## 1. Cyber Risk and Systemic Risk: Transmission Channels

## Source details

**Canonical URL:** [1. Cyber Risk and Systemic Risk: Transmission Channels](https://www.imf.org/-/media/files/publications/wp/2020/english/wpiea2020028-print-pdf.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/wp/2020/english/wpiea2020028-print-pdf.pdf.md)
- [Structured JSON version](/-/media/files/publications/wp/2020/english/wpiea2020028-print-pdf.pdf.json)

---

### I. Motivation and notable examples
- Notorious global cyberattacks:
  - WannaCry (May 2017) affected computer systems in more than 150 countries.
  - NotPetya cost at least US$10bn.
- Sectoral digitization and exposure:
  - Financial services are the fourth most-digitized sector of the economy (Gandhi and others, 2018), increasing exposure to cyber risk.
  - Financial sector characteristics raising cyber vulnerability:
    - Large holdings of sensitive personal information (Verizon, 2017-19).
    - Increased digitalization expands the attack surface and introduces new entry points and digitized tasks/processes.
    - External threats rising with the volume of internet traffic, number of connected devices, and falling cost of launching large-scale cyberattacks (Cambridge Centre for Risk Studies, 2019).
- Macroeconomic relevance:
  - Council of Economic Advisers (2018) estimates malicious cyber activity costs the U.S. economy between 0.3 and 0.6 percent of GDP in a typical year.
  - Lloyds and Cambridge University (2015) estimate a localized U.S. power outage lasting two weeks could cost two percent of GDP.
  - Cybersecurity framed as public health, safety, and national security concern (WEF, 2016; New York Times, 2019).
  - IMF World Economic Outlook added cyberattacks to its list of main risks to global growth.

### II. Systemic and macro-critical risk: transmission channels and features
- Primary systemic transmission channels:
  - Risk concentration: failure or loss of services at key financial market infrastructure, third-party service provider, or systemically important financial institution with low substitutability.
  - Risk contagion: spillovers through interconnectedness (e.g., inability to post margins → counterparty liquidity/solvency stress).
  - Erosion of confidence: widespread attack triggering confidence loss across institutions or system, potentially overwhelming buffers.
- Examples of critical financial market infrastructures:
  - payment and settlement systems, trading platforms, central securities depositories, central counterparties, major ATM networks.
- Additional propagation sources:
  - power grids, telecommunications, cloud providers, internet service providers, global software providers.
- Key differences versus traditional shocks:
  - Faster speed of materialization and transmission.
  - Attacks on multiple non-systemic but technologically connected firms can spill over to systemically important institutions.
- Policy implication:
  - Coordinated crisis communications and effective contingency plans needed to maintain confidence and minimize systemic outcomes.

### III. Surveillance, policy responsibility, and measurement challenges
- Institutional responsibility:
  - Public agencies with macroeconomic and financial stability mandates must assess cyber risk levels but face data and tool constraints.
  - Traditional supervisory stance treats cyber risk as operational risk under microprudential supervision; macroprudential perspective needed when attacks target systemically important infrastructure or providers.
- Data and methodological limitations:
  - Few publicly available datasets due to confidentiality of cybersecurity incidents.
  - Short time series given novelty of cyber risk.
  - Financial institutions reluctant to disclose incidents except where regulations require it; reporting not standardized.
  - Indirect losses (including reputational effects) are difficult to quantify and can take time to materialize.
  - IT sector rapid change can render data obsolete quickly.
- Existing indices and tools:
  - ITU Global Cybersecurity Index useful for cross-country comparisons; latest ITU index ranks Singapore sixth globally and first in the Asia Pacific region.
  - Cyber value-at-risk (CyberVaR) methods in practice; FAIR noted as a proprietary CyberVaR method (Jones and Tivnan, 2018).

### IV. Practical analytical approaches and indicators for surveillance
- Feasible methods in data-poor environments:
  - Collection and tracking of key indicators.
  - Event studies.
  - Targeted survey estimates and questionnaires/self-assessments.
  - Application of statistical models estimated in other contexts (e.g., Kamiya and others (2018)).
  - Presentation of quantitative results in a standardized format (Cyber RAM templates).
- Suggested indicators and benchmarks:
  - Resource allocation: firms allocate 4 percent of their IT budget to cybersecurity (PWC, 2014); CSA in Singapore recommends 8 percent of IT budget (CSA, 2018).
  - Patching benchmarks: critical vulnerabilities within 15 days; high vulnerabilities within 30 days.
  - Typical metrics: headcount, proportion of IT budget, numbers of devices with outdated software, proportion of staff completing security training, phishing exercise results.
  - External ratings: BitSight scores on scale of 250-900 based on compromised systems, security diligence, user behavior, public disclosures.
  - Predictive indices: statistical models analyzing network traffic or firewall logs; internet search trends (e.g., Google Trends).
  - BCBS (2018) firm-monitored indicators: numbers of times malware/websites blocked; numbers of online directories containing stakeholder information; numbers and ratings from penetration tests; numbers of unknown devices on networks.
- Monitoring without local incident data:
  - Apply published formulae/models from other contexts using firm-specific inputs (size, Tobin’s q, stock return, leverage, asset intangibility).
  - Use questionnaires/self-assessments (Healey and others (2018)); caveat: sample selection bias and fixed-effect applicability.

