## wp17185

## Source details

**Canonical URL:** [wp17185](https://www.imf.org/-/media/files/publications/wp/2017/wp17185.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/wp/2017/wp17185.pdf.md)
- [Structured JSON version](/-/media/files/publications/wp/2017/wp17185.pdf.json)

---

### Introduction and scope
- Increased digitalization brings efficiency gains for financial institutions and fosters financial inclusion but also creates a range of new and partially understood risks that evolve quickly and take multiple forms.
- One key risk is cyber-attacks against financial institutions; these are becoming more common and considerably more sophisticated.
- Financial market infrastructures have been attacked; dependence on a relatively small set of technical systems means downtimes and service disruptions can have widespread and systemic knock-on effects.
- Cyber-attacks occur with increasing frequency amid ever-decreasing costs of technology; the economic aspects of cybersecurity are gaining importance and visibility.
- Definitions cited:
  - "Incidents are security events that compromise the integrity, confidentiality or availability of an information asset. Breaches are incidents that results in the confirmed disclosure (not just potential exposure) of data to an unauthorized party (see Verizon, 2013)."
  - "The Internet of Things are everyday electronic devices that are connected to the internet, and send and receive data. Examples include cell phones, car electronics, and smart devices but also household appliances (thermostats, refrigerators, etc.)."

### Evidence, incident patterns, and notable examples (Box 1)
- Empirical findings and incident patterns:
  - Verizon (2016) survey: "the finance industry in 2015 has seen by far the most incidents with confirmed data losses."
  - Web application attack patterns in the U.S. financial industry rose from 31 percent in 2014 to 82 percent in 2015 (Verizon, 2017).
  - About two thirds of attacks on the U.S. financial sector involved ATMs; databases and servers each accounted for 20 percent (Verizon, 2017).
  - Denial-of-service (DoS) attacks constituted 34 percent of all incidents (not breaches) per Verizon (2017).
  - Typical timelines:
    - Perpetrators usually enter a system in less than an hour.
    - 61 percent of attacks and 65 percent of breaches took weeks or more to discover.
    - Discovery sources: one in three breaches is discovered by external fraud detection providers; law enforcement discovers 20 percent; customers discover 15 percent (customers detect one in seven breaches in financial services, double the cross-industry average).
- Recent high-profile incidents:
  - 2016 Bangladesh Bank: Criminals stole US$81 million after infecting the bank’s SWIFT server; criminals sent transfer messages worth almost US$1 billion USD; some transfer messages were stopped due to a typographic error.
  - February 2017 KfW: erroneously transferred $5.4 billion to four other banks reportedly due to a technical problem repeating single transfers multiple times.
  - March 2013 DarkSeoul malware: attacks against three South Korean banks erased files, halted branch operations, disrupted money transfer and ATM operations, infected 48,000 computers and induced losses estimated at US$738 million.
  - September 2014 Corkow malware: criminals used Corkow to execute several high value dollar trades totaling $400 million over a 14-minute period, causing a sudden 15 percent price swing in the USD/Ruble exchange rate.

### Cost phases and magnitude of cyber events
- Cost phases (as catalogued in Table 2):
  - Prevention (continuously): cybersecurity costs; regulatory compliance costs; opportunity cost.
  - Reaction (immediate): technical investigation; stop intrusion and recover systems; customer notification; operational disruption; loss in revenue; loss in equity value.
  - Impact management (short-term): infrastructure/process adjustment; system/data recovery; post-breach customer protection; initiation of cyber audit; attorney and litigation cost; loss in revenue; loss in equity value; customer turnover.
  - Business recovery and remediation (medium- to long-term): increased funding costs; lower future demand for breached firm’s services; redesign of processes; rebuilding reputation; investment in security systems.
- Key magnitude observations:
  - More than 90 percent of the total costs are attributable to indirect factors.
  - Around 60 percent of attacked firms report revenue and customer losses of up to 20 percent.
  - Close to 10 percent report losses exceeding 80 percent of revenue.
  - Revenue losses and long-term cost of losing customers together make up three quarters of the estimated total cyber-event cost in the U.S.
  - Available annual cost estimates:
    - Global cyber losses estimated at $250 billion to $1 trillion.
    - U.S. estimates range from $24 billion to a quarter trillion a year (0.1 to 1.3 percent of U.S. GDP).
  - Internet-related economic contribution and comparison (IMF staff calculations based on cited sources; based on 2015 U.S. real GDP of $17.9 trillion; nominal values in USD billions):
    - Internet contribution to GDP: 3.2% 573 / 6.0% 1,074
    - Cyber losses: 0.6% 100 / 2.2% 400
    - Net benefit: 1.0% 173 / 5.4% 974

### Cyber insurance: structure, limits, and market issues (Box 2)
- Coverage structure:
  - First-party losses: crisis management; customer notification; network business interruption and associated direct cost; systems recovery; reconstitution of damaged software and digital assets.
  - Indemnifiable third-party losses: third party liability for security breaches and data privacy; defense costs; liability for failing to defend; investigation costs; potentially penalties and fines.
- Empirical statistics:
  - In 2016, 13 percent of all cyber insurance claims sampled by NetDiligence (2016) were caused by third-party vendors.
  - In 2016, 17 percent of all cyber insurance claims sampled by NetDiligence (2016) affected the financial services sector.
  - In practice, even the largest financial firms have difficulties getting coverage limits of more than US$300 million.
  - Current conservative coverage limits typically around $25 million (noted elsewhere in the source).
- Market development and concentration:
  - Pricing is challenging due to complex risk aggregation and risk correlation.
  - Actuarial modeling techniques are underdeveloped; insurers add cushions to premiums.
  - A.M. Best (2017) projections and data:
    - Market for cyber insurance in the U.S. will see substantial growth, with coverages increasing up to $20 billion by 2020.
    - In 2016, direct premiums written increased by one third year-on-year, expanding cyber insurance premium volume to $1.3 billion.
    - The largest three insurance writers (AIG, Chubb, and XL Group) cover 40 percent of the market; top-15 insurers serve 83 percent of the market.
    - Cyber insurance policies’ direct loss ratio is around 50 percent.
- Limitations:
  - Policies typically do not cover indirect medium- to long-term costs (reputational damage; lost customer relationship value; increased funding costs and insurance premiums; ex-post defense upgrades).
  - Partial availability and restrictive exclusions can leave tail risks uncovered and create concentration of exposures within insurers.

