Amid growing concerns about cybersecurity in the financial sector, global standards setters are consulting on a proposed set of tools for cyber resilience at infrastructure firms — such as exchanges, clearing and settlement providers — and launched a consultation on the firms’ growing reliance on external providers.
In a joint release, the International Organization of Securities Commissions (IOSCO) and the Bank of International Settlements’ Committee on Payments and Market Infrastructures (CPMI) published a proposed toolkit that aims to strengthen the cyber and operational resilience of financial market infrastructure firms.
The proposed toolkit includes a set of “voluntary, non-binding tools” that set out practical considerations for a handful of areas, including governance, scenario identification, response and recovery plans, and testing these defences.
Among other things, the toolkit aims to address the growing threat posed by advances in AI models that have accelerated the speed, volume and complexity of cyber threats.
“AI-driven threats can now identify vulnerabilities and craft exploits in hours,” it said, adding that these advances have also “lowered the barrier to entry for malicious actors and increased the number of threat actors with sophisticated capabilities.”
Against that backdrop, infrastructure firms may need to “adapt their defensive measures and the policies, procedures and controls that support their cyber resilience frameworks to meet the evolving threat landscape,” it said.
The groups also issued a discussion paper that examines the risks and challenges posed by the growing reliance on third-party services, increasingly to provide critical services.
“The paper examines six key challenges and discusses how they may amplify risks, noting the particular importance of [infrastructure firms’] management of these risks due to their unique and highly interconnected role in the financial system,” it said.
Given the interconnected financial system and concentration in third-party providers, “any outage in their services could cascade risks and disruption throughout the financial system,” the paper said — adding that the market dominance of the limited number of third-party providers may intensify as the industry continues to transition towards cloud computing and other emerging technologies, such as AI.
The standards setters said that they are “seeking industry feedback on the materiality of these challenges, and on how CPMI-IOSCO may be able to help to address these challenges.”
The paper also aims to facilitate sharing of existing practices and views on third-party risk management.
Comments on both the toolkit and the discussion paper are due by Dec. 1.