In the midst of several large cyberattacks in 2017, the European Commission adopted its multi-sector cybersecurity package in September of that same year. Whereas this initiative can be expected to contribute to strengthening the cyber-resilience and response of EU financial firms, several policy issues and unanswered questions remain. In order to analyse the issues that are considered to be relevant to financial fields (retail banking, corporate banking, capital markets, financial infrastructure and insurance), CEPS-ECRI organised a Task Force between September 2017 and May 2018 with a group of experts from the financial industry, tech industry, national supervisors and European institutions, as well from a consumer association and a law firm.
In this Final Report, the Task Force members identify the following nine policy issues that need to be further addressed in order to bolster the financial industry’s cyber-resilience against current and future threats.
Main policy recommendations
- Convergence in the taxonomies of cyber-incidents is needed.
- The framework for incident reporting needs to be significantly improved to fully contribute to the cyber-resilience of financial firms.
- Authorities should assess how and to what extent the data held by the centralised hub should be shared with supervisors, firms and clients.
- Ambitious policies are needed to develop consistent, reliable and exploitable statistics on cyber-trends.
- Best practices for cyber-hygiene should be continuously enhanced by regulators and supervisors.
- The European Cybersecurity Certification Scheme needs to be strengthened to contribute better to cybersecurity, cyber-risk management and capability.
- In order to improve the processes of attribution and extradition, the reinforcement of cross-border cooperation and legal convergence remains a priority, both within the EU and more widely.
- Best practices in remedies in case of cyberattacks need to be further encouraged.
- Policy-makers should further assess the pros, cons and feasibility of creating an emergency fund in case of large cyberattacks.