Bank of England to push for enhanced operational resilience to cyber incidents at banks

Maria Nikolova

The Bank wants financial services firms to be able to demonstrate that they have concrete measures in place to deliver resilient services.

The Bank of England is setting the ground for new requirements concerning firms’ resilience to cyber incidents. This becomes clear from a speech given by Lyndon Nelson, Deputy CEO of the Bank of England’s Prudential Regulation Authority (PRA).

He concedes that there has been an increase in the number of operational incidents – be they caused by internal failures or from external attack. In terms of operational outages the financial sector in the UK has had RBS in 2012 which suffered a major outage in its Irish operations and more recently, of course, TSB. In between, there have been many short-term outages.

Given the circumstances, Lyndon Nelson underlined how important it is that regulators set out their expectations of firms in respect of their operational resilience. The Financial Policy Committee, for example, has been considering its tolerance for disruption to the key economic functions that the finance sector performs, he said. As part of this work, it is likely that the FPC will set a minimum level of service provision it expects for the delivery of key economic functions in the event of a severe but plausible operational disruption. The outlining of supervisory expectations may then be used as an input to guide firms’ actions in managing their own operational resilience.

Lyndon Nelson said he expects that these tolerances will use a combination of time, volume, market share and measures of interconnectedness.

“We have also been developing a suite of supervisory tools that can be used to assess firms’ resilience against our expectations and also inform the supervisory priorities we agree with firms”. Lyndon Nelson says.

He said the Bank was also trialling some other diagnostic tools.

Mr Nelson said the work will start with a Discussion Paper – joint with the Financial Conduct Authority. Although he would not elaborate on the details of the paper, he gave his perspective on these expectations.

“I would like our firms to be on a WAR footing: withstand; absorb; recover”, says Lyndon Nelson.

Firms will be expected to set their own tolerances for key business services. These tolerances will have to be in the form of clear metrics indicating when a disruption would represent a threat to a firm, to consumers or to financial stability. The Bank expects firms to test their tolerances and demonstrate to their supervisors that they have concrete measures in place to deliver resilient services.

In addition, firms will need to clearly define and regularly test their approaches to incident management. These should also include good communication plans both internally and externally.

And firms need to be able to recover from an operational incident. This requires viable, tested contingency plans for the resumption of critical functions.

Lyndon Nelson also made some remarks on the response to cyber incidents. The UK authorities have a response protocol called the Authorities Response Framework (ARF). It consists of the Treasury, FCA and the Bank. In cases of cyber events the National Cyber Security Centre is also a member. Any member can trigger the ARF and it has three response levels: monitor, engage and manage. A few years ago the ARF was rarely triggered, Nelson said, but more recently this has been increasing. This is partially due to the lowered barrier for triggering the mechanism but also because of the greater frequency of events.

Read this next

Digital Assets

Bitcoin halving is done: ViaBTC mines historic block 840K

The Bitcoin network has confirmed its fourth-ever halving block, mined by the cryptocurrency pool ViaBTC, according to data from Blockchain.com. This significant event in the Bitcoin ecosystem reduced the mining reward by half, a deflationary measure occurring approximately every four years to control the issuance of new bitcoins and curb inflation.

Retail FX

True Forex Funds now offers Match-Trader and cTrader platforms

Proprietary trading firm True Forex Funds today announced the launch of Match-Trader, a multi-asset trading platform developed by California-based FX technology provider Match-Trade Technologies.

Retail FX

CySEC hits FXORO parent with €360,000 fine

The Cyprus Securities and Exchange Commission (CySEC) has fined MCA Intelifunds, trading as FXORO, a total of €360,000 for multiple violations of the Cypriot investment laws.  

Digital Assets

Binance’s CZ in good mood ahead of sentencing, says partner

Yi He, co-founder of cryptocurrency giant Binance, has shared a positive outlook on the legal situation of the exchange’s former CEO, Changpeng Zhao. Zhao is currently awaiting a sentencing hearing scheduled for April 30 in the United States.

Fundamental Analysis, Tech and Fundamental

Global FX Market Summary: USD, FED, Middle East Tensions April 17 ,2024

The Federal Reserve walks a delicate line, addressing high inflation through a hawkish stance while avoiding stifling economic growth.

blockdag

‘Kaspa Killer’ BlockDAG Goes To The Moon With $18.5M Presale, Draws Attention from AVAX and Kaspa Investors

Discover how ‘Kaspa Killer’ BlockDAG’s $18.5M presale and 400% surge positions it as the fastest-growing crypto, amidst AVAX’s anticipated market rally and Kaspa’s performance gains.

Tech and Fundamental, Technical Analysis

Bitcoin Technical Analysis Report 19 April, 2024

Bitcoin cryptocurrency can be expected to rise further toward the next resistance level 67000.00, top of the previous minor correction ii.

Digital Assets

Crypto.com denies setback in South Korean market entry

Crypto.com has refuted reports from South Korean media that suggested a regulatory hurdle might delay its expansion in South Korea.

Digital Assets

Tether expands USDT and XAUT offerings on Telegram

Tether’s stablecoin USDT, which boasts a market cap of $108 billion, has expanded its presence onto The Open Network (TON), a blockchain closely linked to the Telegram messaging app.

<