### Market failures, informational problems, and economic drivers of underinvestment
- Information asymmetries:
  - Effective monitoring is "either impossible or extremely costly."
  - Firms lack reliable ex-ante information on extent of exposure, effectiveness of defenses or third-party providers, resilience of market infrastructure, and appropriate liability insurance levels.
  - Asymmetry induces moral hazard and adverse selection; firms may under-invest in security.
  - Drivers: inexperience with cyber risk, heterogeneity and rapid evolution of risks, reputation and insurance premium concerns leading firms to withhold information.
- Strategic complementarities and coordination failures:
  - Investment in cybersecurity has positive externalities; marginal returns to a firm’s security investment increase when others invest.
  - Multiple equilibria possible; without coordination, the system can settle at a low-investment equilibrium.
  - Software flaws and network externalities induce common exposures and incentives to free-ride.
  - Cisco (2017) evidence: U.S. is well above the 61 percent cross-peer country average on maturity of software security; financial sector uses relatively high-maturity software with low share of low- and middle-maturity products.
- Economies of scale, barriers to entry, and concentration:
  - Cybersecurity services market dominated by few providers due to increasing returns; oligopolies produce correlated risks across clients.
  - Insurance market concentration: fixed costs and learning lead to concentration; insurers may be unable to absorb highly correlated systemic losses.

### Systemic transmission channels and financial stability concerns
- Main sources of systemic cyber risk:
  - Access vulnerabilities: financial system is highly connected and “only as good as the weakest link.”
  - Risk concentration: key FMIs, CCPs, messaging systems (e.g., SWIFT), and a small number of institutions handle large transaction volumes; technical and IT concentration (operating systems, cloud servers, hubs) create low external redundancy.
  - Risk correlations and contagion:
    - Idiosyncratic cyber shocks can trigger funding liquidity risks, morph into market liquidity shocks as firms shed assets, depressing prices.
    - Concerns over counterparty integrity can lead firms to stop interacting, exacerbating liquidity recycling pressures.
    - An institution’s inability to meet payment/settlement obligations because internal systems are compromised can cause a name crisis with adverse funding liquidity effects and knock-on effects.
    - Liquidity shortages can lead to fire-sales, depressing asset valuations, eroding capital, and weakening solvency positions.
- As interdependency, interconnectivity, and complexity increase, the probability that an external cyber shock transfers to the financial system and becomes systemic is likely to increase even if mitigation steps are taken.

### Regulatory framing, supervisory expectations, and standards
- Cyber risk is framed as operational risk: "risk of loss resulting from inadequate or failed internal processes, people and systems or from external events."
- Supervisory guidance and expectations:
  - Minimum standards focus on risk management and recovery/business continuity planning.
  - Firms should adopt integrated, risk-based approaches: identify, manage, and report IT-related risks through risk management functions.
  - Regulatory capital treatment: operational risk frameworks require quantifying tail risks; banks set aside capital for operational risk as sum of expected and unexpected losses; scenario analysis with external data is integral.
- Standards and sectoral guidance:
  - Basel Core Principles, Principles for the Sound Management of Operational Risk, Basel Capital Accord, and guidance on IT security and information management underpin expectations.
  - Explicit standards for securities and derivatives market infrastructures (payment, clearing, settlement) due to systemic spillover potential; IOSCO/CPMI guidance requires high standards.
- Supervisory capacity recommendations:
  - Supervisors need flexibility and forward-looking assessment capabilities; must view cyber as a business and economic risk, not only IT.
  - Data, reporting, and law enforcement coordination: reliable cyber risk reporting systems, incentives for timely and accurate event reporting, and formal two-way arrangements with law enforcement are recommended.

### Critical infrastructure approach and public-private coordination (Box 3)
- Prioritization and definition:
  - Differentiated approach: define critical financial sector infrastructure and institutions to set effective cyber responses.
  - Jurisdictions (United States, Japan, EU directives) have begun formal identification processes; EU Network and Information Security Directive addresses need to identify critical infrastructure.
- Public-private partnerships:
  - Provide pragmatic channels for information sharing and coordination given limited private incentives to disclose attacks.
  - Example: U.S. Cybersecurity Framework — voluntary risk-based industry-wide standards, guidelines and best practices.
- Jurisdictional measures (selected):
  - U.S.: FFIEC assessments to support smaller banks; SEC and FINRA examinations for broker-dealers; BHCs expected to recover within two hours; enhanced standards proposed for institutions with total consolidated assets of $50 billion or more; standards tiered and not applied to community banks.
  - Europe/UK: EU Cybersecurity Strategy (2013); NIS directive; UK vulnerability testing frameworks (Waking Shark I/II; CBEST).
  - Japan: Cybersecurity Strategy (2013) strengthening public-private sharing and business continuity exercises.
  - Singapore: National Cyber Security Masterplan 2018.
  - Australia: Australian Cyber Security Centre (ACSC).
  - India: National Cyber Security Policy (May 2013).
- Firm-level resilience measures recommended:
  - Application whitelisting; standardized secure system configurations; rapid patching processes; limit number of administrator privileges.
  - Emphasize incident response and continuity planning; cybersecurity awareness and education; contractual controls with counterparties and third-party providers.
- Information asymmetry mitigation:
  - Collect and share standardized cyber loss data; develop common terminology and definitions; aggregate and anonymize firm-level data for disclosure; institutionalize public-private information sharing among law enforcement, supervisors, regulators and private sector.
- Policy design balance:
  - Cybersecurity requires both ex-ante regulation and ex-post liability.
  - Ex-ante regulation may be ineffective where information asymmetries persist; ex-post liability may fail when firms lack means to cover full scope of damages.
  - "Both ex-ante regulation and ex-post liability could slow down or prevent innovation" because vulnerabilities may be detected only after deployment.
  - Policy implication: find the right balance to improve resiliency without stifling innovation; use high-level principles complemented by bespoke firm-level guidance; continuously refine regulatory architecture as digitalization progresses.
- International coordination:
  - Aggregation of cyber risk is too complex for individual firms or countries; global multilateral action and coordination (BIS, FSB, IMF) are needed to collect/disseminate information, foster cross-border policy coordination, and design coordinated policies.

