卡内基国际和平基金会-The-European-Union-Cybersecurity-and-the-Financial-Sector-A-Primer_45页_665kb
报告摘要
The European Union, Cybersecurity, and the Financial Sector: A Primer Summary
Core Content
This working paper provides an overview of the current regulatory landscape for cybersecurity in the European financial sector and outlines recommendations for improving it. It highlights the increasing importance of cybersecurity in the financial system and the need for a harmonized, comprehensive, and effective legislative framework to address the risks associated with information and communication technology (ICT).
The paper discusses the evolution of European cybersecurity regulation, emphasizing the complexity and fragmentation of the current system. It also evaluates the European Commission's (EC) proposed Digital Operational Resilience Act (DORA), which aims to create a unified approach to digital operational resilience across the financial sector.
Main Viewpoints
-
Regulatory Fragmentation: The EU lacks a single overarching cybersecurity legislation for the financial sector, resulting in a complex and fragmented regulatory environment. Different subsectors (banking, insurance, financial market infrastructures) are subject to varying standards and requirements.
-
Non-Sector-Specific Legislation: The NIS Directive and GDPR are the two most significant general European regulations affecting financial institutions. The NIS Directive focuses on critical infrastructure, while the GDPR standardizes data protection across the EU.
-
Sector-Specific Regulations: The financial sector is governed by multiple sector-specific regulations such as PSD2, CRR, CRD IV, and others. These regulations are more detailed in the banking and payment services subsector, but less explicit in insurance and financial market infrastructures.
-
Emerging Focus on Cyber Resilience: The EC has recognized the need for a more comprehensive approach to cybersecurity, leading to the proposal of DORA, which addresses four key areas: ICT security and risk management, sectoral incident reporting, third-party oversight, and cyber resilience testing.
-
Need for Systemic Approach: Cyber risks are not only a concern for individual institutions but also have implications for the entire financial system. The paper advocates for incorporating systemic dimensions into both legislation and regulatory actions.
Key Information
-
NIS Directive (2016): Applies to operators of essential services (OES), including certain financial institutions. It requires member states to implement national cybersecurity strategies and ensure that OES take appropriate security measures. It does not apply uniformly across all EU member states.
-
GDPR (2016): Aims to standardize data protection across the EU. It applies to all organizations processing personal data and has binding legal force. Financial institutions are heavily impacted due to the volume of data they handle.
-
DORA (2020): The EC's proposed legislation to create a harmonized framework for digital operational resilience in the financial sector. It is part of the digital finance package and is expected to address current gaps and enhance security across the sector.
-
Regulatory Challenges: The current regulatory landscape leads to confusion and overlap, with financial institutions often required to comply with multiple regulations. This fragmentation complicates compliance and can result in inconsistent security levels.
-
Recommendations:
- Establish a single European legislation on ICT and cybersecurity for all financial institutions to ensure harmonization and a baseline of requirements.
- Shift to a risk-centric approach to better align with the goals of operational resilience.
- Incorporate the systemic dimension of cyber risk into legislation and supervision, including macroprudential measures.
- Enhance cooperation mechanisms such as CIISI-EU and ENISA to improve information sharing and coordination between public and private stakeholders.
Structure of the Regulatory Framework
The paper outlines the existing regulatory framework with a focus on legislation relevant to ICT and cybersecurity in the financial sector. It differentiates between general European legislation and sector-specific standards, highlighting the overlap and differences between them. The framework is divided into the following areas:
-
General Legislation:
- NIS Directive
- GDPR
-
Sector-Specific Legislation:
- CRR and CRD IV
- PSD2
- Solvency II
- MiFID II
- EMIR
- CSDR
- CRAR
- SIPS Regulation
Conclusion
The paper concludes that while significant progress has been made in cybersecurity regulation for the financial sector in Europe, there are still gaps and inconsistencies. DORA represents a promising step towards a more unified and effective regulatory approach. However, to achieve a consistent, effective, and comprehensive legislative landscape, the EC must ensure that DORA is adopted without major changes and that regulatory cooperation and information sharing are enhanced across the EU.
About the Authors
- Philipp S. Krüger: Researcher and expert in cybersecurity and financial regulation.
- Jan-Philipp Brauchle: Researcher and expert in cybersecurity and financial systems.
Notes
- The paper is part of the Cyber Policy Initiative Working Paper Series.
- It is designed to stimulate debate and provide fresh ideas on cybersecurity in the financial system.
- The authors emphasize the need for a holistic approach to cybersecurity regulation in the financial sector.
试读结束,高清完整版pdf/doc/ppt,请点下载