### V. Empirical findings from event studies and VaR estimates
- Event-study results:
  - Kamiya and others (2018): sample of 188 incidents (2005–2014) — median stock returns fall by 50 basis points and value-weighted stock returns fall by 76 basis points on a cyberattack.
  - IMF authors’ analysis (ORX news stories subset of 341 cyberattacks on financial institutions worldwide):
    - financial firms’ stock prices fall by 45 basis points on data breaches and 39 basis points on business disruption incidents (measured around day cyberattack made public).
    - cyber-related fraud incidents show much smaller effects; wide confidence bands.
- Value-at-Risk (VaR) estimation of direct losses:
  - Using ORX data, fitted lognormal distribution of direct losses as percent of prior-year revenues.
  - The (one-year, 95 percent) value-at-risk estimated in the paper: 4.7 percent of gross revenues.
  - The 68 percent bootstrapped confidence interval puts the (95 percent) value-at-risk between 1.6 and 9.8 percent of revenues.
  - Sample matching constraints: Of the 102 events in the ORX news stories data with direct losses, only 21 events match to Bloomberg data on revenues.
  - Comparative estimates:
    - Bouveret (2019) estimates analogous VaR of 17 percent of net income.
    - Another cited estimate: 2.5 percent of gross income for the firms in our data (noted as an alternative reported figure).
  - Interpretation: the VaR estimate here measures idiosyncratic rather than systemic risk; systemic measures require allowing for correlations across firms.

### VI. Capital context and implications
- Operational risk capital benchmarks:
  - BCBS recommended capital requirements for operational risk of about 11 percent of gross income for banks with gross income up to €1bn.
  - The (one-year, 95 percent) VaR of 4.7 percent of gross revenues consumes a significant share of that operational risk capital budget: about two-fifths (ratio of 4.7 to 11).
  - Using Bouveret (2019)’s value of 2.5 percent instead would reduce this to one-fifth.
- Caveats:
  - The BCBS formula’s underlying confidence level is not explicit; Basel II advanced measurement approach specified capital for operational risk to cover 99.9 percent of one-year losses.
  - VaR estimates are subject to substantial estimation uncertainty and sample limitations.

### VII. Cyber Risk Assessment Matrix (Cyber RAM) and scenario likelihoods
- Cyber RAM structure:
  - Rows index downside scenarios; columns show likelihood (here based on proportion of banks identifying the scenario) and severity (banks’ estimated losses can be added).
- Typical scenario categories from Singapore banks:
  - Theft of data or money.
  - Disruption of banks’ IT or payment systems.
  - Damage/corruption of customer data.
- Most typical attack pathway:
  - Phishing email infects user workstations with malware, spreads within bank network, resulting in theft of data or money and disruption of services.
- MAS 2019 bank survey scenario likelihoods (fraction of banks identifying the scenario) and mitigants:
  - Corruption of data from data service provider: 0% of respondents; mitigant: due diligence.
  - Theft of data or money (e.g., ATM jackpotting): 60% of respondents; mitigants: access control, multiple security devices, regular security testing, malware protection.
  - Disruption of a bank’s IT systems (e.g., DDOS, payment processing disruption): 60% of respondents; mitigants: disaster recovery systems (including alternate site), incident response plans.
  - Corruption of customer data (three-day corruption of demographics, transactions, account balances): 20% of respondents; mitigant: regular tape backups to enable data restoration.
  - Disruption of third-party services: likelihood reported as n.a.; mitigants: due diligence, contractual cybersecurity obligations, alternate service providers.

### VIII. Stress tests and industry exercises (Singapore examples)
- MAS stress-testing approach:
  - Stress tests focus on adequacy of capital and liquidity buffers; industry-wide exercises focus on business continuity and crisis management.
- 2016 IWST scenario:
  - International crime syndicate simultaneous hacking across some financial institutions in Asia including Singapore, resulting in loss of entire customer databases and 24-hour system downtime for client-facing operational systems.
  - Results: smaller impact than expected; estimated losses varied significantly across banks; banks that considered systemic transmission channels reported much larger losses.
- 2019 IWST and FSAP:
  - Banks built internal inventory of cyber scenarios; aggregation across banks proved harder.
- Aggregate bottom-up estimates of banks’ losses from a direct cyberattack (figures in percent):
  - Direct Cyberattack — Theft / Disruption / Damage:
    - Fall in demand for credit (in percent of credit): 0.4 / 0.1 / 0.1
    - Withdrawal of deposits (in percent of deposits): 1.7 / 1.9 / 1.1
    - Loss (in percent of quarterly profits): 65.2 / 44.4 / 36.4
    - Fall in CAR (in percentage points): 0.1 / 0.2 / 0.4
    - Fall in LCR (in percentage points): 9.5 / 35 / 8.4
  - Indirect Cyberattack — Theft / Disruption:
    - Fall in demand for credit (in percent of credit): 0.2 / 0.1
    - Withdrawal of deposits (in percent of deposits): 5.1 / 3.9
    - Loss (in percent of quarterly profits): 20.4 / 50.7
    - Fall in CAR (in percentage points): 0.1 / 0
    - Fall in LCR (in percentage points): 1.6 / 3.6
  - Notes: estimates reported without banks’ contingency measures; methodology uses historical transactions data, staffing and inventory costs, fines specified in regulation, reference to past incidents and studies; no bank reported a damage-related scenario for indirect cyberattacks.
- Insurance sector stress-test findings (2019 IWST):
  - MAS surveyed 17 direct general/composite insurers on exposures from affirmative and non-affirmative (silent) cyber coverage for their largest clients.
  - Reported exposures: S$600 million (affirmative) and S$3.4 billion (non-affirmative silent).
  - Claims arising from these exposures amounted to S$1.8 billion, shared between direct insurers and reinsurers and potentially offset against a release of technical reserves.
  - Net losses reduced aggregate CAR of participating insurers by only three and two percentage points for affirmative and non-affirmative (silent) cyber coverage, respectively.
  - Some insurers have since inserted appropriate exclusion clauses in contracts to mitigate silent cyber exposure.

