ALSE / PUBLICATIONS / EDUCATIVE MATERIALS
Information Technology
in Financial Markets
COVID-19 and Cyber Risk in the Financial Sector
By Iñaki Aldasoro, Jon Frost, Leonardo Gambacorta and David Whyte
Cyber risk is an umbrella term that encompasses a wide range of risks resulting from the failure or disruption of IT systems. As the economy and financial system become increasingly digitalized, cyber risk is growing. During the COVID-19 pandemic, financial institutions have been key actors in responding to cyber risk.
The exposure of financial institutions to cyber risk has been further highlighted by organizational changes such as working from home. The shift of most activities to the digital environment creates greater opportunities for cyberattacks. If not properly managed, this could create new opportunities for gaining access to IT systems and carrying out cyberattacks and other forms of financial crime.
According to the study conducted, since the beginning of the pandemic, the financial sector has been targeted by cyberattacks more frequently than most other sectors. Therefore, two trends should be taken into account in the policymaking process. First, remote working is likely to remain at higher levels than during the pre-COVID-19 period. Consequently, business continuity plans designed for short-term disruptions may need to be adapted to accommodate working from home for longer periods, while business processes may need to be adjusted to the “new normal.”
Second, financial institutions are likely to continue moving parts of their IT operations to the cloud. A recent study shows that 82% of enterprises have increased their use of cloud services as a result of the coronavirus pandemic, while 91% plan to use them in the near future. Through the use of shared software, cloud services, and personal computers while working from home, incidents could, in principle, spread more rapidly, leading to greater losses for financial institutions and increased stress across the financial system as a whole.
Policymakers and businesses are actively working together to mitigate cyber risks and their systemic implications. For example, many public and private sector organizations are strengthening their operational resilience, and many are conducting cyberattack simulations, which help identify vulnerabilities and enhance preparedness and communication channels.
Source: BIS Bank, translated into Albanian by the Albanian Financial Supervisory Authority (AFSA), in ePeriodik, No. 141, February 2021.
