## Estimating Cyber Risk for the Financial Sector

_IMF Blog, June 22, 2018_

## Source details

**Canonical URL:** [Estimating Cyber Risk for the Financial Sector](https://www.imf.org/en/blogs/articles/2018/06/22/blog-estimating-cyber-risk-for-the-financial-sector)

## Other formats

- [Markdown version](/en/blogs/articles/2018/06/22/blog-estimating-cyber-risk-for-the-financial-sector/index.md)
- [Structured JSON version](/en/blogs/articles/2018/06/22/blog-estimating-cyber-risk-for-the-financial-sector/index.json)
- [Bundle manifest](/en/blogs/articles/2018/06/22/blog-estimating-cyber-risk-for-the-financial-sector/bundle-manifest.json)

## Bibliographic details
- Authors: Christine Lagarde
- Published: June 22, 2018

---

### Cyber risk overview
- Author: Christine Lagarde
- Date: June 22, 2018
- Summary finding: Cyber risk has emerged as a significant threat to the financial system; an IMF staff modeling exercise estimates that average annual losses to financial institutions from cyber-attacks could reach a few hundred billion dollars a year, eroding bank profits and potentially threatening financial stability.
- Recent examples cited:
  - Data breaches exposing confidential information.
  - Fraud, such as the theft of $500 million from the Coincheck cryptocurrency exchange.
  - Risk that a targeted institution could be left unable to operate.

### Financial sector’s vulnerability
- Reasons for heightened vulnerability:
  - Financial institutions’ crucial role in intermediating funds makes them attractive targets.
  - High interconnectedness means a successful attack on one institution could spread rapidly.
  - Many institutions still use older systems that might not be resilient to cyber-attacks.
  - Successful cyber-attacks cause direct financial losses and indirect costs such as diminished reputation.
- Observations:
  - Surveys consistently show risk managers and executives at financial institutions worry most about cyber-attacks.
  - Quantitative analysis of cyber risk is still at an early stage due to lack of data and modeling difficulties.

### Estimating potential losses (modeling framework and results)
- Methodology:
  - Uses techniques from actuarial science and operational risk measurement to estimate aggregate losses from cyber-attacks.
  - Requires assessment of frequency of cyber-attacks on financial institutions and distribution of losses from such events.
  - Numerical simulations used to estimate distribution of aggregate cyber-attack losses.
- Data example:
  - Illustration uses a data set covering recent losses due to cyber-attacks in 50 countries.
  - The exercise is difficult and challenged by major data gaps on cyber risk.
- Key quantitative findings (reported as illustrative):
  - Average annual potential losses from cyber-attacks may be large, close to 9 percent of banks’ net income globally, or around $100 billion.
  - In a severe scenario — in which the frequency of cyber-attacks would be twice as high as in the past with greater contagion — losses could be 2½–3½ times as high as this, or $270 billion to $350 billion.
  - Distributional insight: in extreme scenarios representing the worst 5 percent of cases, average potential losses could reach as high as half of banks’ net income, putting the financial sector at risk.
  - Note: Thankfully, there has yet been no successful, large-scale cyber-attack on the financial system.

### Insurance market and gaps
- Current market size and limitations:
  - Cyber insurance market remains small with around $3 billion in premiums globally in 2017.
  - Most financial institutions do not carry cyber insurance.
  - Coverage is limited.
- Insurer challenges:
  - Difficulty evaluating risk because of uncertainty about cyber exposures, lack of data, and possible contagion effects.
- Comparative note:
  - Estimated potential losses are several orders of magnitude greater than the present size of the cyber insurance market.

### The way forward (policy recommendations and operational steps)
- Data and reporting:
  - Government collection of more granular, consistent, and complete data on frequency and impact of cyber-attacks would help assess risk for the financial sector.
  - Requirements to report breaches—such as considered under the EU’s General Data Protection Regulation—should improve knowledge of cyber-attacks.
- Analytical tools:
  - Use scenario analysis to develop comprehensive assessment of how cyber-attacks could spread and to design adequate responses by private institutions and governments.
- Resilience and capacity building:
  - Further work needed to understand how to strengthen resilience of financial institutions and infrastructures to reduce odds of successful attacks and facilitate rapid recovery.
  - Need to build capacity in the official sector in many parts of the world to monitor and regulate such risks.
- Regulatory and supervisory priorities:
  - Strengthen regulatory and supervisory frameworks for cyber risk.
  - Focus on effective supervisory practices, realistic vulnerability and recovery testing, and contingency planning.
  - IMF is providing technical assistance to help member countries improve their regulatory and supervisory frameworks.

