卡内基国际和平基金会-Cyber-Risk-Scenarios-the-Financial-System-and-Systemic-Risk-Assessment_35页_1mb
报告摘要
Summary: Cyber Risk Scenarios, the Financial System, and Systemic Risk Assessment
Core Content
This working paper explores the evolving nature of cyber risk within the financial system, emphasizing its systemic implications and the challenges in assessing and mitigating such risks. It outlines various cyber risk scenarios, from idiosyncratic to systemic, and presents a framework for evaluating national systemic cyber risk. The paper also highlights the interconnectedness of financial institutions and the complexity of cyber threats, which make traditional risk assessment methods inadequate.
Main Views and Key Points
1. Cyber Risk as a Systemic Threat
- Cyber risk is not only an operational risk but also has systemic implications that can affect the entire financial system.
- Systemic cyber risk can cause chain reactions that disrupt services across logically and geographically connected components.
- The World Economic Forum defines systemic cyber risk as a threat that leads to significant delays, denials, breakdowns, disruptions, or losses in critical infrastructure, with cascading effects on public health, economic security, and national security.
2. Characteristics of Cyber Risk
- Complexity and Risk Aggregation: The rapid expansion of internet-connected devices and software has increased systemic exposure, making it harder to manage.
- Diversifiable vs. Undiversifiable Risk: While diversifiable risk can be mitigated through internal controls, undiversifiable risk persists due to reliance on third-party systems and the internet.
- Lack of Transparency: The interconnected and opaque nature of financial systems complicates ex-ante risk assessment and quantification.
3. Cyber Risk Scenarios
- Operational Risk Scenarios:
- Ransomware Attacks: Such as the Shamoon and WannaCry attacks, which caused operational disruption and financial loss.
- Wire Transfer Fraud: Involving insiders and malware to execute large-scale fraudulent transfers.
- Data Breaches and Information Leaks: Resulting in loss of trust and reputational damage, as seen in the ratings agency example.
- Upstream Infrastructure Scenarios:
- Disruptions to Central Clearing Platforms (CCPs): Coordinated attacks on CCPs can prevent trade clearing, leading to financial instability.
- Disruptions to Financial Market Infrastructures: Such as SWIFT or payment systems, which are critical nodes in the financial network.
- External Shock Scenarios:
- Natural Disasters or Armed Conflict: These can lead to unexpected cyber shocks that require government intervention.
- Systemic Cyber Events: Caused by multiple small-scale attacks with unknown linkages, leading to cascading effects and disruption.
4. Systemic Risk Assessment Framework
- The framework for systemic cyber risk assessment includes:
- Analyzing Cyber Risk Exposures
- Assessing Cybersecurity Preparedness
- Identifying Resilience Buffers to absorb shocks.
- Challenges in Assessment:
- Inadequate Data: Cyber risk data is scarce and not consistently measured in economic terms.
- Structural Limitations: Inexperience with large cyber events, uncertainty in shock transmission, and skewed incentives (e.g., underreporting) complicate risk assessment.
- Interconnectedness: Financial systems are highly interdependent, which amplifies contagion and makes systemic risk more likely.
5. Mitigation Strategies
- Risk Awareness: Policymakers and financial institutions need to recognize the systemic nature of cyber risk.
- Scenario Analysis: This helps in identifying vulnerabilities, transmission paths, and potential impacts of cyber events.
- Resilience Building: Including cyber insurance, buffer mechanisms, and improved coordination between institutions and governments.
Key Information
- Cyber risk is a growing concern for the financial system, with potential systemic consequences.
- Systemic cyber risk is defined as the risk of cascading failures that impact the entire financial ecosystem.
- The NotPetya attack in 2017 is cited as a real-world example of a systemic cyber event, causing billions in losses and disrupting global supply chains.
- Operational risk is now understood to include external threats and third-party dependencies, not just internal ones.
- Cyber insurance may not cover systemic events due to war clause exemptions.
- Systemic risk arises from:
- Risk concentration (e.g., reliance on key hubs like CCPs and SWIFT)
- Loss of confidence and risk correlation
- Shock amplification through complex interconnections
Conclusion
This paper underscores the importance of understanding cyber risk beyond its operational scope, and the need for a more comprehensive and systemic approach to risk assessment and mitigation. It advocates for scenario-based analysis, transparent data sharing, and enhanced preparedness to address the increasing complexity and interconnectedness of the financial system in the digital age.
试读结束,高清完整版pdf/doc/ppt,请点下载