Estimating Cyber Risk for the Financial Sector
IMF Blog, June 22, 2018
Source details
- Canonical URL
- Estimating Cyber Risk for the Financial Sector
Other formats
Bibliographic details
- Authors: Christine Lagarde
- Published: June 22, 2018
Cyber risk overview
- Author: Christine Lagarde
- Date: June 22, 2018
- Summary finding: Cyber risk has emerged as a significant threat to the financial system; an IMF staff modeling exercise estimates that average annual losses to financial institutions from cyber-attacks could reach a few hundred billion dollars a year, eroding bank profits and potentially threatening financial stability.
- Recent examples cited:
- Data breaches exposing confidential information.
- Fraud, such as the theft of $500 million from the Coincheck cryptocurrency exchange.
- Risk that a targeted institution could be left unable to operate.
Financial sector’s vulnerability
- Reasons for heightened vulnerability:
- Financial institutions’ crucial role in intermediating funds makes them attractive targets.
- High interconnectedness means a successful attack on one institution could spread rapidly.
- Many institutions still use older systems that might not be resilient to cyber-attacks.
- Successful cyber-attacks cause direct financial losses and indirect costs such as diminished reputation.
- Observations:
- Surveys consistently show risk managers and executives at financial institutions worry most about cyber-attacks.
- Quantitative analysis of cyber risk is still at an early stage due to lack of data and modeling difficulties.
Estimating potential losses (modeling framework and results)
- Methodology:
- Uses techniques from actuarial science and operational risk measurement to estimate aggregate losses from cyber-attacks.
- Requires assessment of frequency of cyber-attacks on financial institutions and distribution of losses from such events.
- Numerical simulations used to estimate distribution of aggregate cyber-attack losses.
- Data example:
- Illustration uses a data set covering recent losses due to cyber-attacks in 50 countries.
- The exercise is difficult and challenged by major data gaps on cyber risk.
- Key quantitative findings (reported as illustrative):
- Average annual potential losses from cyber-attacks may be large, close to 9 percent of banks’ net income globally, or around $100 billion.
- In a severe scenario — in which the frequency of cyber-attacks would be twice as high as in the past with greater contagion — losses could be 2½–3½ times as high as this, or $270 billion to $350 billion.
- Distributional insight: in extreme scenarios representing the worst 5 percent of cases, average potential losses could reach as high as half of banks’ net income, putting the financial sector at risk.
- Note: Thankfully, there has yet been no successful, large-scale cyber-attack on the financial system.
Insurance market and gaps
- Current market size and limitations:
- Cyber insurance market remains small with around $3 billion in premiums globally in 2017.
- Most financial institutions do not carry cyber insurance.
- Coverage is limited.
- Insurer challenges:
- Difficulty evaluating risk because of uncertainty about cyber exposures, lack of data, and possible contagion effects.
- Comparative note:
- Estimated potential losses are several orders of magnitude greater than the present size of the cyber insurance market.
The way forward (policy recommendations and operational steps)
- Data and reporting:
- Government collection of more granular, consistent, and complete data on frequency and impact of cyber-attacks would help assess risk for the financial sector.
- Requirements to report breaches—such as considered under the EU’s General Data Protection Regulation—should improve knowledge of cyber-attacks.
- Analytical tools:
- Use scenario analysis to develop comprehensive assessment of how cyber-attacks could spread and to design adequate responses by private institutions and governments.
- Resilience and capacity building:
- Further work needed to understand how to strengthen resilience of financial institutions and infrastructures to reduce odds of successful attacks and facilitate rapid recovery.
- Need to build capacity in the official sector in many parts of the world to monitor and regulate such risks.
- Regulatory and supervisory priorities:
- Strengthen regulatory and supervisory frameworks for cyber risk.
- Focus on effective supervisory practices, realistic vulnerability and recovery testing, and contingency planning.
- IMF is providing technical assistance to help member countries improve their regulatory and supervisory frameworks.
Estimating Cyber Risk for the Financial Sector — Christine Lagarde, June 22, 2018
Content in this bundle
- 估计金融部门的网络风险; IMF blog, 2018 年6 月22 日
- 金融セクターのサイバーリスクを試算する; クリスティーヌ・ラガルド, IMF ブログ 2018年6月22日掲載
- Memprakirakan Risiko Cyber untuk Sektor Keuangan; IMF blog; 22 Juni 2018
- Оценка кибер-риска для финансового сектора; Кристин Лагард; Блог МВФ; 22 июня 2018 года
References
- عربي
- Português
- https://www.imf.org/wp-content/uploads/2018/06/BLOG-1024x600-cyber-security-EtiAmmos-gettyimages-iStock-854938338.jpg
- https://www.imf.org/wp-content/uploads/2018/06/eng-june-19-cyber-losses1-1-1.png
- international organizations
- https://www.imf.org/wp-content/uploads/2018/06/eng-june-19-cyberlosses2.png