### Policy recommendations and key takeaways
- Firms: adopt risk-based, integrated cybersecurity management; invest in incident response, continuity planning, and workforce awareness; control third-party and upstream dependencies via contractual and risk-management mechanisms.
- Regulators and supervisors: treat cyber as an operational and economic risk; require scenario analysis; set and validate tail-loss assessments; develop flexible, forward-looking supervisory approaches; coordinate with law enforcement.
- Public sector and international organizations: reduce information asymmetries via standardized data collection and anonymized aggregation; facilitate public-private partnerships; support international policy coordination and multilateral solutions to systemic cyber risk.
- Insurance market: promote data sharing to improve actuarial modeling and pricing; monitor concentration risks in insurers and third-party providers; encourage market completeness while recognizing current coverage limitations.
- Overall objective: build resilience at firm, market, and system levels through a calibrated mix of ex-ante regulation, ex-post liability, market instruments, information sharing, and international coordination—balancing security and continued innovation.

*Source: IMF Working Paper wp17185, selected boxes and sections.*

### References ________________________________________________________________32

### References ________________________________________________________________32

### Introduction
- Increased digitalization brings efficiency gains for financial institutions and fosters financial inclusion but also creates a range of new and partially understood risks that evolve quickly and take multiple forms.
- One of the key risks is cyber-attacks against financial institutions; these are becoming more common and considerably more sophisticated.
- Large-scale data breaches "feature prominently in the media."
- All types of banks—from small community and regional banks to the U.S. largest bank holding companies—money transfer services, and third party payment processors have seen their systems compromised.
- Financial market infrastructures have been attacked, and given the financial system’s dependence on a relatively small set of technical systems, knock-on effects from downtimes and service disruptions due to successful attacks have the potential to be widespread and systemic.
- Cyber-attacks occur with increasing frequency amid ever-decreasing costs of technology.
- The economic aspects of cybersecurity are gaining increased importance and visibility, and the days when cyber risk was understood as a pure IT problem are now gone.
- Today, many countries set the development of a cybersecurity industry and standards as key policy objectives.

### Definitions and scope
- "Incidents are security events that compromise the integrity, confidentiality or availability of an information asset. Breaches are incidents that results in the confirmed disclosure (not just potential exposure) of data to an unauthorized party (see Verizon, 2013)."
- "The Internet of Things are everyday electronic devices that are connected to the internet, and send and receive data. Examples include cell phones, car electronics, and smart devices but also household appliances (thermostats, refrigerators, etc.)."

### Evidence and examples cited
- Verizon (2016) survey: "the finance industry in 2015 has seen by far the most incidents with confirmed data losses."
- Box 1: "Recent Cyber Attacks on the Financial Services Industry" (listed in the source's box inventory).
- Box 2: "Cyber Insurance."
- Box 3: "Approach to Critical Infrastructure."

### Visuals and data references
- Figure 1: "Internet of Things: Devices Connected to the Internet (August 2014)" — Source: Shodan (2017).
- Figure 2: "Sources of Threat by Type of Actor (March 2017)."
- Figure 3: "Impact, Shock Transmission, and Control."
- Figure 4: "Cyber Risk Management."
- Figure 5: "Coverage Limits and Effective Risk Coverage."
- Figure 6: "Maturity of Software Security."
- Figure 7: "Regulatory Architecture for Cyber Risk."
- Table 1: "Cyber Risk Aggregation Levels."
- Table 2: "Cost of Cyber Events."
- Table 3: "Estimated Annual Costs of Cyber Risk."
- Table 4: "United States: Benefits, Costs, and Economic Net Benefit of Internet Use."

### Notable observations from the excerpt
- "Virtually everybody is exposed to cyber risk in some form."
- "The financial sector is a popular target."
- The incident distribution figure labels organizations by size categories: "Small organizations (<=1K employees)", "Large organizations  (>1K employees)", and "Unknown."
- Industry categories shown include: "Other industries", "Utilities", "Other services", "Transportation", "Administrative", "Educational", "Manufacturing", "Entertainment", "Professional", "Healthcare", "Retail", "Public", "Information", "Unknown", "Accommodation", "Finance."
- Figure caption: "Incidents with Confirmed Data Loss, Per Industry (2015)" — Source: Verizon. IMF staff illustration.

*Source: wp17185 - References ________________________________________________________________32*

### Box 1. Recent Cyber Attacks on the Financial Services Industry

### Box 1. Recent Cyber Attacks on the Financial Services Industry

### Recent high-profile incidents
- Transfer fraud via compromised SWIFT servers: 2016 Bangladesh Bank
  - Criminals stole US$81 million from the central bank of Bangladesh after getting malware onto the bank’s SWIFT server that defeated business process controls, allowing the criminals to send transfer messages worth almost US$1 billion USD; some transfer messages were stopped due to a typographic error.
  - February 2017: KfW, a German development bank, erroneously transferred $5.4 billion to four other banks, reportedly due to a technical problem that repeated single transfers multiple times.
- Destructive attacks: 2013 DarkSeoul malware
  - March 2013 attacks against three South Korean banks erased files, halted some branch operations, disrupted money transfer and ATM operations, infected 48,000 computers and induced losses estimated at US$738 million.
- Malware on a trading terminal: 2016 Corkow malware
  - In September 2014 criminals used Corkow malware to execute several high value dollar trades totaling $400 million over a 14-minute period, causing a sudden 15 percent price swing in the USD/Ruble exchange rate.

