Global fintech and funding innovation ecosystem

Global Governance Insights on Emerging Risks

Bleu Azur Consulting | June 17, 2018

Direct and indirect costs of cyberattacks - Global Governance Insights on Emerging RisksA HEIGHTENED FOCUS ON RESPONSE AND RECOVERY

Over a third of directors of US public companies now discuss cybersecurity at every board meeting. Cyber risks are being driven onto the agenda by

  • high-profile data breaches,
  • distributed denial of services (DDoS) attacks,
  • and rising ransomware and cyber extortion attacks.

The concern about cyber risks is justified. The annual economic cost of cyber-crime is estimated at US$1.5 trillion and only about 15% of that loss is currently covered by insurance.

MMC Global Risk Center conducted research and interviews with directors from WCD to understand the scope and depth of cyber risk management discussions in the boardroom. The risk of cyberattack is a constantly evolving threat and the interviews highlighted the rising focus on resilience and recovery in boardroom cyber discussions. Approaches to cyber risks are maturing as organizations recognize them as an enterprise business risk, not just an information technology (IT) problem.

However, board focus varies significantly across industries, geographies, organization size and regulatory context. For example, business executives ranked cyberattacks among the top five risks of doing business in the Asia Pacific region but Asian organizations take 1.7 times longer than the global median to discover a breach and spend on average 47% less on information security than North American firms.

REGULATION ON THE RISE

Tightening regulatory requirements for cybersecurity and breach notification across the globe such as

  • the EU GDPR,
  • China’s new Cyber Security Law,
  • and Australia’s Privacy Amendment,

are also propelling cyber onto the board agenda. Most recently, in February 2018, the USA’s Securities and Exchange Commission (SEC) provided interpretive guidance to assist public companies in preparing disclosures about cybersecurity risks and incidents.

Regulations relating to transparency and notifications around cyber breaches drive greater discussion and awareness of cyber risks. Industries such as

  • financial services,
  • telecommunications
  • and utilities,

are subject to a large number of cyberattacks on a daily basis and have stringent regulatory requirements for cybersecurity.

See:  Bithumb $31 Million Crypto Exchange Hack: What We Know (And Don’t)

Kris Manos, Director, KeyCorp, Columbia Forest Products, and Dexter Apache Holdings, observed, “The manufacturing sector is less advanced in addressing cyber threats; the NotPetya and WannaCry attacks flagged that sector’s vulnerability and has led to a greater focus in the boardroom.” For example, the virus forced a transportation company to shut down all of its communications with customers and also within the company. It took several weeks before business was back to normal, and the loss of business was estimated to have been as high as US$300 million. Overall, it is estimated that as a result of supply chain disruptions, consumer goods manufacturers, transport and logistics companies, pharmaceutical firms and utilities reportedly suffered, in aggregate, over US$1 billion in economic losses from the NotPetya attacks. Also, as Cristina Finocchi Mahne, Director, Inwit, Italiaonline, Banco Desio, Natuzzi and Trevi Group, noted, “The focus on cyber can vary across industries depending also on their perception of their own clients’ concerns regarding privacy and data breaches.”

LESSONS LEARNED: UPDATE RESPONSE PLANS AND EVALUATE THIRD-PARTY RISK

The high-profile cyberattacks in 2017, along with new and evolving ransomware onslaughts, were learning events for many organizations. Lessons included the need to establish relationships with organizations that can assist in the event of a cyberattack, such as l

  • aw enforcement,
  • regulatory agencies and recovery service providers
  • including forensic accountants and crisis management firms.

Many boards need to increase their focus on their organization’s cyber incident response plans. A recent global survey found that only 30% of companies have a cyber response plan and a survey by the National Association of Corporate Directors (NACD) suggests that only 60% of boards have reviewed their breach response plan over the past 12 months. Kris Manos noted, “[If an attack occurs,] it’s important to be able to quickly access a response plan. This also helps demonstrate that the organization was prepared to respond effectively.”

Experienced directors emphasized the need for effective response plans alongside robust cyber risk mitigation programs to ensure resilience, as well as operational and reputation recovery. As Jan Babiak, Director, Walgreens Boots Alliance, Euromoney Institutional Investor, and Bank of Montreal, stressed, “The importance of the ’respond and recover’ phase cannot be overstated, and this focus needs to rapidly improve.”

