Why, despite the cybersecurity risks, do companies and financial institutions continue to use and adopt third-party IT services in the cloud? Katie Shanahan examines why the UK government is consulting on new cybersecurity rules for the cloud and how that will impact banks and finance firms.
From virtual desktops and customer relationship management platforms to managed security service providers and data centres, organisations increasingly rely on third parties. In particular, many firms now use the processing power of the cloud, rather than solely in-house capabilities.
Outsourcing IT seems like an easy way for organisations to tap into external expertise. It offers flexibility in resources and reduces overheads but also expands the organisation’s reliance on external parties and their cybersecurity.
Cyber security regulations
The EU’s Network and Information System Directive (NIS) of 2018 aimed to ensure the cyber resilience of critical national infrastructure. That includes water companies, energy firms, healthcare and banking, as well as digital service providers including online search engines, online market-places and some large-scale cloud providers.
When the NIS Directive was embedded into UK law, the government decided to exempt most banking and financial services firms because existing regulation already set “equivalent” standards.
Now, though, the UK government is proposing to improve the UK’s cyber-resilience further.
Banks and the cyber-risk in the cloud In March 2021, the Prudential Regulation Authority (PRA) published a supervisory statement on outsourcing and third-party risk management, effective from March 2022.
The PRA stated that “the failure of, or a prolonged significant disruption at a critical third party could have adverse consequences on the safety and soundness of multiple firms and, potentially, on financial stability”.
The PRA, Financial Conduct Authority (FCA) and Bank of England will publish a joint discussion paper on how to “designate certain third-party service providers as critical” later this year.
The paper will also cover resilience standards and resilience testing.
Banks and the cyber-risk in the cloud
In March 2021, the Prudential Regulation Authority (PRA) published a supervisory statement on outsourcing and third-party risk management, effective from March 2022.
The PRA stated that “the failure of, or a prolonged significant disruption at a critical third party could have adverse consequences on the safety and soundness of multiple firms and, potentially, on financial stability”.
The PRA, Financial Conduct Authority (FCA) and Bank of England will publish a joint discussion paper on how to “designate certain third-party service providers as critical” later this year.
The paper will also cover resilience standards and resilience testing.
How risky is outsourcing to the cloud?
How risky is outsourcing to the cloud?
In the light of ever-increasing cyberattacks, it may appear that the risks of using the cloud and managed services outweigh the benefits.
However, the biggest risk is taking a passive approach.
Organisations must:
- understand the context of the managed service provision
- set clear expectations for resilience, and
- actively manage the relationship with their service providers.
You can do this by following the Shared Responsibility Model. This involves setting out clear areas of responsibility for the customer and the service provider. The customer is always responsible for:
- information and data
- devices, and
- accounts and identities.
Applications, network controls and operating systems could be the responsibility of either the customer or the service provider – depending on what’s been agreed.
The best way for the banking and finance sector to defend itself against cyber attacks is to take a proactive approach.
Management should set minimum security baselines and hold its IT suppliers accountable. There has to be board level oversight of cyber risks, of critical IT suppliers, and of IT controls. Without that, the company won’t resource protection accordingly.
And every cloud needs a secure lining!
Related content