### Attack patterns, detection, and timelines
- Web application attack patterns in the U.S. financial industry rose from 31 percent in 2014 to 82 percent in 2015 (Verizon, 2017).
- About two thirds of attacks on the U.S. financial sector involved ATMs; databases and servers each accounted for 20 percent (Verizon, 2017).
- Denial-of-service (DoS) attacks constituted 34 percent of all incidents (not breaches) per Verizon (2017).
- Typical timelines and discovery:
  - Perpetrators usually enter a system in less than an hour.
  - 61 percent of attacks and 65 percent of breaches took weeks or more to discover.
  - Discovery sources: one in three breaches is discovered by external fraud detection providers; law enforcement discovers 20 percent; customers discover 15 percent (customers detect one in seven breaches in financial services, double the cross-industry average).

### Systemic nature of cyber risk and attribution challenges
- The internet’s anonymity complicates identification and attribution of cyber threats; the financial industry uses threat-motivation-capability analysis and cyber threat maps to illustrate exposure.
- Main sources of systemic cyber risk: exposures to access vulnerabilities, risk concentration, risk correlation and contagion.
- Market failures and informational problems:
  - Information asymmetries, misaligned incentives, strategic complementarities, and externalities can lead to underestimation and mispricing of cyber risk.
  - The market for cyber risk transfer can fail, producing inefficient risk allocation across the financial system.
- Policy uncertainty: It is unclear what the best policy response to systemic cyber risk is, including design of ex-ante regulation, assignment of ex-post liability, and the appropriate roles for firms, governments, and international financial institutions.

### Cyber risk aggregation and externalities
- Cyber risk aggregation levels (ranked by degree of control an individual institution may have):
  - Internal communication and information technology: Hardware, software, servers, staff, data.
  - Counterparties and business partners: Interbank relationships, joint ventures, associations.
  - Outsourcing and contracting: IT and cloud providers; outsourced legal, HR, or consulting activities.
  - Technological externalities: Internet of Things; automatization of services; artificial intelligence.
  - Upstream infrastructure: Electricity; telecommunication; internet access.
  - Feedback loops: Interrelationships between technologies and industries leading to cascading effects.
  - External shocks: International conflicts; viruses, pandemics — nearly impossible to predict.
- External and upstream dependencies (electricity, telecoms, market infrastructures) are outside individual firms’ control and complicate risk management even with MOUs and contractual arrangements.

### Costs of cyber events: phases and magnitudes
- Cost phases (Table 2):
  - Prevention (continuously): cybersecurity costs; regulatory compliance costs; opportunity cost.
  - Reaction (immediate): technical investigation; stop intrusion and recover systems; customer notification; operational disruption; loss in revenue; loss in equity value.
  - Impact management (short-term): infrastructure/process adjustment; system/data recovery; post-breach customer protection; initiation of cyber audit; attorney and litigation cost; loss in revenue; loss in equity value; customer turnover.
  - Business recovery and remediation (medium- to long-term): increased funding costs; lower future demand for breached firm’s services; redesign of processes; rebuilding reputation; investment in security systems.
- More than 90 percent of the total costs are attributable to indirect factors.
- Verizon (2017) / Cisco (surveys) findings on impacts:
  - Around 60 percent of attacked firms report revenue and customer losses of up to 20 percent.
  - Close to 10 percent report losses exceeding 80 percent of revenue.
  - Revenue losses and long-term cost of losing customers together make up three quarters of the estimated total cyber-event cost in the U.S.
- Available annual global and U.S. cost estimates:
  - Global cyber losses estimated at $250 billion to $1 trillion.
  - U.S. estimates range from $24 billion to a quarter trillion a year (0.1 to 1.3 percent of U.S. GDP).
- Internet-related economic contribution and comparison (U.S., IMF staff calculations based on cited sources):
  - Internet contribution to GDP: 3.2% 573 / 6.0% 1,074
  - Cyber losses: 0.6% 100 / 2.2% 400
  - Net benefit: 1.0% 173 / 5.4% 974
  - Notes: Based on 2015 U.S. real GDP of $17.9 trillion. Nominal values are given in USD billions.

### Cyber risk management options and market instruments
- Risk management approaches:
  - Risk reduction: ex-ante security measures (physical, digital, human controls), preparedness, business continuity planning; security measures are costly and can affect usability and performance.
  - Risk avoidance: redesigning activities, products, processes or business models to reduce exposure; new technologies can create new vulnerabilities.
  - Risk transfer: cyber liability insurance or transferring operational risk to third-party service providers.
- Cyber insurance:
  - Can improve risk allocation by incentivizing firms to invest in defense and increase transparency; insurers collate data to better understand event frequency and nature.
  - Current policy characteristics limit coverage: conservative coverage limits (typically around $25 million), restrictive exclusions and conditions, reflecting partial information and rapidly changing risk.
  - Result: potentially missing or incomplete markets for cyber risk insurance.
- Third-party service providers and indirect intermediary liability:
  - Shared service providers can create economies of scale and positive externalities; using multiple suppliers can reduce concentration risk.
  - Re-concentration risk remains if multiple suppliers rely on a common component (e.g., a shared operating system).
  - Third-party providers may be uninsured or underinsured; low coverage limits and pricing difficulties can leave residual systemic exposure.

