Japan: Financial Sector Assessment Program-Technical Note on Cyber Resilience and Financial Stability
IMF Staff Country Reports, May 13, 2024
Source details
- Canonical URL
- Japan: Financial Sector Assessment Program-Technical Note on Cyber Resilience and Financial Stability
Other formats
Bibliographic details
- Published: May 13, 2024
- Series: IMF Staff Country Reports
- DOI: https://doi.org/10.5089/9798400276255.002
Executive summary and key findings
- The Technical Note focuses on Cyber Resilience and Financial Stability for the Japan Financial Sector Assessment Program.
- The cyber ecosystem is mature in Japan, with a range of stakeholders involved in ensuring the cybersecurity of the financial sector.
- The Financial Services Agency (FSA) is responsible for developing and operationalizing the cyber strategy for the financial sector.
- Cyber risk regulation and supervisory practice need further improvements.
- The Bank of Japan (BOJ) should strengthen the cyber risk oversight of financial market infrastructures.
- The FSA would benefit from deepening its analysis of the operational interconnectedness of the financial system.
- Further improvements in the response and recovery capabilities are recommended.
- The FSA and BOJ should keep upgrading, as necessary, a range of extreme but plausible cyber scenarios along with their existing Business Continuity Plans and/or Cyber Incident Response and Recovery Plans, for the financial sector.
- The authorities currently have strong cyber incident reporting regimes in place, with clear definitions, taxonomies, thresholds, and communication channels.
Policy recommendations and supervisory priorities
- Strengthen cyber risk regulation and supervisory practice across the financial sector.
- BOJ to enhance cyber risk oversight specifically for financial market infrastructures.
- FSA to deepen analysis of operational interconnectedness to better understand systemic cyber contagion channels.
- Improve response and recovery capabilities across financial entities and infrastructure providers.
- Regularly upgrade extreme but plausible cyber scenarios and integrate them into Business Continuity Plans and Cyber Incident Response and Recovery Plans.
Institutional roles and coordination
- Financial Services Agency (FSA): responsible for developing and operationalizing the cyber strategy for the financial sector.
- Bank of Japan (BOJ): recommended to strengthen oversight of financial market infrastructures.
- Multiple stakeholders: the report highlights a range of stakeholders involved in ensuring cybersecurity within Japan’s mature cyber ecosystem.
Publication and metadata
- Publication date: May 13, 2024
- Pages: 39
- Volume: 2024
- Issue: 113
- Series: Country Report No. 2024/113
- DOI: https://doi.org/10.5089/9798400276255.002
- Stock No: 1JPNEA2024005
- ISBN: 9798400276255
- ISSN: 1934-7685
Subjects and keywords
- Subject: Cyber risk; Economic sectors; Financial sector; Financial sector policy and analysis; Financial sector stability; Financial stability assessment; International organization; Monetary policy; PFM information systems; Public financial management (PFM); Technology
- Keywords: BOJ-NET participant; context of the Financial Sector Assessment Program; Cyber risk; Financial sector; Financial sector stability; Financial stability assessment; FSAP finding; Global; Japan Computer Emergency Response Team coordination Center; PFM information systems; securities commission
International Monetary Fund. Monetary and Capital Markets Department "Japan: Financial Sector Assessment Program-Technical Note on Cyber Resilience and Financial Stability", IMF Staff Country Reports 2024, 113 (2024).
Content in this bundle
- 1jpnea2024005 - Executive Summary