### IX. Outsourcing concentration, financial-cyber network mapping, and supervision
- Outsourcing-related cyber risks:
  - Outsourcing increases efficiency but exposes firms to providers’ IT security posture; concentration risk arises if many firms rely on the same service providers.
- MAS practices:
  - Financial institutions must maintain an updated register of all existing outsourcing arrangements and submit it to MAS at least annually or upon request.
  - MAS uses registers to determine commonly-used service providers warranting closer scrutiny; a review concluded there are no significant operational linkages between major financial institutions and technology firms.
- Financial-cyber network map:
  - Nodes: financial institutions, critical information infrastructures and third-party providers.
  - Edges: financial and ICT connections; ICT connections can reflect actual or potential data flows (measured by importance to business or existence).
  - Constructing a weighted adjacency matrix enables plotting a two-layer network map (financial links layer and ICT links layer) to signal contagion or concentration risks and inform microprudential supervision.
  - Singapore is undertaking such mapping work.

### X. Regulatory framework, industry practices, and operational capabilities (Singapore)
- Regulatory instruments and guidance:
  - TRM Notice: obliges financial institutions to maintain minimum levels of availability, resilience and recoverability for critical systems; implement IT controls to preserve confidentiality of customer information.
  - Cyber Hygiene Notice: obliges implementation of cybersecurity measures including network perimeter defense, malware protection, multi-factor authentication, timely patch updates, baseline configuration standards.
  - TRM Guidelines: recommend practices for cyber surveillance and security operations, cybersecurity testing, protection of online financial services.
- Supervision and cooperation:
  - Onsite inspections and off-site surveillance verify compliance; monitoring of cybersecurity strategy and changes in risk management frameworks.
  - MAS Financial Sector Security Operations Center (FS-SOC) collects and analyzes cyber threat information and shares distilled insights with financial institutions.
  - MAS chairs the Financial Stability Board working group on Cyber Incident Response and Recovery (CIRR).
- Competency building and industry collaboration:
  - Cybersecurity Capability Grant to encourage international financial institutions to base cybersecurity functions in Singapore.
  - Industry forum: Association of Banks in Singapore (ABS) Standing Committee on Cyber Security (SCCS).
- Cybersecurity Act 2018 and CSA:
  - Cyber Security Agency (CSA) established in 2015 with mandates including protection of critical information infrastructures, strategy and policy, security operations, ecosystem development.
  - Cybersecurity Act 2018 requires owners of critical information infrastructures to implement mandatory measures and to notify CSA of cybersecurity incidents.
  - Mandatory measures include conducting regular audits and risk assessments and participating in exercises to validate response measures.
- Financial institutions’ layered defenses:
  - Predictive: data analytics and machine learning for threat intelligence.
  - Preventive: segregation of internet browsing and email access on endpoints.
  - Detective: system and endpoint monitoring, dashboards with real-time metrics.
  - Respond and recover: cybersecurity exercises to test response and recovery plans.
  - Operational capabilities: Security Operations Centers (SOCs) using SIEM, network traffic inspection, security analytics; some institutions planning cyber security fusion centres.

### XI. Conclusions, open questions, and suggested analytical directions
- Main contributions of the paper:
  - Presents data sources and methods for analyzing cyber risk: key indicators, event studies, value-at-risk, custom surveys, Cyber RAM, and financial-cyber network maps, illustrated with Singapore applications.
  - Shows models estimated elsewhere can be applied when local event data are scarce.
- Open research and policy questions:
  - Estimating the size of systemic risk from cyberattacks remains an open question; bottom-up stress tests often focus on firm-specific events and financial institutions may not internalize systemic implications.
  - Systemic losses could be larger or could be offset by diversification effects.
  - Selection biases in cyber event datasets require further work; future analyses may build first-stage models of the selection process.
  - Financial-cyber network maps are a recent idea not yet widely applied; specialized contagion risk models (e.g., contagion over a two-layer network combining financial and ICT links) may be needed when data become available.
  - Concentration analysis for outsourcing arrangements should distinguish between concentration risk and desirable concentration from many firms using the same reputable third-party providers.

*Source: wpiea2020028-print-pdf*

### 1. Cyber Risk and Systemic Risk: Transmission Channels  ___________________________9

### 1. Cyber Risk and Systemic Risk: Transmission Channels

### I. Motivation — prominence and examples
- Notorious global cyberattacks cited: WannaCry (May 2017) affected computer systems in more than 150 countries, and NotPetya cost at least US$10bn.
- Singapore example: breach of confidential data at SingHealth.
- Financial services are the fourth most-digitized sector of the economy (Gandhi and others, 2018), increasing exposure to cyber risk.
- Financial sector characteristics raising cyber vulnerability:
  - Large holdings of sensitive personal information, making it a highly targeted sector for data breaches (Verizon, 2017-19).
  - Increased digitalization expands the attack surface and introduces new entry points and digitized tasks/processes.
  - External threats rising with the volume of internet traffic, number of connected devices, and falling cost of launching large-scale cyberattacks (Cambridge Centre for Risk Studies, 2019).