### Policy implications and roles for public institutions
- Negative externalities in the private market justify a public-sector role to reduce information asymmetries and limit systemic spillovers from individual firm breaches.
- International financial institutions (Bank for International Settlements, World Bank, IMF) are positioned to collect and disseminate information and foster cross-border policy coordination to address informational and coordination challenges posed by systemic cyber risk.
- Effective resilience-building requires active risk management at firm, market, and system levels, combined with appropriate regulation and international cooperation.

*Source: IMF — Box 1. Recent Cyber Attacks on the Financial Services Industry, wp17185.*

### Box 2. Cyber Insurance

### Box 2. Cyber Insurance

### Structure and scope of cyber liability insurance
- Cyber liability insurance is structured to transfer indemnifiable first and third party losses.
- First-party losses include:
  - cost of crisis management;
  - customer notification;
  - network business interruption and associated direct cost;
  - systems recovery;
  - reconstitution of damaged software and digital assets (which would normally be covered under comprehensive crime insurance).
- Indemnifiable third-party losses include:
  - third party liability for security breaches and data privacy in general;
  - defense costs;
  - liability for failing to defend against a cyber-attack;
  - investigation costs; and
  - potentially, penalties and fines.

### Empirical observations and key statistics
- In 2016, 13 percent of all cyber insurance claims sampled by NetDiligence (2016) were caused by third-party vendors.
- In 2016, 17 percent of all cyber insurance claims sampled by NetDiligence (2016) affected the financial services sector.
- In practice, even the largest financial firms have difficulties getting coverage limits of more than US$300 million.

### Coverage limitations and market inefficiencies
- Cyber insurance policies typically do not cover indirect costs from cyber-attacks that manifest over the medium- to long-term, including:
  - reputational damage;
  - lost value of customer relationship;
  - increased funding costs and insurance premiums;
  - the cost of having to beef up defense systems ex post to increase resilience against cyber risk.
- Such exclusions can be explicit or implicit by imposing coverage limits and very restrictive liability exclusions.
- Partial availability of coverage can render the market-based risk transfer mechanism inefficient, not covering unexpected losses in the tail of the distribution.
- There are concerns that risk exposures are becoming more concentrated in the insurance market and that the insurance companies involved may not be able to withstand a large and correlated loss triggered by a systemic cyber-attack.

### Pricing challenges and market development
- Pricing cyber risk and liability insurance policies is challenging due to:
  - complex risk aggregation;
  - correlation of different risks in case of an event, which makes cyber risk difficult to measure and even harder to price.
- The field is relatively new, and both firms and customers have very little experience with the characteristics of cyber risk or the longer-term effects of cyber-attacks and breaches on business relationships.
- Actuarial modeling techniques are underdeveloped compared to those for other insurable risks.
- Insurance companies have responded by adding a considerable cushion to the premium, causing premiums to be higher relative to other types of coverage.
- These difficulties in pricing can:
  - undermine the provision of financial protection;
  - leave gaps in coverage;
  - lead to an inefficient pricing and allocation of risks throughout the system.

### Role of cyber insurance in risk management
- Cyber insurance is not a panacea for managing cyber risk and cannot replace active cyber risk management in financial firms.
- As insurance companies gain more experience with cyber risk insurance and the market matures:
  - the pricing of policies and the allocation of risks in the financial system are expected to become more efficient;
  - markets will be more complete;
  - cyber liability insurance will more efficiently transfer and pool risk.

*Source: Box 2. Cyber Insurance, wp17185*

### introduction of software liability would slow down innovation. and that it would basically be

### wp17185 - introduction of software liability would slow down innovation. and that it would basically be

### A. Information Asymmetries
- Effective monitoring in cyberspace is "either impossible or extremely costly."
- Firms often lack the information needed to make informed decisions about how to best manage cyber risk, including how much to invest in cyber security.
- Firms cannot reliably judge ex-ante:
  - the extent of cyber risk they are exposed to,
  - the effectiveness of defensive systems or third-party cybersecurity services,
  - the resilience of market infrastructure the firm’s operations rely on,
  - how high a liability insurance may be needed as to meet the long-term impacts of cyber-attacks.
- Asymmetry in information induces both moral hazard and adverse selection problems, which can undermine system functioning.
- If asymmetrically distributed information is a systematic feature of the cyber system, the overall level of security will be below the socially optimal level.
- Drivers of information asymmetries:
  - Inexperience with cyber risk and events complicates quantification of cyber risk exposures.
  - The nature of risks is diverse and evolving rapidly, making characterization and comparability difficult.
  - Firms withhold information due to legitimate concerns of reputational costs or impacts on demand.
  - Insurance considerations: firms estimate net cost of disclosure in terms of future premium increases.
- Cross-border and state/non-state actor dynamics:
  - Strategic reasons may lead countries not to share information on cyber losses or protection strategies.
  - Important information asymmetries exist between national regulators and across borders; risk of fragmentation and overlap was noted in a U.S. Department of the Treasury (2017) report.
  - International policy coordination is needed—facilitating coordination, supporting information sharing, and designing coordinated policies.
- Final form of information problem: judging need/efficacy of cyber protection.
  - Many firms, especially smaller ones, lack cyber-specific knowledge to choose software or cybersecurity providers.
  - Ex-ante, the net quality of services/vendors is difficult to evaluate, which can disincentivize security investment or cause firms to opt for cheaper (and perhaps less safe) solutions.

