Georgia: Technical Assistance Report-Cyber Risk: Regulation, Supervision and Testing
Technical Assistance Reports, December 23, 2024
Source details
- Canonical URL
- Georgia: Technical Assistance Report-Cyber Risk: Regulation, Supervision and Testing
Other formats
Bibliographic details
- Published: December 23, 2024
- Series: Technical Assistance Reports
- DOI: https://doi.org/10.5089/9798400296154.019
Mission objectives
- Strengthen cyber risk regulation, supervision, and testing for the National Bank of Georgia (NBG).
- Focus areas:
- (i) an assessment of NBG’s cyber risk regulation,
- (ii) an assessment of cyber risk supervisory arrangements of NBG,
- (iii) assisting in the development of a cyber testing framework,
- (iv) assisting in the development of a methodology for cyber exercising and stress testing.
Key findings
- Cyber risk regulations, including incident reporting requirements, are in place, but gaps remain.
- Cyber risk supervision practices need improvements and more focus on supervisory priorities.
- Information sharing practices within the financial sector require strengthening.
- Cyber testing and exercises are an area where significant improvements are needed.
- Overall assessment: the NBG would benefit from an overarching cyber strategy for its financial sector.
Subject scope and keywords
- Subject areas covered: Auditing, Commercial banks, Cyber risk, Economic sectors, Financial institutions, Financial regulation and supervision, Financial sector, Operational risk, Public financial management (PFM), Technology.
- Keywords used: Auditing, Central Bank., Commercial banks, Cyber risk, Cyber risk regulation, cyber testing, cybersecurity risk management regulation, cybersecurity strategy, cybersecurity supervision, Financial sector, Georgia, Global, incident reporting, information security Act, information sharing, offsite supervision activity, Operational risk, request of the National Bank of Georgia.
Implications for policy and supervisory practice
- Regulatory strengthening:
- Address identified gaps in cyber risk regulations and incident reporting requirements.
- Supervisory focus:
- Improve cyber risk supervision practices and align supervisory priorities with identified risks.
- Enhance offsite supervision activity to better monitor cyber risks.
- Information sharing:
- Strengthen mechanisms for information sharing within the financial sector to improve collective cyber resilience.
- Testing and exercises:
- Develop and implement a comprehensive cyber testing framework.
- Establish a methodology for cyber exercising and stress testing to assess resilience across scenarios.
- Strategic framework:
- Develop an overarching cyber strategy for the financial sector to coordinate regulation, supervision, information sharing, and testing efforts.
International Monetary Fund. December 23, 2024.
Content in this bundle
- Preface — IMF Technical Assistance Report