Cyber Attacks On Banks Could Trigger Financial Crisis

The head of the European Central Bank (ECB) has warned that a combined cyber-attack on important banks could trigger financial crisis and instability.

The financial system has so far weathered larger-scale cyber-attacks, but some now argue that the system has not been properly tested for a systemic cyber-attack. As the connection between cyberspace and the real economy intensifies, amid widely expected further increases in interdependency, interconnectivity, and complexity, the probability that an external shock will affect the financial system and become a systemic event increases.

Christine Lagarde (pictured), the ECB’s president, said that a report by the European Systemic Risk Board (ESRB) estimates the global cost of cyber-attacks at between $45bn and $654bn. “As an operator of critical infrastructures, the ECB obviously takes such threats very seriously,” she said earlier this moneth, adding that there are several “plausible channels” through which a cyber-attack could morph into a serious financial crisis. One such channel might be an operational outage that destroyed or encrypted the balance accounts of a major financial institution could trigger a liquidity crisis. 

The report by the ESRB, which was set up by the European Commission, will look how a cyber incident could, under certain circumstances, rapidly escalate from an operational outage to a liquidity crisis.

It will say that in common with historical financial crises this liquidity crisis could, in certain circumstances, lead to a systemic crisis. At its most recent board meeting the ESRB revealed that it had identified cyber warfare as a source of risk to the financial system.

Last year, the G7 announced a joint cross-border crisis management exercise on a cyber incident affecting the financial system that it carried out in June 2019, saying that cyber risks were increasing and posed a “genuine and growing threat” to the stability and integrity of the financial sector. It was the first exercise of its kind to be organised by finance ministries, central banks, regulators and financial market authorities. It did not reveal the results but the G7 asked its Cyber Experts Group to review financial regulation, and to look at whether the impacts could be measured better. The Trump administration is expected to take up the issue when it assumes the G7 presidency this year.

In her speech, the ECB’s president also said it needed to look the risks and opportunities of issuing central bank digital currencies to respond to changing consumer demand and to strengthen Europe’s place in the world.

Last month, the Bank of England announced it would work with the ECB and the central banks of Canada, Japan, Sweden and Switzerland to share experiences as they assess the potential cases for central bank digital currency (CBDC). Central banks have accelerated their work on digital currencies after Facebook unveiled plans to introduce its Libra cryptocurrency and China said it was developing a digital currency.

Jake Moore, cybersecurity expert at ESET, said: “The recent Travelex ransomware attack highlighted the ease at which taking out one organisation can, in fact, knock on into other companies. “There will always be a cyber-risk posed to the financial industry due to the vast amounts at stake, but this risk is managed to the highest capacity." he said.  

"When companies work together to build more robust defenses we see the potential risk lowered and the best outcomes." 
 

Carnegie Endowment:       ECB Europa:       InfoSecurity Magazine:          Independent:       Image: WEF 

You Might Also Read:

Online Bank Fraud Is Up 40% In The UK:

Bank of England Testing Banks' Cyber Resilience:

 

 

 

« Cyber Incidents Jump Up The Risk Index
It Was The Chinese Army That Hacked Equifax »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Link11 GmbH

Link11 GmbH

Link11 provides DDoS protection solutions to protect websites and complete server infrastructures from DDoS attacks.

IGEL Technology

IGEL Technology

IGEL Technology is one of the world's leading thin client vendors. Thin clients increase data security and compliance.

ShmooCon

ShmooCon

ShmooCon is an annual east coast hacker convention offering three days of demonstrations and discussions of critical infosec issues.

StackRox

StackRox

StackRox delivers a container-native security platform that adapts detection and response to new threats.

National Cyber Security Authority (NCA) - Saudi Arabia

National Cyber Security Authority (NCA) - Saudi Arabia

The NCA is the government entity in charge of cybersecurity in Saudi Arabia and serves as the national authority on its affairs.

Crypto4A Technologies

Crypto4A Technologies

Crypto4A quantum-ready cybersecurity solutions significantly improve protection for Cloud, loT, Blockchain, V2X, government and military application deployments.

6point6

6point6

6point6 is a technology consultancy with strong expertise in digital transformation, emerging technology and cyber security.

Sovereign Intelligence

Sovereign Intelligence

Sovereign Intelligence provides automated insight into the relative intensity of hidden Cyber, Brand, and Financial Risks to your company.

SyncDog

SyncDog

SyncDog is a leader in enterprise security and the preeminent vendor for containerized mobile application security across cloud & on-premise computing environments.

Cyber Gate Defense (CyberGate)

Cyber Gate Defense (CyberGate)

CyberGate is an Emirati establishment founded with an objective to provide cyber security services that would improve the overarching cyber security posture of the UAE.

Let's Encrypt

Let's Encrypt

Let’s Encrypt is a free, automated, and open digital certificate authority, run for the public’s benefit. It is a service provided by the Internet Security Research Group (ISRG).

Air IT

Air IT

Air IT are a responsive, client-focused and award-winning Managed Service Provider, helping clients achieve success and transformation through their IT and communications.

Cyware

Cyware

Cyware is the only company building Virtual Cyber Fusion Centers enabling end-to-end threat intelligence automation, sharing, and unprecedented threat response for organizations globally.

Pathlock

Pathlock

Pathlock (formerly Greenlight) help enterprises and organizations automate the enforcement of any process, access, or IT general control, for any business application.

Global Resilience Federation (GRF)

Global Resilience Federation (GRF)

GRF builds, develops and connects security information sharing communities for mutual defense.

Fingerprints

Fingerprints

Fingerprints is the world-leading biometrics company. Our solutions are found in millions of devices providing safe and convenient identification and authentication with a human touch.