### B. Strategic Complementarities, Coordination Failure, and Externalities
- Externalities arise when one institution’s behavior has side effects that affect net risk borne by others.
- Investment in cybersecurity creates positive externalities within the same network:
  - Individual firms’ cyber risk decreases with additional investment in (i) the firm’s own cybersecurity and (ii) security in other organizations connected to the same network.
- Strategic complementarities: agents’ decisions mutually reinforce one another; marginal returns increase when others increase their actions; can lead to multiple equilibria with different levels of cyber investment and system risk.
  - Effective coordination can achieve a better equilibrium.
- Software flaws create common exposures to cybersecurity risk; these externalities often are not internalized by vendors and can induce negative externalities from exposure to the same network or technologies.
- Software developers do not particularly emphasize security until products achieve market dominance because it is more difficult and costly to develop applications for secure products.
- Market entry timing: firms push new software to market with flaws not fully eliminated, creating common exposures.
- Network externalities: choice of operating system or other software depends considerably on number of existing users—explains dominance of certain systems.
- Empirical indicators (from Cisco 2017 analysis as presented):
  - U.S. is well above the 61 percent cross-peer country average (context: maturity of software security).
  - Software used by the financial sector typically shows relatively high maturity; share of low- and middle-maturity products used is among the lowest.
- Positive externalities can incentivize free-riding and cause under-investing.
  - If externalities persist, firms have incentives to free ride by under-investing in cybersecurity.
  - If private costs are lower than social costs, market outcomes will not be efficient with underinvestment and resulting negative externalities borne by industry or society.

### C. Economies of Scale, Barriers to Entry and Risk Concentration
- Cybersecurity services market is dominated by a relatively small number of companies providing similar or indistinguishable products/services to entire industries.
  - Concentration driven by increasing returns in provision of such services, creating barriers to entry for new companies even with superior but unproven technology.
- Oligopolies among providers can create correlated risks and common exposures for financial institutions because vendors/third-party providers frequently use similar software, hardware, and internet access modalities.
  - Individual oligopolist has strong incentive to protect its own systems; protection failure can lead to systemic effects across financial industry.
- Insurance provision concentration:
  - Fixed costs and increasing returns in understanding cyber risks and developing insurance products can concentrate the insurance market.
  - Risk that the insurance industry itself could be a financial stability risk in the event of a widespread coordinated cyber event.
  - A.M. Best (2017) predictions and data:
    - Market for cyber insurance in the U.S. will see substantial growth, with coverages increasing up to $20 billion by 2020.
    - In 2016, direct premiums written increased by one third year-on-year, expanding cyber insurance premium volume to $1.3 billion.
    - The largest three insurance writers (AIG, Chubb, and XL Group) cover 40 percent of the market; top-15 insurers serve 83 percent of the market.
    - Cyber insurance policies’ direct loss ratio is around 50 percent.
  - Industry has managed to fully cover incoming claims and make a profit in part by building sizable cushions in premiums, but there is concern insurers may not be able to absorb highly correlated losses from a systemic attack on the financial system.

### IV. Interactions of Cyber-Related Market Failures and Financial Stability
- Risk management in financial institutions has focused on idiosyncratic risk, with insufficient attention to systemic cyber risks from dependence on complex infrastructure or disruptions to critical information.
- Systemic risk arises where exposures are common or correlated across financial institutions. Main sources of systemic cyber risk:
  - Access vulnerabilities:
    - Financial system is highly connected; systems can be accessed by customers and business partners from anywhere.
    - System characterized by inherent access vulnerabilities; access protection is only as good as the weakest link.
  - Risk concentration:
    - Significant in key financial market infrastructures and systemically important financial institutions.
    - Certain infrastructures, including central clearing platforms (CCPs) or messaging systems like SWIFT, are key hubs and generate concentration risk due to low (external) redundancy.
    - A small number of institutions handle large shares of transaction volume in certain markets (e.g., G7 foreign currency trading) over proprietary electronic trading platforms.
    - Technical and IT concentration (operating systems, programs, cloud servers, electronic network hubs) can also generate systemic risk.
    - Cyber risk transfer via liability insurance has caused a build-up of risk exposures in cyber insurance market.
  - Risk correlations and contagion:
    - Idiosyncratic cyber shocks can trigger funding liquidity risks, morph into market liquidity shocks as firms shed assets, pulling down asset prices.
    - Concerns over counterparty integrity can lead firms to stop interacting with certain participants, exacerbating liquidity recycling pressures.
    - Materialized liquidity and market risk shocks can lead to solvency problems.
    - Close direct connections (interbank, transfer markets) and indirect relationships (liquidity cascades) allow shocks to spread quickly.
    - An institution’s inability to meet payment/settlement obligations because internal systems have been compromised can cause a name crisis with adverse funding liquidity effects and knock-on effects to others.
    - Liquidity shortages can lead to fire-sales, depressing asset valuations and spreading to investors/traders in affected assets; over time losses erode capital and weaken solvency positions.
- As interdependency, interconnectivity, and complexity increase, probability for an external cyber shock to transfer to the financial system and become systemic is likely to increase even if mitigation steps are taken.