Directors need to review how the organization will communicate and report breaches. Response plans should include preliminary drafts of communications to all stakeholders including customers, suppliers, regulators, employees, the board, shareholders, and even the general public. The plan should also consider legal requirements around timelines to report breaches so the organization is not hit with financial penalties that can add to an already expensive and reputationally damaging situation. Finally, the response plan also needs to consider that normal methods of communication (websites, email, etc.) may be casualties of the breach. A cyber response plan housed only on the corporate network may be of little use in a ransomware attack.

Other lessons included the need to focus on cyber risks posed by third-party suppliers, vendors and other impacts throughout the supply chain. Shirley Daniel, Director, American Savings Bank, and Pacific Asian Management Institute, noted, “Such events highlight vulnerability beyond your organization’s control and are raising the focus on IT security throughout the supply chain.” Survey data suggests that about a third of organizations do not assess the cyber risk of vendors and suppliers. This is a critical area of focus as third-party service providers (e.g., software providers, cloud services providers, etc.) are increasingly embedded in value chains.

More:  The growing cost of cybersecurity

FRUSTRATIONS WITH OVERSIGHT

Most directors expressed frustrations and challenges with cyber risk oversight even though the topic is frequently on meeting agendas. Part of the challenge is that director-level cyber experts are thin on the ground; most boards have only one individual serving as the “tech” or “cyber” person. A Spencer Stuart survey found that 41% of respondents said their board had at least one director with cyber expertise, with an additional 7% who are in the process of recruiting one. Boards would benefit from the addition of experienced individuals who can identify the connections between cybersecurity and overall company strategy.

A crucial additional challenge is obtaining clarity on the organization’s overall cyber risk management framework. (See Exhibit 1: Boards Need More Information on Cyber Investments.) Olga Botero, Director, Evertec, Inc., and Founding Partner, C&S Customers and Strategy, observed, “There are still many questions unanswered for boards, including:

  • How good is our security program?
  • How do we compare to peers?

There is a big lack of benchmarking on practices.” Anastassia Lauterbach, Director, Dun & Bradstreet, and member of Evolution Partners Advisory Board, summarized it well, “Boards need a set of KPIs for cybersecurity highlighting their company’s

  • unique business model,
  • legacy IT,
  • supplier and partner relationships,
  • and geographical scope.”

Nearly a quarter of boards are dissatisfied with the quality of management-provided information related to cybersecurity because of insufficient transparency, inability to benchmark and difficulty of interpretation.

EFFECTIVE OVERSIGHT IS BUILT ON A COMPREHENSIVE CYBER RISK MANAGEMENT FRAMEWORK

Organizations are maturing from a “harden the shell” approach to a protocol based on understanding and protecting core assets and optimizing resources. This includes the application of risk disciplines to assess and manage risk, including quantification and analytics. (See Exhibit 2: Focus Areas of a Comprehensive Cyber Risk Management Framework.) Quantification shifts the conversation from a technical discussion about threat vectors and system vulnerabilities to one focused on maximizing the return on an organization’s cyber spending and lowering its total cost of risk.

Cyber risk management process - Global Governance Insights on Emerging Risks

See:  FSB warns of third-party FinTech risk

Directors also emphasized the need to embed the process in an overall cyber risk management framework and culture. “The culture must emphasize openness and learning from mistakes. Culture and cyber risk oversight go hand in hand,” said Anastassia Lauterbach. Employees should be encouraged to flag and highlight potential cyber incidents, such as phishing attacks, as every employee plays a vital role in cyber risk management. Jan Babiak noted, “If every person in the organization doesn’t view themselves as a human firewall, you have a soft underbelly.” Mary Beth Vitale, Director, GEHA and CoBiz Financial, Inc., also noted, “Much of cyber risk mitigation is related to good housekeeping such as timely patching of servers and ongoing employee training and alertness.”

Boards also need to be alert. “Our board undertakes the same cybersecurity training as employees,” noted Wendy Webb, Director, ABM Industries. Other boards are putting cyber updates and visits to security centers on board “offsite” agendas.

