Our latest post helping banks prior to their forthcoming ECB Cyber Resilience test.
Cyber Security & Resilience Researcher, Product Advocate and Advisor to keep businesses and individuals safe in business and as a volunteer at Parkrun.
Over 100 European banks will be tested on their cyber-attack response and recovery capabilities this year, the European Central Bank (ECB) has announced. https://lnkd.in/eSkEVYkZ Resilience is essential to keep CNI organisations operational. While distributed denial-of-service attacks remained the most common type of incident against banks, the recent increase in ransomware incidents has raised supervisory concerns. In the IT Risk Questionnaire Self Assessment form that banks have to submit, Question 13a in the IT Cyber Risk table states requires a response to "Of which (critical systems), the overall unplanned downtime (in hours,) that exceeded business agreements (e.g. SLA, RTO)? 'Unplanned Time' includes those exceptional incidents such as the cyber attacks noted at the start of this post. The image below is taken from the same IT Risk Questionnaire (IT Environment section), it specifically requires the respondent to detail their detection and recovery data points. As most ransomware attacks are not detected by any security tools (they have been evaded), it becomes a waiting game until a system or user is unable to access systems or data. In my recent report (link in the first comment box), the capability to restore data operations from backups in an acceptable Recovery Time (RTO) was found to be woefully inadequate, and the additional costs needed to accelerate the RTO would be included in question 32 of the image. Recovery time and significantly lower costs when recovering data can be achieved, but not from your existing tools. Read the report as it outlines your ability to score better and have data and devices immediately available. Synergy Six Degrees Cybrilliance NeuShield, Inc. Lloyds Banking Group HSBC NatWest Group Barclays Metro Bank (UK) BNP Paribas Crédit Agricole CIB UBS Groupe BPCE Societe Generale Deutsche Bank Crédit Mutuel Intesa Sanpaolo ING UniCredit Standard Chartered Bank La Banque Postale BBVA Rabobank DZ BANK AG #bankingtech #ransomwareprotection #cio #ciso