### V. Financial Regulation of Cyber Risk
- Cyber risk framed as operational risk within existing regulatory structures:
  - Operational risk: risk of loss resulting from inadequate or failed internal processes, people and systems or from external events. (Includes legal risk; excludes strategic and reputational risk.)
- Minimum regulatory standards for IT-related risks focus on risk management and recovery/business continuity planning.
  - Supervisors encourage firms to develop more sophisticated operational risk measurement systems and practices.
  - Firms should adopt integrated, risk-based approach: identify, manage, and report IT-related risks through risk management functions.
- Regulatory capital treatment:
  - Operational risk frameworks require quantifying tail risks in regulatory capital.
  - Banks expected to set aside capital for operational risk as sum of expected and unexpected losses.
  - Use of scenario analysis with external data to evaluate exposure to tail events and deviations from correlation assumptions is integral.
  - Scenario analysis used to assess potential unexpected losses and set aside capital; assessments must be validated via comparisons to actual loss experience.
- Standards established by international standards-setting bodies (SSBs) and applied sectorally:
  - Framework elements include Basel Core Principles, Principles for the Sound Management of Operational Risk, Basel Capital Accord, and guidance on IT security and information management.
- Explicit standards for cyber resilience applied to securities and derivatives markets (payment, clearing, settlement systems) due to potential systemic spillovers; IOSCO/CPMI guidance requires high standards of operational risk management for these systems.
- Cyber risks pose new challenges relative to traditional IT risk:
  - Changing distribution channels and nature of incidents require regulations and supervisory approaches to adapt to rapidly changing risk profile.
  - Effective management of technology-related operational risk is fundamental to a bank’s risk management.
- G7 non-binding fundamental elements for cybersecurity strategy (to be tailored by regulators and financial institutions):
  - Element 1: Cybersecurity Strategy and Framework
  - Element 2: Governance
  - Element 3: Risk and Control Assessment
  - Element 4: Monitoring
  - Element 5: Response
  - Element 6: Recovery
  - Element 7: Information Sharing
- Data, reporting, and law enforcement coordination:
  - A reliable cyber risk reporting system is crucial: cyber information asset prioritization, standardize data gathering, build frameworks to model and price cyber risk.
  - National authorities should provide incentives for timely and accurate cyber event reporting; standards should require periodic internal cyber risk data reporting and eventually real-time reporting.
  - Data reliability checks and automated processing should be responsibilities of standard setters.
  - Due to criminal nature of attacks, regulators need to coordinate with law enforcement; formal arrangements for two-way exchange ideally needed.
- Supervisory capacity and flexibility:
  - Supervisors need flexibility to adapt cyber risk supervision approaches to fast-evolving threats.
  - Changing supervisors’ mindset to view cyber as a business and economic risk is a main challenge in transitioning from IT-based supervision.
  - Supervisors must develop forward-looking cyber risk assessment based on available data, understanding of institutions’ technology and business models, evaluation of cyber risk appetites and breach trends, and analysis of economic environment implications.
  - Critical to have capacity and authority to adapt supervisory response quickly as threats evolve.

*Source: wp17185 - introduction of software liability would slow down innovation. and that it would basically be*

### Box 3. Approach to Critical Infrastructure

### Box 3. Approach to Critical Infrastructure

### Defining and prioritizing critical financial infrastructure
- A differentiated approach for critical infrastructure is needed. Defining the scope of critical financial sector infrastructure and institutions is key to setting an effective cyber risk response.
- Certain types of financial institutions and infrastructures play a more pivotal role to the global financial and technological network, and thus may be responsible for spillover and contagion effects through the global financial system.
- Several jurisdictions (e.g., United States and Japan) have commenced this work by defining formally what constitutes critical infrastructure.
- In Europe, the 2008 Directive on European Critical Infrastructures (ECI) established procedures for determining critical infrastructures, even though so far these have largely focused on energy and transportation (no financial ECI has been identified to-date).
- More recently, the Network and Information Security Directive addresses the need to identify critical infrastructure.
- Footnote examples:
  - U.S.: Executive Order 13636, “Improving Critical Infrastructure Cybersecurity” (February 12, 2013), established criteria for identifying critical infrastructure based on its ability to “reasonably result in catastrophic national effects on public health or safety, economic security or national security” in the event of a cyber-attack.
  - Japan: defined via the “Special Action Plan on Countermeasures to Cyberterrorism of Critical Infrastructure”, adopted in December 2000.

### Role of public-private partnerships
- Public-private partnerships provide a pragmatic policy set-up, given limited incentives for coordination and cooperation across financial institutions.
- Such partnerships provide an effective channel for the sharing of information and coordination of cyber-threat prevention and identification across private entities, given there are limited private incentives to reveal instances of cyber-attacks.
- Public-private partnerships can be a good platform for exchanging information on cyber-threats and collaborating on cyber threat prevention and identification.
- Example framework: In the United States a Cybersecurity Framework has been established, consisting of a set of voluntary risk-based industry-wide standards, guidelines and best practices.

### Regulatory and supervisory measures taken by jurisdictions
- U.S.:
  - The cybersecurity framework has been supported by more intense supervision and regulatory requirements to contain cyber risk-related vulnerabilities.
  - The Federal Financial Institutions Examination Council (FFIEC) has initiated assessments to support smaller banks in addressing cybersecurity risks, inter alia via business continuity plans.
  - For broker-dealers, the Securities and Exchange Commission (SEC) and the Financial Industry Regulatory Authority (FINRA) in 2014 announced broad examinations of cybersecurity preparedness.
  - U.S. bank regulators expect the large bank holding companies (BHCs) to have the most sophisticated defense capabilities and to be able to recover from any attack within two hours.
  - Since 2013, banks include cyber risks and operational risks in the scenarios they submit in their annual stress tests required under the Dodd-Frank Act.
  - The agencies responsible for the supervision of BHCs (Federal Reserve, FDIC, and OCC) have issued an Advanced Notice of Proposed Rulemaking on Enhanced Cyber Risk Management Standards.
  - The standards are tiered, with a set of higher standards for systems that provide key functionality to the financial sector. These enhanced standards do not apply to community banks.
  - These standards apply to depository institutions and depository institution holding companies with total consolidated assets of $50 billion or more, the U.S. operations of foreign banking organizations with total U.S. assets of $50 billion or more, and financial market infrastructure companies and nonbank financial companies supervised by the Federal Reserve Board.
- Europe and UK:
  - The EU adopted a Cybersecurity Strategy in 2013, with emphasis on harmonization across states and on international cooperation.
  - The EU also adopted a directive on Network and Information Security (NIS) in 2013, aiming at strengthening preparedness, cross-border cooperation and information exchange.
  - In the UK, authorities set up a vulnerability testing framework to evaluate preparedness to simulated cyber-attacks (Waking Shark I and II exercises in 2011 and 2013; CBEST vulnerability testing in 2014).
  - The UK framework entails provision of detailed and reliable threat intelligence to the financial sector via the U.K.’s Certificateless Registry for Electronic Share Transfer (CREST).
- Japan:
  - Established a comprehensive cybersecurity policy, most recently enhanced by an updated Cybersecurity Strategy in 2013, which seeks to strengthen private-public information sharing; introduce business continuity exercises; establish a platform for evaluation and authentication of systems used by critical infrastructure; and enhance international cooperation.
- Singapore, Australia, India:
  - Singapore: National Cyber Security Masterplan 2018, with expected assessments of cybersecurity preparedness of critical sectors and the national infrastructure more broadly.
  - Australia: established the Australian Cyber Security Centre (ACSC) to ‘bring under one roof’ the cybersecurity capabilities of various government agencies.
  - India: adopted a National Cyber Security Policy in May 2013 to establish a comprehensive cybersecurity mechanism.
- Regional organization:
  - The Organization of American States (OAS) has established a secretariat to support better coordination across countries (including exchange of views and experiences) and the introduction of early warning mechanisms in each country.
- International standards and guidance:
  - Owing to the high reliance on technology in the securities and derivatives markets a layered approach has been developed drawing on the Committee on Payment and Market Infrastructures and Board of the International Organization of Securities Commission’s joint paper.
  - Key elements of the general approach: requiring strong governance; identification of systemic information assets (“crown jewels”); identifying cyber threats; building protections against cyber-attacks; detection of abnormal events; reducing recovery costs through incident response planning; and comprehensive stress testing of systems and processes.