*Estimating Cyber Risk for the Financial Sector — Christine Lagarde, June 22, 2018*

---

## Content in this bundle

- **估计金融部门的网络风险; IMF blog, 2018 年6 月22 日**
  - [估计金融部门的网络风险; IMF blog, 2018 年6 月22 日 (Markdown version)](/external/chinese/np/blog/2018/062218c.pdf.md){rel="alternate" type="text/markdown"}
  - [估计金融部门的网络风险; IMF blog, 2018 年6 月22 日 (PDF)](/external/chinese/np/blog/2018/062218c.pdf){rel="external" type="application/pdf"}
- **金融セクターのサイバーリスクを試算する;   クリスティーヌ・ラガルド, IMF ブログ 2018年6月22日掲載**
  - [金融セクターのサイバーリスクを試算する;   クリスティーヌ・ラガルド, IMF ブログ 2018年6月22日掲載 (Markdown version)](/external/japanese/np/blog/2018/062218j.pdf.md){rel="alternate" type="text/markdown"}
  - [金融セクターのサイバーリスクを試算する;   クリスティーヌ・ラガルド, IMF ブログ 2018年6月22日掲載 (PDF)](/external/japanese/np/blog/2018/062218j.pdf){rel="external" type="application/pdf"}
- **Memprakirakan Risiko Cyber untuk Sektor Keuangan; IMF blog; 22 Juni 2018**
  - [Memprakirakan Risiko Cyber untuk Sektor Keuangan; IMF blog; 22 Juni 2018 (Markdown version)](/external/lang/indonesian/np/blog/2018/062218i.pdf.md){rel="alternate" type="text/markdown"}
  - [Memprakirakan Risiko Cyber untuk Sektor Keuangan; IMF blog; 22 Juni 2018 (PDF)](/external/lang/indonesian/np/blog/2018/062218i.pdf){rel="external" type="application/pdf"}
- **Оценка кибер-риска для финансового сектора; Кристин Лагард; Блог МВФ;  22 июня 2018 года**
  - [Оценка кибер-риска для финансового сектора; Кристин Лагард; Блог МВФ;  22 июня 2018 года (Markdown version)](/external/russian/np/blog/2018/062218r.pdf.md){rel="alternate" type="text/markdown"}
  - [Оценка кибер-риска для финансового сектора; Кристин Лагард; Блог МВФ;  22 июня 2018 года (PDF)](/external/russian/np/blog/2018/062218r.pdf){rel="external" type="application/pdf"}

---

## References

- [عربي](http://www.imf.org/ar/News/Articles/2018/06/22/blog-estimating-cyber-risk-for-the-financial-sector)
- [Português](https://www.imf.org/pt/News/Articles/2018/06/22/blog-estimating-cyber-risk-for-the-financial-sector)
- [https://www.imf.org/wp-content/uploads/2018/06/BLOG-1024x600-cyber-security-EtiAmmos-gettyimages-iStock-854938338.jpg](https://www.imf.org/wp-content/uploads/2018/06/BLOG-1024x600-cyber-security-EtiAmmos-gettyimages-iStock-854938338.jpg)
- [https://www.imf.org/wp-content/uploads/2018/06/eng-june-19-cyber-losses1-1-1.png](https://www.imf.org/wp-content/uploads/2018/06/eng-june-19-cyber-losses1-1-1.png)
- [international organizations](https://blogs.imf.org/2017/10/26/cyber-defense-must-be-global/)
- [https://www.imf.org/wp-content/uploads/2018/06/eng-june-19-cyberlosses2.png](https://www.imf.org/wp-content/uploads/2018/06/eng-june-19-cyberlosses2.png)

_Source: https://www.imf.org/en/blogs/articles/2018/06/22/blog-estimating-cyber-risk-for-the-financial-sector_