### Systemic and macro-critical risk
- Cyber events can have systemic consequences for financial intermediation:
  - Examples: runs on bank deposits, claims against insurers, attacks on systemically important financial institutions, central counterparties, major ATM networks, corruption of upstream provider data, disruption of critical third-party providers (global software providers, cloud computing services).
  - Systemic amplification channels: financial and technological links between firms, concentrations, common exposures, second-round confidence effects.
- Cyber risk could be macro-critical without triggering a financial crisis:
  - Council of Economic Advisers (2018) estimates malicious cyber activity costs the U.S. economy between 0.3 and 0.6 percent of GDP in a typical year.
  - Downside scenarios could be several multiples greater; a localized U.S. power outage lasting two weeks is estimated to cost two percent of GDP and affect public/private consumption, labor productivity, imports and exports (Lloyds and Cambridge University, 2015).
- Cybersecurity framed as public health, safety, and national security concern (WEF, 2016; New York Times, 2019).
- IMF World Economic Outlook added cyberattacks to its list of main risks to global growth.

### Policy responsibility and surveillance challenges
- Public agencies with macroeconomic and financial stability mandates are responsible for assessing cyber risk levels, but face data and tool constraints.
- Existing cross-country indices:
  - ITU Global Cybersecurity Index useful for cross-country comparisons and tracking progress; latest ITU index ranks Singapore sixth globally and first in the Asia Pacific region.
- Traditional supervisory stance: cyber risk treated as operational risk under microprudential supervision.
- Need for macroprudential perspective when attacks target systemically important infrastructure or providers.

### Data, measurement, and methodological limitations
- Limited data availability is a key challenge:
  - Few publicly available datasets due to confidentiality of cybersecurity incidents.
  - Novelty of cyber risk yields short time series for analysis.
  - Financial institutions reluctant to disclose incidents except where regulations require it.
  - Reporting not standardized; direct loss estimates may not be comparable.
  - Indirect losses (including reputational effects) are difficult to quantify and can take time to materialize.
  - IT sector rapid change can render data obsolete quickly.
- Existing academic and practitioner work:
  - Kamiya and others (2018): drivers of likelihood and severity of data breaches using 188 incidents between 2005 and 2014.
  - Bouveret (2019): estimates tail quantiles of direct losses from 341 cybersecurity incidents affecting financial institutions between 2009 and 2017.
  - Santucci (2018): lists processes and frameworks for cyber risk management (IRAM, Risk IT, FAIR, NIST, CyberVaR).
  - Cyber value-at-risk appears to be the primary measurement methodology currently applied; FAIR is noted as a proprietary CyberVaR method (Jones and Tivnan, 2018).

### Practical contributions and scope of this paper
- The paper offers simple analytical techniques and data sources for policymakers to assess and monitor cyber risk in the financial sector as part of regular surveillance.
- Methods and data highlighted as feasible in data-poor environments:
  - Collection and tracking of key indicators.
  - Event studies.
  - Targeted survey estimates.
  - Application of statistical models developed in other contexts.
  - Presentation of quantitative results in a standardized format.
- The quantitative approach complements qualitative work on cyber risk surveillance and policy frameworks (BCBS, 2018; FSB, 2017-18; IMF, 2019b; Kopp and others, 2017).
- The paper draws on the experience of Singapore given its significant commitment to building capabilities in this area.

*Source: wpiea2020028-print-pdf - 1. Cyber Risk and Systemic Risk: Transmission Channels*

### Section IV. These approaches can serve as a checklist for those with responsibility for

### Section IV. These approaches can serve as a checklist for those with responsibility for surveillance of cyber resilience and for other jurisdictions seeking to improve their institutional arrangements

### II. FINANCIAL STABILITY IMPLICATIONS OF CYBER RISK
- Purpose: presents framework for considering financial stability risks posed by cyber events; complements entity-level operational risk analyses by focusing on system-wide financial implications.
- Cyber events categorized by harm inflicted:
  - theft
  - disruption
  - damage (physical damage to data integrity, software or hardware)
- Microprudential impacts on financial institutions can include:
  - solvency, liquidity, market, operational, legal, and reputational risks.
  - Examples: capital buffers drawn down from monetary losses; technical defaults from inability to receive/make payments; deposit runs and liquidity shortages from confidence erosion; market losses from corrupted time-sensitive market data; legal and reputational losses exacerbating solvency and liquidity pressures.
- Insurer-specific microprudential exposures:
  - underwriting losses from affirmative cyber insurance and from non-affirmative (silent) cyber coverage (example: fire claim arising from hardware overheating due to a cyberattack).

### A. Microprudential Risks Posed by Cyber Events
- Theft-related cyberattacks: extract funds, customer credentials, intellectual property, or market-valuable information.
- Disruption-related cyberattacks: degrade availability of transactions or communications (examples: websites, servers, internet-based businesses).
- Damage-related cyberattacks: affect data integrity or physically damage hardware/software.
- Notable citations/observations preserved in source:
  - BCBS (2018) notes lack of established data and immaturity of resilience metrics.
  - Duffie and Younger (2019) argue large U.S. banks’ liquid assets are enough to cover wholesale funding obligations due within one month (contrarian view on likelihood of deposit runs).