### A. Reducing access vulnerabilities while boosting resilience — firm-level measures
- Basic measures firms can take to address idiosyncratic cyber risk include:
  - Application whitelisting (only run pre-approved software on firms’ computers);
  - Use of standardized secure system configurations (since complex configurations are more difficult to defend);
  - Having processes in place to patch system and application software within a short period; and
  - Limiting the number of individuals with administrator privileges.
- Increased resiliency requires education efforts to change institutions’ mindsets:
  - Full security is an illusion; firms should accept that cyber risks cannot be fully eliminated.
  - Firms need to take a risk-based approach in defensive measures and strengthen resilience to quickly bounce back from attacks.
  - Incident response and continuity planning are key elements for successfully dealing with breaches.
  - Firms should increase cybersecurity awareness and education efforts to increase their resiliency amongst their people.
  - Relationships with counterparties, third-party security services, and upstream infrastructure should be controlled through contracts and agreements and integrated into broader risk management processes.

### B. Lessening information asymmetries
- Data collection and sharing, better risk modeling, and a forward-looking perspective with respect to new or emerging risks is needed.
- Cyber risk loss data is scarce and since its collection is not standardized it often cannot be used as an input into risk management models.
- Useful information would include statistics on the type and frequency of threats and breaches, together with their realized or expected monetary impact, both for the compromised firm itself and its stakeholders.
- Systematic and timely information sharing will increasingly determine how quickly and effectively systemic risks can be understood and contained.
- Scenario analysis can help institutions understand potential risks, transmission, investment needs, and responses to breaches, but calibration depends on quantitative understanding of the nature and size of risks.
- Public roles and institutional arrangements recommended:
  - Define cyber-related terms and standards; develop a common terminology and identical definitions of cyber risk terms.
  - Collect information, aggregate it to preserve confidentiality, and then disclose that information.
  - Institutionalize information sharing among law enforcement, supervisors, regulators and the private sector; use public-private partnerships to facilitate distribution of information and coordination.
  - Anonymize and/or aggregate individual firms’ information to provide insights while preserving confidentiality.
  - Make information and data publicly available so firms, supervisors, and regulators can use these sources as inputs into risk management frameworks, models, surveillance, and early warning frameworks.

### C. Designing effective policies — balance of regulation and liability
- Cybersecurity risk needs to be managed using both ex-ante regulation and ex-post liability.
- The literature cited indicates:
  - Ex-ante regulation appears ineffective where serious information asymmetries persist between regulator and firms, or if regulation fails to design effective standards.
  - Ex-post liability does not work when firms are not held accountable or if they don’t have the means to cover the full scope of damages and losses (including because of the limited liability nature of corporate structures).
- Both ex-ante regulation and ex-post liability could slow down or prevent innovation because new software and systems embed new risks and vulnerabilities that may be detected only in practice.
- Policy implications:
  - Find the right balance of ex-ante regulation and ex-post liability to improve resiliency without stifling innovation.
  - Regulatory architecture needs to adapt and be continually refined as digitalization and adoption of new technologies progress.
  - The regulatory regime should encourage ongoing vigilance by boards and senior management to build resilience through investment in cyber security while giving institutions flexibility to address risks optimally.
  - Constantly evolving industry-wide standards are needed to keep pace with evolving cyber risks, even if these create compliance costs for the affected institutions.
  - High level principles should be complemented with bespoke guidance at the firm level to influence, incentivize, and shape financial institutions’ cyber security capability from elementary defenses to a state of cyber resilience.
  - Regulatory framework and supervision need to adequately incentivize implementation of risk management techniques, including to contain free-rider effects.

### D. Address coordination failures and manage systemic cyber risk
- In the highly interconnected IT and financial system, effective national and international coordination will be crucial.
- Governments need to ensure that different agencies collaborate coherently, avoid duplication, and pool initiatives.
- As cyber risk is not limited by political or geographical barriers, international policy coordination is needed.
- International organizations—like the Bank for International Settlements, the Financial Stability Board, or the IMF—can play a key role in facilitating coordination, supporting information sharing, designing coordinated policies, and helping solve disputes, if they emerge.
- The aggregation of cyber risk is too complex to be managed at the level of individual firms or countries; it is a global source of systemic risk that needs to be addressed on a multilateral level.

*Source: IMF Working Paper, Box 3. Approach to Critical Infrastructure (wp17185).*

---


_Source: https://www.imf.org/-/media/files/publications/wp/2017/wp17185.pdf_
