financial system could spill over to others and endanger global financial stability.
- The international community has various programs to assist low-income countries with technical skills and resources; additional attention to capacity and global financial stability concerns would benefit the global community as a whole.
- International financial institutions, including the IMF, have an important role in supporting capacity building and delivering technical assistance to financial supervisors and central banks in developing economies to help them identify, measure, monitor, and address risks to financial stability posed by cyber risks.
- Strengthening capacity is imperative given the increasing digitalization of financial services delivery and the entry of many new providers, which may present new vulnerabilities.

### Appendix I — Financial Market Infrastructures (FMIs): key findings and scenarios
- FMIs are key nodes in the financial system: often connected to most participants, responsible for a large volume of transactions daily, and highly dependent on technology—making them a serious cyber risk concern.
- Successful cyberattacks on FMIs have the potential to transmit shocks to direct participants, other FMIs and their customers, and markets.
- Possible successful-attack scenarios relate to confidentiality, service availability, and integrity.
- A successful cyberattack on a systemically important payment system that processes large-value and time-critical transactions could transmit disruption to the entire financial system (across borders as well as domestically) with system, institutional, and environmental interdependencies.
- Cyberattack on Payment Systems and Possible Transmission Paths (Figure 6) illustrates transmission channels across participants, FMIs, and markets.
- Evidence on systemic spillovers:
  - According to Eisenbach, Kovner, and Lee (2020), the impairment of any of the five most active US banks can affect as much as 38 percent of the network.
  - Using a reverse stress test, the same study found that interruptions originating in some banks with less than $10 billion in assets may be sufficient to impair a significant proportion of the system.
- FMIs have been identified as critical infrastructures in some jurisdictions, requiring incident reporting and regulatory cooperation with the national cybersecurity agency.
- Because FMIs are highly concentrated, connected, and systemic, cyber threats to FMIs are increasingly considered a key risk to financial stability.

### FMI mitigation practices and supervisory measures
- Core measures for FMIs:
  - FMIs are normally required to have comprehensive information security policies, standards, practices, and controls as part of their operational risk-management framework.
  - FMI critical service providers (CSPs) such as IT and messaging services are expected to meet the same standards on information security to ensure continuous and adequate performance.
  - Further guidance focuses on governance, risk management frameworks, settlement finality, operational risks, and FMI links.
- Peripheral measures:
  - Enhancing endpoint security at banks, FMIs, and nonbank financial institutions aims to reduce the risk of wholesale payment fraud.
- Central bank and authority actions:
  - Some central banks have established cyber resiliency frameworks that comprise critical infrastructure such as central-bank-operated FMIs.
  - Efforts include expanding surveillance coverage, reinforcing protection capabilities, reducing time to recover, and developing cyber competencies.
- ECB operationalization of CPMI-IOSCO guidance:
  - Five primary risk management categories: (1) governance, (2) identification, (3) protection, (4) detection, and (5) response and recovery.
  - Three overarching components: (1) testing, (2) situational awareness, and (3) learning and evolving.
  - Although designed in the European Union, the approach could be used by other authorities and FMIs.
- CSP oversight and endpoint security improvements:
  - For SWIFT, authorities committed to considering legal reviews to investigate how moral suasion could be combined with a regulatory backstop, broaden membership of the SWIFT Oversight Forum, and improve information sharing on SWIFT oversight and assurance reports.
  - Authorities have set oversight priorities to monitor the effectiveness of the SWIFT Customer Security Program.

### Appendix II — Outsourcing and third-party risk: risks and supervisory options
- Third-party risk management—including cyber risk—is gaining importance as the number and scope of outsourced services continue to grow; some providers service a large portion of the sector.
- Concentration in a limited number of providers creates challenges for regulators and supervisors because they are key contributors to financial stability risk; cybersecurity failures in a major third-party provider could have a very serious impact on the sector as a whole.
- Typical supervisory and policy aspects covered in jurisdictional policies:
  - A. Soundness of governance arrangements in the outsourcing institutions
  - B. Adequacy of pre-outsourcing risk analysis, due diligence, and contracting
  - C. Security of information and systems
  - D. Notification procedures for sub-outsourcing
  - E. Robustness of operational resilience arrangements
  - F. Right to access and audit the vendor (both by the outsourcing institutions and the supervisor)
  - G. Effectiveness of termination rights and exit strategies
- International guidance progress:
  - Examples include the G7 fundamental elements for third-party cyber risk management in the financial sector and the Financial Stability Board publication “Third-Party Dependencies in Cloud Services—Considerations on Financial Stability Implications.”
- Supervision in practice remains challenging; critical vendors are typically not subject to the same depth of supervision as regulated financial institutions.
- Proposed supervisory models for critical providers:
  - Intensive supervision akin to utilities by a dedicated agency in charge of all critical infrastructure.
  - A trusted independent certification program where an agreed-on third party sets or attests to security standards in service providers.
  - Direct supervision by the financial sector supervisory agencies.
- Global cooperation is needed since dominant service providers are global in nature.

*Source: sdnea2020007 - "44. Building skills, resources, and operational capacity in all countries would have a global" (IMF).*

---


_Source: https://www.imf.org/-/media/files/publications/sdn/2020/english/sdnea2020007.pdf_
