Rising Cyber Threats Pose Serious Concerns for Financial Stability
IMF Blog, April 9, 2024
Source details
- Canonical URL
- Rising Cyber Threats Pose Serious Concerns for Financial Stability
Other formats
Bibliographic details
- Authors: Fabio Natalucci, Mahvash S Qureshi, Felix Suntheim
- Published: April 9, 2024
Key findings
- Cyberattacks have more than doubled since the pandemic.
- Some firms have incurred very large direct losses; US credit reporting agency Equifax paid more than $1 billion in penalties after a major data breach in 2017 that affected about 150 million consumers.
- The size of extreme losses from cyber incidents has more than quadrupled since 2017 to $2.5 billion.
- Indirect losses such as reputational damage or security upgrades are substantially higher than direct losses.
- Attacks on financial firms account for nearly one-fifth of the total, with banks the most exposed.
Financial sector exposure and mechanisms of harm
- Financial firms are uniquely exposed because they handle large amounts of sensitive data and transactions and are targets for criminals seeking to steal money or disrupt economic activity.
- Cyber incidents can:
- Erode confidence in the financial system.
- Disrupt critical services (for example, payment networks).
- Cause spillovers to other institutions and funding problems that could jeopardize solvency.
- Analysis suggests modest and somewhat persistent deposit outflows have occurred at smaller US banks after a cyberattack (no significant “cyber runs” have occurred thus far).
Illustrative incidents and channels of contagion
- A December attack at the Central Bank of Lesotho disrupted the national payment system, preventing transactions by domestic banks.
- A 2023 ransomware attack on a cloud IT service provider caused simultaneous outages at 60 US credit unions.
- Attacks often originate outside a firm’s home country and proceeds can be routed across borders, increasing the need for international cooperation.
Drivers and trends increasing systemic risk
- Greater digitalization and heightened geopolitical tensions imply that the risk of a cyberattack with systemic consequences has risen.
- Financial firms’ increasing reliance on third-party IT service providers, and potentially more so with the emerging role of artificial intelligence, can improve operational resilience but also increase exposure to systemwide shocks.
Policy recommendations and governance priorities
- Public intervention may be necessary because private incentives can be insufficient to address systemwide cyber risks.
- Authorities should develop an adequate national cybersecurity strategy accompanied by effective regulation and supervisory capacity that should encompass:
- Periodically assessing the cybersecurity landscape and identifying potential systemic risks from interconnectedness and concentrations, including from third-party service providers.
- Encouraging cyber “maturity” among financial sector firms, including board-level access to cybersecurity expertise; the chapter’s analysis suggests that better cyber-related governance may reduce cyber risk.
- Improving cyber hygiene of firms (such as antimalware and multifactor authentication) and training and awareness.
- Prioritizing data reporting and collection of cyber incidents, and sharing information among financial sector participants to enhance their collective preparedness.
- Financial firms should develop and test response and recovery procedures; national authorities should have effective response protocols and crisis management frameworks in place.
- International cooperation is imperative to address cross-border aspects of cyber risk.
Gaps in current frameworks
- According to an IMF survey of central banks and supervisory authorities, cybersecurity policy frameworks often remain insufficient, especially in emerging market and developing economies.
- For example, only about half of countries surveyed had a national, financial sector-focused cybersecurity strategy or dedicated cybersecurity regulations.
IMF engagement
- The IMF helps member countries strengthen cybersecurity frameworks through policy advice (for example as part of the Financial Sector Assessment Program) and through capacity-building activities.
Fabio Natalucci, Mahvash S. Qureshi, Felix Suntheim; April 9, 2024.
Content in this bundle
- Chapter 3