2018年-WEF世界经济论坛_Innovation-Driven_Cyber-Risk_to_Customer_Data_in_Financial_Services_22页_853kb
报告摘要
Summary of Innovation-Driven Cyber-Risk to Customer Data in Financial Services
Core Content
This document explores the growing cyber-risk to customer data in the financial services industry due to innovation-driven technologies. It outlines a three-stage process to identify, design, and prioritize solutions to address these risks, emphasizing the need for collaboration between the public and private sectors.
The financial services system is increasingly reliant on technology, which has both expanded the attack surface and enabled more sophisticated cyber-attacks. The report highlights that innovations such as digitization, open APIs, Internet of Things (IoT), artificial intelligence (AI), and blockchain are reshaping the cyber-risk landscape, presenting both opportunities and challenges.
The report identifies 19 potential solutions to mitigate innovation-driven cyber-risk, but two are prioritized for further action: cyber-risk metrics and cybersecurity assessment. These solutions aim to improve risk understanding, comparability, and security readiness across the financial services industry.
Main Challenges
-
Innovation is increasing cyber-risk to customer data
- New technologies expand data collection, sharing, and attack capabilities.
- Customers and employees may be desensitized to data security practices.
- Legacy systems in incumbent firms are more vulnerable to attacks.
-
Financial services firms face specific challenges in managing cyber-risk
- Technical and operational expertise is limited.
- Regulatory fragmentation hinders effective oversight.
- Third-party risk is not well managed.
- Cybersecurity frameworks are inconsistent and uncoordinated.
-
Strategic, innovative, multistakeholder solutions are needed
- Cyber-risk is not just a technical issue but a strategic one.
- Collaboration across public and private sectors is essential.
- Solutions must be sustainable, scalable, and actionable.
Key Solutions
1. Cyber-Risk Metrics
-
Purpose: To help organizations better quantify and understand their cyber-risk exposure.
-
Main Points:
- Current metrics are non-standardized and inadequate.
- Advanced, standardized metrics would support risk-based decision-making and investment planning.
- Enables comparability across firms and with regulators.
- Supports legacy system evaluation and cyber insurance development.
-
Next Steps:
- A joint industry venture could develop preliminary metrics.
- Leverage existing frameworks like NIST.
- Work towards public-private collaboration using risk-based metrics.
2. Cybersecurity Assessment
-
Purpose: To improve cybersecurity readiness and risk management across the industry.
-
Main Points:
- Includes common principles, point-based scoring, and practical steps for improvement.
- Provides actionable solutions for fintechs and incumbents.
- Raises cybersecurity standards across the board.
- Encourages cybersecurity by design, ensuring secure innovation.
-
Next Steps:
- Convene a working group of public and private stakeholders.
- Model on US Chamber of Commerce projects and NIST updates.
- Develop best practices that align with regulatory guidance and offer practical steps to enhance security.
Main Recommendations
- Standardized Cyber-Risk Measurement: Develop advanced and standardized approaches to quantify cyber-risk.
- Enhanced Cybersecurity Assessment: Create common principles, scoring mechanisms, and improvement steps to evaluate and enhance cybersecurity readiness.
- Collaborative Framework: Use public-private partnerships to build a toolkit for managing cyber-risk in a fast-changing environment.
- Strategic Approach: Focus on strategic, innovative, and multistakeholder solutions to address systemic cyber-risk.
Conclusion
The financial services industry must collaborate across sectors to manage innovation-driven cyber-risk effectively. The proposed solutions provide a framework for improving cybersecurity through risk awareness, assessment, and public-private cooperation. By adopting these initiatives, the industry can balance innovation with security, ensuring trust and resilience in an increasingly digitized world.
试读结束,高清完整版pdf/doc/ppt,请点下载