Advertisement
UK markets closed
  • FTSE 100

    8,433.76
    +52.41 (+0.63%)
     
  • FTSE 250

    20,645.38
    +114.08 (+0.56%)
     
  • AIM

    789.87
    +6.17 (+0.79%)
     
  • GBP/EUR

    1.1622
    +0.0011 (+0.09%)
     
  • GBP/USD

    1.2525
    +0.0001 (+0.01%)
     
  • Bitcoin GBP

    48,572.35
    -2,000.68 (-3.96%)
     
  • CMC Crypto 200

    1,256.40
    -101.60 (-7.48%)
     
  • S&P 500

    5,222.68
    +8.60 (+0.16%)
     
  • DOW

    39,512.84
    +125.08 (+0.32%)
     
  • CRUDE OIL

    78.20
    -1.06 (-1.34%)
     
  • GOLD FUTURES

    2,366.90
    +26.60 (+1.14%)
     
  • NIKKEI 225

    38,229.11
    +155.13 (+0.41%)
     
  • HANG SENG

    18,963.68
    +425.87 (+2.30%)
     
  • DAX

    18,772.85
    +86.25 (+0.46%)
     
  • CAC 40

    8,219.14
    +31.49 (+0.38%)
     

REUTERS SUMMIT-UK banks might become test bed in fight against cyber attacks

(For other news from Reuters Financial Regulation Summit, click on http://www.reuters.com/summit/FINANCIALREGULATION17)

By Huw Jones, Andrew MacAskill and Rachel Armstrong

LONDON, Sept 26 (Reuters) - Britain's banks may have to comply with the world's first set of rules for coping with cyber attacks and other outages, Bank of England Deputy Governor Sam Woods said on Tuesday.

The theft of 2.5 million pounds from 9,000 customers of Tesco Bank last November rang alarm bells for regulators and put cyber security high up on their priority list.

Woods said a landmark case like that of Tesco Bank, where money was actually stolen from customers accounts, it is important to ensure the bank has enough capital to safeguard customers - but this was not enough.

ADVERTISEMENT

While UK banks like HSBC, Barclays (LSE: BARC.L - news) , Lloyds and RBS (LSE: RBS.L - news) have had to undergo specific cyber resilience tests set by the BoE (Shenzhen: 000725.SZ - news) , Woods thinks that more needs to be done as the number of serious cyber attacks on financial firms rises.

The regulators' "emergency" response system has been triggered six times in the past 12 months alone, Woods told the Reuters Financial Regulation Summit.

New (KOSDAQ: 160550.KQ - news) , so-called "operational resilience" rules would spell out what systems at a firm underpin critical services, and the "tolerance" level for an outage before regulatory intervention.

"We need to ask ourselves, because no IT system is absolutely perfect, what is the degree of outage that is acceptable," Woods said.

He foresees three levels of "tolerance", the lowest for activities regulated by the Financial Conduct Authority, whose core aim is to protect consumers.

A second layer would be monitored by the BoE's Prudential (Amsterdam: PD8.AS - news) Regulation Authority, which Woods heads, and looks at whether the solvency of the firm being hacked remained robust enough.

A third layer would be set by the BoE's Financial Policy Committee, which monitors threats to wider financial stability.

"At the moment nowhere in the world has anyone articulated a view on that stuff, and we are going to attempt to do so," Woods said.

"It is extremely challenging, but I think we need to build that or we don’t have a solid basis to deal with this stuff."

Woods expects the issue to be discussed at the FPC and PRA by the end of this year or early in 2018, depending on how the initial thinking develops.

"The reason I am cautious is because this is really an entirely new field of work. It is a greenfield site in regulatory terms," Woods said.

"So as we go through it, I think it is possible we have to have several runs at it to get it right because we don’t want to agree something, impose something and then decide that it was really down the wrong track."

Reuters Summits on Twitter (Swiss: TWTR-USD.SW - news) @Reuters_Summits

(For more summit stories, see)

(Reporting by Huw Jones. Editing by Jane Merriman)