Continue to the full article --> here

 

Click for News:

latest news - Global Governance Insights on Emerging Risks

 

AI | Oct 2, 2023 Microsoft has recently made waves in the tech industry with its announcement of the Copilot Copyright Commitment. Microsoft's Copilot Commitment Shields AI Users from Copyright Concerns. Problem: While Microsoft's AI-powered Copilots have been transformative, enhancing efficiency and unlocking new levels of creativity they've raised questions about the risk of IP infringement claims when using the output produced by generative AI. Solution: To address these concerns, Microsoft has introduced its new Copilot Copyright Commitment. This commitment ensures that customers can use Microsoft’s Copilot services and their generated output without fearing copyright claims. If a customer faces a copyright challenge, Microsoft will assume responsibility for the potential legal risks involved. This commitment extends Microsoft's existing intellectual property indemnity support to commercial Copilot services. If a third party sues a commercial customer for copyright infringement for using Microsoft’s Copilots or the output they generate, Microsoft will defend the customer and cover any adverse judgments or settlements, provided the customer used the guardrails and content filters integrated into Microsoft’s products. See:  How do intellectual property rights apply to AI? This move by Microsoft comes after a recent federal court ruling that stated artwork created by AI cannot be copyrighted ...
Unsplash Oscar Sutton Copilot - Global Governance Insights on Emerging Risks
AI | Oct 2, 2023 Federal Minister François-Philippe Champagne launches voluntary code of conduct for advanced generative AI systems but some are wondering if this a step forward will hinder innovation? On September 27, Minister Champagne announced Canada's Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems, effective immediately.  The new code of conduct revolves around several key principles around transparency, bias, oversight and detectability. AI systems must be clear about where and how the information they collect is used. There should be methods in place to tackle potential biases within the system. Human monitoring of AI systems is essential. Developers creating generative AI for public use must ensure that any content produced by their system can be identified. Minister Champagne emphasized the urgency of implementing measures to foster trust in AI products. I think that if you ask people in the street, they want us to take action now to make sure that we have specific measures that companies can take now to build trust in their AI products. Mixed Reactions While there's been significant support from major players in the business sector, concerns have also been raised. Some fear that the code, ...
Unsplash Mojahid Mottakin Chatgpt - Global Governance Insights on Emerging Risks
Oct 2, 2023 In the era of digital gold, where cryptocurrencies reign supreme, the allure of Bitcoin has captivated both seasoned investors and newcomers alike. Suppose you're looking to grow your money. In that case, dipping your toes into the cryptocurrency world is exciting and potentially rewarding. This article will demystify the art of Bitcoin investment and show you how to start investing 100 dollars. The Bitcoin Phenomenon: A Brief Overview Before we dive into the nitty-gritty of Bitcoin investment, let's take a moment to understand why Bitcoin has become the poster child of the cryptocurrency revolution. Bitcoin, often called "digital gold," was created in 2009 by an anonymous individual or group of individuals using the pseudonym Satoshi Nakamoto. It's a decentralized digital currency that operates on blockchain, which ensures transparency, security, and immutability of transactions. The appeal of Bitcoin lies in its scarcity; only 21 million coins will ever be mined, making it a deflationary asset. As a result, Bitcoin has garnered immense attention and investment interest over the years, skyrocketing from mere cents to thousands of dollars per coin. Why Should You Invest in Bitcoin? Diversification: Diversifying your investment portfolio is a fundamental strategy to mitigate risks. As ...
Unsplash Michael Fortsch Bitcoin - Global Governance Insights on Emerging Risks
