Cyber-Resilience—A Repeated Regulatory Message

Editor’s Note: See, Achieving a Cyber-Reliant Infrastructure.

From: Mondaq

Article by David Rundle | WilmerHale

An expectation that regulated financial services firms be ‘cyber-resilient’ should not cause any surprise. Cyber-crime and data breaches represent major risks for business generally. Comparatively, that risk is not mitigated by the standards of British employees, who have been found to be particularly ineffective at protecting their data and devices.1 Accordingly, cyber-crime has the potential to be profoundly destabilizing, as well as costly, to the UK financial services sector.

However, the framework against which the expectation of cyber-resilience translates into tangible and measurable obligations is not substantially developed. Two recent FCA public announcements provide some insight into the Regulator’s approach to cyber security, and indicate the direction and shape of regulatory change. The FCA released its Business Plan for 2017/2018 on 18 April.2 The document sets out the FCA’s priorities. ‘Technological change and resilience’ is one of six cross-sector priorities listed. The following week, on 24 April, the FCA’s acting COO (Nausicaa Delfas) delivered a speech at the Financial Information Security Network, titled “Expect the Unexpected – cyber security – 2017 and beyond”.3 Ms. Delfas reviewed the landscape of cybercrime risk, before proposing ways of managing it.

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *