A. Widespread Expectations and Practices –
B. Expectations on the Scope of the Ecosystem and Management of Third Parties
C. Observed Supervisory Practices
Cyber-resilience refers to an organization’s ability to anticipate, withstand, and recover from cyber incidents while continuing its mission.
Common standards include NIST, ISO/IEC, and COBIT, which guide cybersecurity practices globally.
Regulators use off-site reviews, on-site inspections, and penetration tests to assess cybersecurity frameworks and ensure alignment with international best practices.
The Board of Directors oversees the implementation of cybersecurity strategies and ensures alignment with broader risk management frameworks.
Cyber-risk awareness among all staff, including management, is critical to fostering a risk culture that supports overall cyber-resilience.
Third-party risks include vulnerabilities introduced by outsourcing, interconnected systems, and service providers, which need to be monitored to safeguard data and operations.
Organizations conduct penetration tests, business continuity tests, and response exercises to ensure the effectiveness of their cybersecurity frameworks.
Incident response involves identification, analysis, classification, escalation, and post-incident learning to prevent future cyber incidents.
Information-sharing among banks, regulators, and security agencies helps mitigate cyber threats and facilitates coordinated responses to cyber incidents.
Auditing third-party cybersecurity is complex due to varying regulations, service provider involvement, and the need for direct audit rights in outsourcing agreements.