Funding | Sep 29, 2023 ZayZoon, a prominent Earned Wage Access scale-up for small and mid-sized businesses, and founded in Calgary, recently announced that they raised $34.5 million in debt and equity during its Series B financing round. Investors include Framework Venture Partners who led this round, with notable co-investment from Export Development Canada (EDC) and participation from ATB Financial and existing shareholders. ZayZoon is a financial empowerment platform specifically designed for small and mid-sized businesses. The company's primary mission is to provide employees with the ability to access their earned wages before the traditional payday, a service known as Earned Wage Access (EWA). This innovative approach aims to alleviate financial stress and break the paycheck-to-paycheck cycle that many individuals face. Catering to the varied needs of its users, ZayZoon offers multiple payout options, including bank deposits, debit cards, and fee-free alternatives like Instant Gift Cards and Gas Cards See:  Redefining Payday: Earned Wage Access (EWA) Insights from Harvard Study ZayZoon emphasizes seamless integration with existing payroll and HR infrastructures. In 2023, the company was notably recognized as an ADP and PrismHR Marketplace Partner of the Year. Their trajectory is nothing short of remarkable, boasting a 400% increase in payouts ...
Unsplash Fabian Blank Earned wages - Global Governance Insights on Emerging Risks
Capital | Sep 29, 2023 This week hails the launch of Capital Compass BC, a dynamic and collaborative platform by Innovate BC, InBC Investment Corp., PacifiCan, and New Ventures BC, designed to bolster and connect BC's thriving entrepreneurial ecosystem. British Columbia (B.C.) is a hub of innovation, with entrepreneurs and companies propelling it as a leading innovation center in North America. Capital Compass BC is not just a boon for businesses but also for investors, innovators, and ecosystem enablers. It's publicly accessible, free-to-use, and allows individuals to submit relevant information, making it searchable within the platform. Key Features of Capital Compass BC: Comprehensive Database: The platform provides detailed insights into startups, scaleups, investors, entrepreneurial resources, and the flow of investment capital within BC.  There are currently 538 fintech startups and scale-ups based in BC listed on the platform. Advanced Filtering: Users can explore the vast database using filters like sector, company stage, funding round, and other pivotal characteristics. This facilitates the identification of trends, opportunities, and gaps in the regional innovation ecosystem. Support for Companies: Beyond just being a data repository, Capital Compass BC aids companies in navigating funding sources and amplifying their visibility in the market. Investor's Paradise: Investors ...
Capital Compass BC - Global Governance Insights on Emerging Risks
Sep 29, 2023 Funding Transfers Via PayID From Australia Gambling for real money is not complete without a reliable payment system. This is a guarantee that fraudsters won’t get your cash. And it will not magically disappear. Therefore, the transfer method choice is on par with the search for a casino. Security comes first, so let's take a look at how the system creators provide it. First of all, we'd like to point out that only your bank can see the personal data required to receive the code. The online casino does not see them. In addition, PayID uses SSL protection. Advantages And Disadvantages We highlight such pros: Speed. Online casino transfers are instant, so you can start betting right away. Withdrawals depend on the gambling platform due to additional checks. Security. Everything is as safe as transferring directly to a bank account, just more anonymous. You only need a code. Simplicity. Remembering a combination or just a login is easier than looking for a piece of paper with your account number every time. You can connect to the system in just a few clicks. Communication. PayID transfers allow short descriptions of up to 280 characters. You can specify the ...
Unsplash mobile payment 1 - Global Governance Insights on Emerging Risks
BoC | Sep 28, 2023 The Bank of Canada has extended an invitation to members of the Retail Payment Advisory Committee (RPAC) and the broader payment service provider (PSP) community to share feedback on its supervisory approach to transaction reporting. The Bank is keen on understanding the current practices of payment service providers (PSPs) and aims to develop an effective strategy for transaction reporting. This initiative is not limited to RPAC members alone; the Bank is actively seeking diverse opinions from the entire PSP industry. See:  Citi’s Top 10 Insights on Cross-Border Payments 2023 By sharing your feedback, you will help the Bank gain insights into the current practices of PSPs and also contribute to the development of a robust transaction reporting approach. Survey The Bank has launched a survey to better understand the information needs of PSPs. This will aid PSPs in understanding the Bank's expectations and preparing for upcoming retail payment supervision. The results of this survey will shape the Bank's communication strategy, ensuring PSPs are well-informed and ready to comply with forthcoming legislation.  The survey is entirely voluntary, and the Bank guarantees that no personally identifiable information will be collected or shared. You can complete the survey ...
Wikicommons media Bank of Canada - Global Governance Insights on Emerging Risks
