布鲁盖尔-Hybrid-and-cybersecurity-threats-and-the-European-Union-s-financial-system_14页_465kb
报告摘要
Summary of "Hybrid and Cybersecurity Threats and the European Union's Financial System"
Core Content
This policy contribution by Maria Demertzis and Guntram Wolff examines the growing risks posed by cyber and hybrid threats to the European Union's financial system, emphasizing the need for enhanced resilience and integration of security measures across the EU.
Main Viewpoints
- Hybrid threats are defined as activities by state and non-state actors that combine conventional and non-conventional means to destabilize the EU and its member states. These threats are multidimensional, involving diplomatic, military, economic, and technological tactics.
- Cyber attacks are a key component of hybrid threats but are not always hybrid in nature. They can be purely criminal in intent and affect financial institutions independently of hybrid strategies.
- The financial system is considered an essential service, and the NIS Directive (2016/1148/EU) mandates that EU countries ensure cybersecurity for critical market operators, including the financial sector.
- Cybersecurity risks are increasingly costly and frequent, with 61% of companies reporting one or more cyber events in 2018, up from 45% the previous year. These attacks can lead to significant financial losses and operational disruptions.
- Systemic risks are a major concern, as cyber attacks can propagate through interconnected systems and affect the entire financial infrastructure. This is highlighted by the example of the Bulgarian tax authority cyber attack in 2019, which exposed personal data of 5 million citizens.
Key Information
Rising Cyber Threats
- Frequency and cost of cyber attacks have increased significantly.
- Small and medium-sized companies are often targeted, with data breaches and sabotage causing substantial damage.
- Media reports indicate a clear upward trend in cyber incidents affecting financial institutions in the EU.
Hybrid Threats and Their Implications
- Hybrid threats can involve social media disinformation, cyber attacks, and physical disruptions (e.g., electricity blackouts).
- These threats are difficult to detect or attribute, and their combined effects can lead to panic, loss of trust, and systemic instability.
- The 2007 Estonia cyber attack and the 2014 Bulgaria bank run are cited as real-world examples of hybrid threats.
EU's Response
- The EU has developed a comprehensive set of policies to address hybrid threats, including the NIS Directive, cybersecurity strategy, and guidelines for financial market infrastructures (FMIs).
- The ECB's Cyber Resilience Oversight Expectations (CROE) outline key expectations for governance, risk identification, protection, testing, and response procedures.
- TIBER-EU, a testing framework developed by the ECB and ESA, aims to improve resilience rather than enforce accountability.
Challenges and Gaps
- Systemic preparedness remains underdeveloped, despite progress at the institutional level.
- Collaboration between the private sector and EU authorities is suboptimal, with limited information sharing and inconsistent risk assessments.
- Governance asymmetry between national and EU levels is a problematic feature, especially as the global security environment becomes more complex and adversarial.
- The EU's reliance on the US for military and security infrastructure is questioned, as trust in the US declines and security weaknesses are exposed.
Recommendations
- EU finance ministers should increase preparedness through regular exercises and system-wide regulatory considerations.
- A broader political discussion is needed to integrate the EU's security architecture with the financial system.
- The foreign investment screening framework should be reopened to ensure EU-level oversight of critical financial infrastructure.
- Enhanced intelligence sharing between national and EU institutions is essential for effective response and preparedness.
Conclusion
The EU faces real and complex threats from both cyber and hybrid attacks, which can disrupt public trust, financial stability, and economic continuity. While individual institutions have made significant strides in cybersecurity preparedness, systemic coordination and policy integration remain areas of concern. A more holistic and integrated approach is necessary to ensure the resilience of the EU's financial system in the face of evolving threats.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载