### B. Systemic Risk Transmission Channels of Cyber Events
- Three broad transmission channels:
  - Risk concentration: failure or loss of services at key financial market infrastructure, third-party service provider, or systemically important financial institution with low substitutability.
  - Risk contagion: spillovers through interconnectedness (e.g., inability to post margins → counterparty liquidity/solvency stress; domino effects).
  - Erosion of confidence: widespread attack triggering confidence loss across institutions or system, potentially overwhelming buffers.
- Examples of critical financial market infrastructures: payment and settlement systems, trading platforms, central securities depositories, central counterparties.
- Additional systemic propagation sources: disruption of power grids, telecommunications, cloud providers, internet service providers.
- Key differences versus traditional shocks:
  - Faster speed of materialization and transmission.
  - Attacks on multiple non-systemic but technologically connected firms can spill over to systemically important institutions.
- Policy implication highlighted: coordinated crisis communications and effective contingency plans needed to maintain confidence and minimize systemic outcomes.

### C. Systemicity of Cyber Events
- Assessment requires understanding event type and relevant transmission channels.
- Relative systemicity by event type (illustrative approach):
  - Theft and disruption: primarily pressure on liquidity and solvency buffers; post-crisis buffer buildup likely reduces systemic likelihood.
  - Data damage: higher systemic risk due to importance of data integrity; indirect effects (loss of clients, reputational risk) may exceed direct recovery/litigation costs; prolonged undetected data manipulation can propagate widely and require extended rectification.

### III. ANALYSIS OF CYBER RISK TO FINANCIAL INSTITUTIONS (introductory material)
- Traditional risk analyses (solvency stress tests, liquidity stress tests, contagion analyses) can be reinterpreted to capture some cyber risk aspects:
  - solvency stress tests simulate sharp asset price declines (cyber-driven market manipulation could be a source).
  - liquidity stress tests simulate depositor withdrawals and forced asset sales (cyber-driven reputation loss could trigger withdrawals).
  - contagion analyses via interbank networks can model domino effects starting from a cyber-triggered failure.
- Singapore case: 2019 Financial Sector Assessment Program concluded buffers adequate under adverse macroeconomic conditions, implying buffers also mitigate cyberattack impacts absent direct cyber risk appraisal.

### A. Reinterpreting Traditional Risk Analyses as Cyber Risk Analyses
- Traditional analyses provide partial assessment of cyber risk via institution resilience to solvency, liquidity, and contagion shocks.

### B. Key Indicators for Monitoring Cyber Risk
- Incident-based monitoring:
  - Frequency of cybersecurity incidents can be tracked over time and by firm type.
  - Example findings preserved from source:
    - In Singapore, cyberattacks primarily targeted securities firms and banks; only one incident led to direct pecuniary loss (a capital markets intermediary).
    - Most Singapore incidents aimed at business disruption (DDoS, website vandalism); incidents also include ransomware and attacks on third-party providers.
- Resource and operational indicators:
  - Firms allocate 4 percent of their IT budget to cybersecurity (PWC, 2014).
  - Cyber Security Agency (CSA) in Singapore recommends 8 percent of IT budget be allocated to cybersecurity (CSA, 2018).
  - Patching benchmarks: critical vulnerabilities within 15 days; high vulnerabilities within 30 days.
  - Typical metrics: headcount, proportion of IT budget, numbers of devices with outdated software, proportion of staff completing security training, results of phishing exercises.
  - External ratings: BitSight scores on scale of 250-900 based on compromised systems, security diligence, user behavior, public disclosures.
  - Predictive indices: statistical models analyzing network traffic or firewall logs; internet search trends (e.g., Google Trends) for institution-specific cybersecurity interest.
- BCBS (2018) additional firm-monitored indicators: numbers of times malware/websites blocked; numbers of online directories containing stakeholder information; numbers and ratings from penetration tests; numbers of unknown devices on networks.
- Note: Appendix in source gathers potential indicators into example templates for regulators and financial institutions.

### C. Monitoring Risk Without Cybersecurity Incident Data
- Alternatives when local incident data unavailable:
  - Apply published formulae/models estimated in other contexts (e.g., Kamiya and others (2018)) using firm-specific inputs such as size, Tobin’s q, stock return, leverage, asset intangibility.
  - Use questionnaires/self-assessments to obtain information from financial institutions (examples in Healey and others (2018)).
  - Caveat: sample selection bias and applicability of fixed effects when transferring models across contexts.

### D. Data Sources, Event Studies and Value-at-Risk
- Examples of empirical analyses using incident datasets:
  - Kamiya and others (2018): used Privacy Right Clearinghouse; sample of 188 cyberattacks (data breaches on U.S. financial and non-financial firms, 2005–2014); median stock returns fall by 50 basis points and value-weighted stock returns fall by 76 basis points on a cyberattack.
  - IMF authors’ analysis: subset of 341 cyberattacks on financial institutions worldwide using ORX news stories data:
    - Event study: financial firms’ stock prices fall by 45 basis points on data breaches and 39 basis points on business disruption incidents (measured around day cyberattack made public).
    - Cyber-related fraud incidents show much smaller effects; wide confidence bands indicate losses are difficult to distinguish from normal market volatility.
- Value-at-Risk (VaR) estimation of direct losses:
  - Using ORX data, estimated lognormal distribution of direct losses as percent of prior-year revenues.
  - The 95 percent one-year value-at-risk is 4.7 percent of revenues (subject to significant estimation uncertainty).
  - Comparable estimate: Bouveret (2019) estimates analogous VaR of 17 percent of net income.