Crypto Regulation | Sep 28, 2023 EU's MiCA framework sets a new standard in crypto regulation, as the UK and US navigate their unique challenges and the global community calls for coordinated oversight. The European Union, with its groundbreaking MiCA framework has set a precedent. Meanwhile, the UK and the US are carving their unique paths. Drawing insights from a recent EU report, this article provides an update of the regulatory landscape across these jurisdictions, highlighting the challenges, opportunities, and global implications of their respective approaches to crypto-assets and stablecoins. EU's Regulatory Approach to Crypto-Assets In 2023, the European Union introduced the innovative Markets in Crypto-assets (MiCA) framework, a comprehensive regulatory measure designed to oversee the burgeoning crypto-asset markets. The primary focus of MiCA is on stablecoins, ensuring that their value remains consistent with official currencies. This framework combines stringent transparency and governance measures with prudential rules similar to those applied to traditional financial institutions. The overarching aim of MiCA is to ensure better protection for citizens, maintain financial stability, and foster both innovation and financial inclusion in the crypto space. UK and US The United Kingdom has charted its own path in the crypto realm. With comprehensive crypto legislation ...
Unsplash Charles Forerunner - Global Governance Insights on Emerging Risks
Sep 28, 2023 Fintech is an ever-evolving world where every click counts and every lead may be game-changing; therefore mastering SEO has become essential. Welcome to Fintech SEO where competing for top search engine results pages (SERPs) rankings doesn't simply translate to visibility but rather leads to sales conversion. In this article, we'll uncover its immense power, discuss why high SERP rankings lead to conversions and traverse organic traffic that fuels fintech success. SERP Rankings in Fintech Imagine this: you need financial advice or are searching for investment options, where would you go? Chances are you would consult your search engine; the websites appearing at the top of those search results have built trust among both their users and search engines alike. ➡️ High Rankings Are an Indication of Trustworthiness Achieving high rankings on SERPs for your fintech website is like earning a gold star of trustworthiness from users; they know Google or Bing have already approved and reviewed your services - often leading to them opting for them over those offered by your competitors. When you enlist the expertise of a fintech SEO agency such as Sure Oak, you're essentially enlisting professionals who specialize in elevating your trustworthiness on ...
Unsplash John Schnobrich SEO - Global Governance Insights on Emerging Risks
Cyber Security | Sep 27, 2023 The cyber landscape in 2023 has witnessed a significant surge in ransomware attacks, with small businesses becoming the primary targets. According to a report from Infosecurity Magazine, ransomware attackers are increasingly targeting smaller, less defended organizations. There was a 47% increase in new victims in the latter half of 2022, with many of these being small businesses with less mature cyber postures. Specifically, 57% of the victims of the LockBit gang, known for high-profile attacks on the Royal Mail and Taiwan Semiconductor Manufacturing Company (TSMC), were small businesses. Many of these groups are moving away from traditional encryption-based attacks. Instead, they threaten to expose and publicize sensitive information, shifting from ransomware to pure extortion tactics. See:  Small Businesses Incur Greatest Loss of Cyber Attacks | 67% Suffer Repeat Attacks Within 12 Months Ransomware by the Numbers In the first half of 2023, there was a 45.27% global increase in ransomware victim organizations, totaling 2,001. During the same period, the sectors most targeted by ransomware were banking, retail, and transportation. LockBit, a dominant ransomware since 2022, primarily targeted IT, finance, and professional services. Nearly 50% of all ransomware victims were US-based organizations, a significant increase ...
Wikimedia Commons BlueBreezeWiki Ransomware - Global Governance Insights on Emerging Risks

 


NCFA Jan 2018 resize - Global Governance Insights on Emerging RisksThe National Crowdfunding & Fintech Association of Canada (NCFA Canada) is a cross-Canada non-profit actively engaged with cryptocurrency, blockchain, crowdfunding, alternative finance, fintech, P2P, ICO, STO, and online investing stakeholders globally. NCFA Canada provides education, research, industry stewardship, services, and networking opportunities to thousands of members and subscribers and works closely with industry, government, academia, community and eco-system partners and affiliates to create a strong and vibrant crowdfunding and fintech industry. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: ncfacanada.org

Leave a Reply

Your email address will not be published. Required fields are marked *

three × 4 =