FCA warns managers of wholesale banking and asset management firms have limited familiarity with cyber risks

Maria Nikolova

Firms reviewed by the FCA generally lacked Board members with strong familiarity or specific technical cyber-expertise.

The UK Financial Conduct Authority (FCA) has earlier today published the findings of cyber multi-firm review, covering a sample of companies from the wholesale banking and asset management sectors.

The review marked a further stage of discovery work which followed on from the FCA Technology and Cyber Resilience Questionnaire exercise in these sectors. Let’s recall that the survey showed cyber-attacks accounted for 18% of the operational incidents reported to the FCA between October 2017 and September 2018. Technology outages in the financial services sector are becoming more frequent. The number of such incidents reported to the FCA has increased by 138% in the year to September 2018.

The results of the review published today indicate there has been a growing level of public and regulatory focus on cybersecurity across financial services. Boards and Management Committees of wholesale banks and asset management companies are more sensitive to the topic than in the past. However, most continue to have limited familiarity with the specific cyber risks their organisations face.

“Almost all the Board members and non-IT senior management told us how challenging it was to fully understand and explain the specific risks that their firms face”, the FCA says.

Firms in the sample generally lacked Board members with strong familiarity or specific technical cyber-expertise. Many said this was because of their size, low risk-profile or the limited availability of that skillset in the wider independent non-executive director (INED) population.

The FCA notes that some firms viewed the range of consequences from a successful cyber-attack quite narrowly. For instance, in both the asset management and wholesale banking sectors, not all firms appeared to have considered the risk that their firm may be used as conduits to damage other firms or connected infrastructure. Nor had they considered the risk that attacks may be motivated by attempts to commit market abuse.

Beyond the Board and Management Committee, the FCA observed that that the second line of defence – the risk and compliance functions – has limited technical cyber-expertise.

The lack of in-house cyber knowledge results in a high level of reliance, potentially overreliance, on third-party advisors to supplement the firm’s cyber capabilities, the FCA warns. External expertise may be helpful but may also, if overly relied on, undermine the effectiveness of the ‘3 lines of defence’ model in identifying and managing cyber risks in a timely way.

Further findings concern testing. The FCA says it met firms that had carried out almost no testing of their cyber arrangements at all. The regulator also met others that had run extensive programs covering both staff, such as ethical phishing, and systems, including near-real simulated, so-called ‘red team’ attacks. Testing seemed to have most value where it was part of a considered strategy for managing cyber risks, and less value where the tests appeared piecemeal, with no clear plan on how to address the test’s findings.

Read this next

blockdag

Blockchain World Backs BlockDAG As The Best Performing Crypto With 30,000x ROI Potential, Beats Dogwifhat and Pepe Cryptos

Standing out among competitors like Dogwifhat (WIF) and Pepe (PEPE), BlockDAG is lauded by BLockChainWorld as the best-performing crypto with robust presale momentum.

Market News

Navigating Shifting Sands: Recession Risks and Global Commodity Trends

Regardless of the outcome of last Friday’s US labor market data, our indicators for the risk of recession have fallen surprisingly over the past few days: The ‘Macro Fever Curve’ fell from 100% recession risk to 86%…

blockdag

BlockDAG Introduces 10 New Crypto Deposit Methods As Presale Explodes To $23.6M; More On Shiba Inu and Avalanche Prices

Discover BDAG’s role in forecasting Shiba Inu prices and influencing Avalanche market trends with innovative payment methods, strategic investment phases, and a liquidity boost of $100 million.

Market News, Tech and Fundamental, Technical Analysis

EURJPY Technical Analysis Report 7 May, 2024

Given the prevailing daily uptrend, EURJPY currency pair can be expected to rise further toward the next resistance level 168.00.

Fintech

AS LPB Bank is transitioning to AS Magnetiq Bank and will henceforth focus on the FinTech and e-commerce sectors

AS LPB Bank officially changed its legal name to AS Magnetiq Bank, while also introducing a new brand visual identity.

Inside View

Finalto explains how brokers can better engage new retail traders

Marketing to a New Kind of Trader: (Without Alienating Your Main Audience) addresses the new challenges and opportunities faced by brokers amid spiking retail investor activity since 2021, which now accounts for nearly 25% of the total trading volume in the equities market. 

Industry News

UK FCA bans and fines ex-Shard James Lewis £120k

The regulatory agency claims that, in both instances, James Lewis knew the information he provided would be used to produce the clients’ annual accounts, and that’s why he misstated.

Market News

Rivian Stock Moves Higher Amid Mounting Anticipation for Q1 Report

The anticipation surrounding Rivian Automotive’s first-quarter earnings report has sent its stock on a rollercoaster ride of volatility.

Institutional FX

Amwal deploys Broadridge’s investment management platform

“We are delighted to provide Amwal Capital Partners with the technology they need to drive new efficiencies and automate their key processes, allowing them to make better-informed investment decisions and effectively manage their overall risk.”

<