*Source: Section IV (excerpts) of wpiea2020028-print-pdf*

### 2.5 percent of gross income for the firms in our data. Our value-at-risk is expected to be a bit

### 2.5 percent of gross income for the firms in our data. Our value-at-risk is expected to be a bit

### Value-at-risk estimates and sample limitations
- The analysis aggregates losses to the firm–year level and matches to each firm’s gross revenues of the previous year; the fitted distribution is therefore the distribution of yearly losses, in percent of revenues, directly.
- Comparison to alternative approaches:
  - Bouveret (2019) fits a distribution to event-level losses in constant price U.S. dollars and uses a calibrated Poisson random variable for the number of events to simulate a compound distribution of annual losses; external data are then used to express estimated dollar value-at-risk as a percent of net revenues.
  - The author’s approach might overestimate value-at-risk (in percent of revenues) if there is a positive correlation between nominal losses and income, as suggested by the present data and certain results in Kamiya et al. (2018).
- Key numeric estimates and uncertainty:
  - The (one-year, 95 percent) value-at-risk estimated in the paper: 4.7 percent of gross revenues.
  - The 68 percent bootstrapped confidence interval puts the (95 percent) value-at-risk between 1.6 and 9.8 percent of revenues.
  - Sample matching issues: Of the 102 events in the ORX news stories data with direct losses, only 21 events match to Bloomberg data on revenues.
  - The reduced sample size motivates using a simple lognormal distribution rather than more flexible distributions considered in Bouveret (2019).
  - Note on interpretation: the value-at-risk estimate here is a measure of idiosyncratic rather than systemic risk because it is based on idiosyncratic events; systemic measures can be derived by modifying the approach to allow for correlations across firms.

### Comparative capital context and implications
- Operational risk capital context:
  - BCBS recommended capital requirements for operational risk of about 11 percent of gross income for banks with gross income up to €1bn.
  - The (one-year, 95 percent) value-at-risk of 4.7 percent of gross revenues consumes a significant amount of the capital budget for operational risk.
  - Implication: for these banks, even just the 95th percentile of cyber risk consumes about two-fifths of the capital budget for operational risk over one year (two-fifths computed as the ratio of 4.7 to 11).
  - Using Bouveret (2019)’s value of 2.5 percent instead of 4.7 percent would reduce this to one-fifth.
- Caveats:
  - The BCBS formula’s underlying confidence level is not explicit; the Basel II advanced measurement approach specified capital for operational risk to cover 99.9 percent of one-year losses.
  - The calculated value-at-risk applies to all financial institutions in the dataset, not just banks, and is subject to substantial estimation uncertainty.

### Cyber Risk Assessment Matrix (Cyber RAM) — structure and application
- Purpose and design:
  - A RAM presents results of an assessment where rows index downside scenarios and columns show likelihood and severity; adapted here as a Cyber RAM to collect cyber scenarios into one table.
  - Likelihood in the presented Cyber RAM is based on the proportion of banks that identified the scenario (not expert judgement).
  - A column for banks’ estimated losses under each scenario can be added to capture severity.
- Typical scenario categories identified by banks in Singapore:
  - Theft of data or money.
  - Disruption of banks’ IT or payment systems.
  - Damage/corruption of customer data.
- Most typical attack pathway: phishing email infects user workstations with malware, spreads within bank network, resulting in theft of data or money and disruption of services.

### Cyber RAM example (from MAS 2019 bank survey) — scenario likelihoods and mitigants
- Scenario likelihoods reported (fraction of banks identifying the scenario):
  - Corruption of data from data service provider: 0% of respondents; mitigant: due diligence (e.g., on service provider).
  - Theft of data or money (e.g., ATM jackpotting): 60% of respondents; mitigants include access control, multiple security devices (e.g., firewalls, intrusion prevention systems), regular security testing, malware protection.
  - Disruption of a bank’s IT systems (e.g., DDOS, payment processing disruption): 60% of respondents; mitigants include disaster recovery systems (including alternate site), incident response plans.
  - Corruption of customer data (three-day corruption of demographics, transactions, account balances): 20% of respondents; mitigant: regular tape backups to enable data restoration.
  - Disruption of third-party services: likelihood reported as n.a.; mitigants include due diligence, third parties’ contractual cybersecurity obligations, business continuity measures like alternate service providers.

