Don’t do SECURITY. Do business SECURELY.

CPMI-IOSCO publish cyber resilience guidance for financial market infrastructures

CPMI and IOSCO publish Guidance on Cyber Resilience for Financial Market Infrastructures, including a two-hour recovery expectation.

The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) have published the Guidance on Cyber Resilience for Financial Market Infrastructures, the first internationally agreed cyber resilience expectations for payment systems, central securities depositories, central counterparties and trade repositories.

Key points

  • Organised around governance, identification, protection, detection, and response and recovery.
  • Adds testing, situational awareness, and learning and evolving as overarching components.
  • Sets an expectation that critical operations can resume within two hours of a disruption.
  • Expects FMIs to manage cyber risk arising from participants, suppliers and other interconnected entities.
  • FMIs are expected to take immediate action with national regulators to implement it.

UK regulators, including the Bank of England, are expected to apply the guidance to the FMIs they supervise. Technology and service providers to FMIs should anticipate more demanding security, testing and recovery requirements in their contracts.

Source: Guidance on cyber resilience for FMIs (BIS CPMI-IOSCO)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights