In its recently released April 2024 Global Financial Stability Report, ‘Cyber Risk: A Growing Concern for Macrofinancial Stability’ the IMF has warned of the growing risk of systemic consequences linked to a cyber attack.
The financial sector is highly exposed to cyber risks, with nearly one-fifth of all incidents affecting financial firms says the report and “although cyber incidents have thus far not been systemic, severe incidents at major financial institutions could pose an acute threat to macrofinancial stability through a loss of confidence, the disruption of critical services, and because of technological and financial interconnectedness.”
To attempt to reduce the risk the IMF makes a number of policy recommendations, including (verbatim):
- Cyber resilience of the financial sector should be strengthened by developing an adequate national cybersecurity strategy, appropriate regulatory and supervisory frameworks, a capable cybersecurity workforce, and domestic and international information-sharing arrangements.
- Reporting of cyber incidents by financial firms to supervisory agencies should be strengthened to allow for more effective monitoring of cyber risks.
- Supervisors should hold board members responsible for managing the cybersecurity of financial firms and promoting a conducive risk culture, cyber hygiene, and cyber training and awareness.
- Financial firms should develop and test response and recovery procedures to remain operational in the face of cyber incidents. National authorities should also develop effective response protocols and crisis management frameworks to deal with systemic cyber crises.






