2018年-SWIFT环球同业银行金融电讯_How_Cyber_Attackers_Could_Target_the_Worlds_Financial_Markets_32页_9mb
报告摘要
Summary of "The Evolving Advanced Cyber Threat to Financial Markets"
Core Content
This document outlines the evolving nature of advanced cyber threats in financial markets, with a focus on the risks posed to both Market Infrastructures and Participants. It emphasizes the need for a holistic, cross-functional approach to cybersecurity, involving collaboration across all levels of an organization and with industry peers and regulators.
Main Threats and Trends
- Cyber Threat Scale: The financial sector faces an unprecedented scale of cyber threats, ranging from individual customer attacks to systemic risks posed by ransomware and APT groups.
- Threat Evolution: The threat landscape is continuously changing, with attackers adapting their methods and targeting areas that are more complex and less regulated.
- Market Vulnerabilities: Certain financial markets are more vulnerable due to their complexity, lack of standardization, and reliance on trust-based interactions.
Key Markets and Their Risks
| Market | Threat Level | Key Vulnerabilities |
|---|---|---|
| Foreign Exchange (FX) | Medium Term | Complex, multi-level operations; high volume; potential for direct cash out |
| Banking and Payments | Near Term | Direct cash out opportunities; improved defenses via SWIFT CSP |
| Trade Finance | Near Term | Relatively lower return for attackers; trust-based interactions |
| Securities | Near Term | High number of participants; complex and diverse market; long chains of custody |
Main Threats to Market Infrastructures
- Standardization and Oversight: Market Infrastructures are generally more standardized and subject to greater oversight, making them harder to attack.
- Complexity of Interactions: Despite this, their complexity and the number of interactions with Participants create potential vulnerabilities.
- Stealthiness and Traceability: The high volume and complexity of transactions make it difficult to detect subtle changes, but transactions are well-documented, enabling traceability.
Main Threats to Participants
- Higher Susceptibility: Participants are more vulnerable due to varied cyber maturity, complex interactions, and reliance on trust.
- Misplaced Trust: Manual and automated hybrid processes, combined with trust in systems and procedures, provide opportunities for APT groups.
- Cash Out Opportunities: Participants have more straightforward cash out paths compared to Market Infrastructures.
Key Trends and Themes
- Understanding of Market Practices: Practices such as delivery free of payment and documentary collection are vulnerable to cyber exploitation.
- Digitisation and Automation: While beneficial, these trends increase the risk of cyber attacks if not properly secured.
- Disruption and Competition: The rise of FinTechs and new entrants increases the risk due to the introduction of less mature technologies and processes.
Recommendations
- Holistic Approach: Cybersecurity must be integrated across all levels of an organization, from the board to operations.
- Collaboration: Stakeholders must work together to understand market operations, share threat intelligence, and defend against APT attacks.
- Structured Risk Assessment: Organizations should map out their people, processes, technology, and dependencies to identify and address potential cyber threats.
Immediate Actions
- Continuous Improvement: Security programs must be continually updated and reviewed.
- Review Vulnerable Practices: Identify and mitigate risks in market practices that rely on trust and unstructured communication.
- Strengthen Upstream Systems: Beyond securing payment systems, organizations should ensure protections are extended to upstream systems.
Threat and Susceptibility Factors
| Factor | Description |
|---|---|
| Ease of Attack | The effort required to attack Market Infrastructures is high due to their importance and awareness. |
| Reward per Attack | High due to the large volume and value of transactions in FX and securities markets. |
| Repeatability | Low due to the diversity of Market Infrastructures and their functions. |
| Stealthiness | High due to the complexity and volume of transactions, making subtle changes hard to detect. |
| Ease of Cash Out | Difficult for Market Infrastructures but more straightforward for Participants. |
| Traceability | High due to the detailed recording of transactions, which supports audit trails. |
| Complexity | FX and securities markets are more complex due to the variety of interactions and operations. |
| Standardisation | FX and banking and payments markets are more standardised, reducing attack opportunities. |
| Concentration | Market Infrastructures are concentration points, making them systemically important. |
| Regulation Oversight | Greater oversight for Market Infrastructures, but less for Participants. |
| Transaction Speed | Faster transaction speeds in some markets increase the risk of cyber exploitation. |
Conclusion
The document highlights that while Market Infrastructures are generally more resilient due to standardization and oversight, Participants are more vulnerable due to their complex, trust-based interactions and varying levels of cyber maturity. It stresses the importance of continuous vigilance, collaboration, and structured risk assessments to effectively counter the evolving threat from APT groups.
试读结束,高清完整版pdf/doc/ppt,请点下载