### Stress tests on cyber risk in Singapore — design and findings
- MAS stress-testing approach:
  - MAS conducts stress tests and industry-wide exercises focusing on adequacy of capital and liquidity buffers (stress tests) and business continuity/crisis management (industry-wide exercises).
  - 2016 IWST scenario: international crime syndicate simultaneous hacking across some financial institutions in Asia including Singapore, resulting in loss of entire customer databases and 24-hour system downtime for client-facing operational systems.
    - Results: smaller impact than expected; estimated losses varied significantly across banks; banks that considered systemic transmission channels reported much larger losses.
  - 2019 IWST and FSAP: banks asked to identify most impactful direct and third-party cyberattack scenarios; approach built internal inventory of cyber scenarios but was harder to aggregate across banks.
- Aggregate bottom-up estimates of banks’ losses from a direct cyberattack (Table 2; figures in percent):
  - Direct Cyberattack — Theft / Disruption / Damage:
    - Fall in demand for credit (in percent of credit): 0.4 / 0.1 / 0.1
    - Withdrawal of deposits (in percent of deposits): 1.7 / 1.9 / 1.1
    - Loss (in percent of quarterly profits): 65.2 / 44.4 / 36.4
    - Fall in CAR (in percentage points): 0.1 / 0.2 / 0.4
    - Fall in LCR (in percentage points): 9.5 / 35 / 8.4
  - Indirect Cyberattack — Theft / Disruption:
    - Fall in demand for credit (in percent of credit): 0.2 / 0.1
    - Withdrawal of deposits (in percent of deposits): 5.1 / 3.9
    - Loss (in percent of quarterly profits): 20.4 / 50.7
    - Fall in CAR (in percentage points): 0.1 / 0
    - Fall in LCR (in percentage points): 1.6 / 3.6
  - Notes: estimates reported without banks’ contingency measures; methodology uses historical transactions data, staffing and inventory costs, fines specified in regulation, reference to past incidents and studies; no bank reported a damage-related scenario for indirect cyberattacks.
- Insurance sector stress-test findings (2019 IWST):
  - MAS surveyed 17 direct general/composite insurers on exposures from affirmative and non-affirmative (silent) cyber coverage for their largest clients.
  - Reported exposures: S$600 million (affirmative) and S$3.4 billion (non-affirmative silent).
  - Claims arising from these exposures amounted to S$1.8 billion, shared between direct insurers and reinsurers and potentially offset against a release of technical reserves.
  - Net losses reduced aggregate CAR of participating insurers by only three and two percentage points for affirmative and non-affirmative (silent) cyber coverage, respectively.
  - Some insurers have since inserted appropriate exclusion clauses in contracts to mitigate silent cyber exposure.

### Outsourcing concentration and financial-cyber network mapping
- Outsourcing-related cyber risks:
  - Outsourcing to third-party service providers increases efficiency but exposes firms to cyber risks associated with providers’ IT security posture (service disruption, leakage of sensitive customer information, compromise via IT linkages).
  - Concentration risk arises if many financial firms rely on the same service providers.
- MAS practices:
  - Financial institutions are expected to maintain an updated register of all existing outsourcing arrangements and submit it to MAS at least annually or upon request.
  - MAS uses registers to determine commonly-used service providers warranting closer scrutiny; a review concluded there are no significant operational linkages between major financial institutions and technology firms.
- Financial-cyber network map:
  - Nodes include financial institutions, critical information infrastructures and third-party providers.
  - Edges are financial and ICT connections; ICT connections can reflect actual or potential data flows (measured by importance to business or existence).
  - Constructing a weighted adjacency matrix enables plotting a two-layer network map (one layer for financial links, one for ICT links).
  - Such mapping can signal contagion or concentration risks and inform microprudential supervision; constructing such a map is ongoing in Singapore.

### Regulatory approach and industry practices in Singapore
- MAS strategic elements:
  - Regulation and Guidance:
    - TRM Notice: obliges financial institutions to maintain minimum levels of availability, resilience and recoverability for critical systems; implement IT controls to preserve confidentiality of customer information.
    - Cyber Hygiene Notice: obliges implementation of cybersecurity measures including network perimeter defense, malware protection, multi-factor authentication, timely patch updates, baseline configuration standards.
    - TRM Guidelines: recommend practices for cyber surveillance and security operations, cybersecurity testing, protection of online financial services.
  - Supervision: onsite inspections and off-site surveillance to verify compliance; monitoring of cybersecurity strategy and changes in risk management frameworks.
  - Cyber Surveillance and International Co-operation:
    - MAS Financial Sector Security Operations Center (FS-SOC) collects and analyzes cyber threat information and shares distilled insights with financial institutions.
    - MAS participates in international cooperation including chairing the Financial Stability Board (FSB) working group on Cyber Incident Response and Recovery (CIRR).
  - Competency Building and Industry Collaboration:
    - Cybersecurity Capability Grant to encourage international financial institutions to base cybersecurity functions in Singapore (e.g., SOCs, fusion centers, centers of excellence).
    - Industry forum: Association of Banks in Singapore (ABS) Standing Committee on Cyber Security (SCCS).
- Cybersecurity Act 2018 and CSA:
  - Cyber Security Agency (CSA) established in 2015 with mandate including protection of critical information infrastructures, strategy and policy, security operations, ecosystem development.
  - Cybersecurity Act 2018 requires owners of critical information infrastructures to implement mandatory measures and to notify CSA of cybersecurity incidents.
  - Mandatory measures include conducting regular audits and risk assessments and participating in exercises to validate response measures.

### Financial institutions’ layered defenses and operational capabilities
- Typical layered controls adopted by major financial institutions:
  - Predictive mechanisms: data analytics and machine learning for cyber threat intelligence.
  - Preventive mechanisms: segregation of internet browsing and email access on endpoints.
  - Detective mechanisms: system and endpoint monitoring, dashboards with real-time metrics.
  - Respond and recovery mechanisms: cybersecurity exercises to test response and recovery plans.
- Operational capabilities:
  - Key financial institutions have established SOCs with tools such as Security Information and Event Management (SIEM) solutions, network traffic inspection solutions, and security analytics tools.
  - Some institutions plan cyber security fusion centres integrating cyber intelligence, security operations, incident management and forensic investigation.
  - SOC staff undergo regular professional training.

### Conclusions, open questions, and suggested analytical directions
- Main contributions:
  - The paper presents data sources and methods for analyzing cyber risk: key indicators, event studies, value-at-risk, custom surveys, Cyber RAM, and financial-cyber network maps, illustrated with Singapore applications.
  - Even without local cyber event data, models estimated in other contexts can be applied regularly in a jurisdiction.
- Open research and policy questions:
  - Estimating the size of systemic risk from cyberattacks remains an open question; bottom-up stress tests often focus on firm-specific events and financial institutions may not internalize systemic implications.
  - Systemic losses could be larger or could be offset by diversification effects.
  - Selection biases in cyber event datasets require further work; future analyses may build first-stage models of the selection process.
  - Financial-cyber network maps are a recent idea not yet widely applied in practice; when data become available, specialized contagion risk models (e.g., contagion over a two-layer network combining financial and ICT links) may be needed.
  - Concentration analysis for outsourcing arrangements should distinguish between concentration risk and desirable concentration arising from many firms using the same reputable third-party providers.

*Source: wpiea2020028-print-pdf - 2.5 percent of gross income for the firms in our data. Our value-at-risk is expected to be a bit*

### REFERENCES

### REFERENCES

### Referenced works (selection from the list)
- Afonso, G., Curti, F., McLemore, P. and A. Mihov. 2019 “Understanding Cyber Risk: Lessons from a Recent Fed Workshop.” Blog, Liberty Street Economics, Federal Reserve Bank of New York.
- Basel Committee on Banking Supervision, 2011. “Operational Risk - Supervisory Guidelines for the Advanced Measurement pproach.” Bank for International Settlements, June.
- Basel Committee on Banking Supervision, 2016. “Standardised Measurement Approach for Operational risk.” Consultative Document, March.
- Basel Committee on Banking Supervision, 2018. “Cyber Resilience: Range of Practices.” Bank for International Settlements, December.
- Bouveret, Antoine, 2019, “ Estimation of losses due to cyber risk for financial institutions,” Journal of Operational Risk, 14(2) pp. 1-20.
- Committee on Payments and Market Infrastructures, 2016. “Guidance on cyber resilience for financial market infrastructures.” Joint with the Board of the International Organization of Securities Commissions. June.
- Financial Stability Board, 2018. “Cyber Lexicon.” November.
- International Monetary Fund, 2019b. “Cybersecurity Risk Supervision.” Departmental Paper No. 19/15, Monetary and Capital Markets Department.
- Kopp, E., Kaffenberger, L. and Jenkinson, N., 2017. “Cyber Risk, Market Failures, and Financial Stability.” Working Paper no. 17/185, International Monetary Fund.
- Oliver Wyman, 2019. “Navigating Cyber Risk Quantification. The Art and Science of Cyber Quantification Through a Scenario-Based Approach.”
- World Economic Forum, 2016. “Understanding Systemic Cyber Risk.” White Paper, Global Agenda Council on Risk & Resilience, October.

(Full list of references appears in the source document.)

### Types of sources included
- Central bank and supervisory reports (e.g., Bank of Canada, MAS, Basel Committee documents)
- International organizations and IMF publications (e.g., IMF departmental papers, Financial Stability Board)
- Academic working papers and journal articles (e.g., NBER Working Paper No. 24409; Journal of Operational Risk 14(2))
- Industry reports and practitioner pieces (e.g., Lloyds and Cambridge University Center for Risk Studies; Oliver Wyman)
- Government and policy white papers (e.g., Council of Economic Advisers, Department of Homeland Security directives)
- Media and incident reports (e.g., Reuters, The Straits Times, Wired)

---

### APPENDIX I. EXAMPLE DATA REPORTING TEMPLATES

- Purpose: Stylized templates to collect data from individual financial firms on cyber risk exposure and cybersecurity practices; to be tailored to each jurisdiction.

Annual budget for cybersecurity (fields)
- number of full-time employee equivalents spending (US$ '000)
- Total budget for ICT (1)
- of which, budget for cybersecurity (2)
- = (1)/(2) x 100

Board and senior management (questions)
- Are there Board members with expertise in cybersecurity?   yes/no
- Does the Board receive training on cyber risk?   yes/no
- Does the Board receive regular cyber risk reports from staff?   yes/no
- If so, how many times per year?
- Does the firm's senior management designate an individual responsible for cybersecurity?   yes/no

Cyber hygiene practices (questions and fields)
- Does the firm apply automatic security patches?   yes/no
- Average number of days it takes to patch software vulnerabilities
- Does the firm use multi-factor authentication:
  - for all administrative accounts?   yes/no
  - for all accounts with access to customer data?   yes/no
- Does the firm use malware protection software?   yes/no
- Does the firm maintain a list of its critical information infrastructures (CIIs)?   yes/no
- Does the firm maintain a written set of security standards for each CII?   yes/no

Incident reporting table (columns to be completed for each incident)
- ID
- earliest date of occurrence (yyyy/mm/dd)
- date of detection (yyyy/mm/dd)
- event type (breach, disruption or fraud)
- cause (external, people, processes)
- third party provider involved (yes/no)
- number of records breached
- estimated direct loss amount (US$ '000)
- reported to law enforcement (yes/no)
- insured (yes/no)
- direct loss amount insured (US$ '000)
- jurisdiction
- business line
- description

Cyber risk scenario table (fields)
- scenario number
- description
- direct loss (in US$ '000)
- fall in deposits (percent)
- fall in CAR (percent)
- fall in LCR (percent)
- mitigating actions
- preventive measures

*Source: wpiea2020028-print-pdf - REFERENCES (canonical source content included in the PDF).*

---


_Source: https://www.imf.org/-/media/files/publications/wp/2020/english/wpiea2020028-print-pdf.pdf_
