ECB concludes cyber resilience stress test (2024)

  • PRESS RELEASE

26 July 2024

  • Stress test gauged how banks would respond to and recover from severe but plausible cybersecurity incident
  • 109 banks tested, of which 28 underwent more extensive testing
  • Results to feed into ECB’s 2024 Supervisory Review and Evaluation Process

The European Central Bank (ECB) today concluded its cyber resilience stress test, which gauged how banks would respond to and recover from a severe but plausible cybersecurity incident. Overall, the stress test showed that banks have response and recovery frameworks in place, but areas for improvement remain. The results will feed into the 2024 Supervisory Review and Evaluation Process (SREP) and have helped increase banks’ awareness of the strengths and weaknesses of their cyber resilience frameworks.

The exercise was launched in January 2024 and featured a fictitious stress test scenario under which all preventive measures failed and a cyberattack severely affected the databases of each bank’s core systems. The stress test therefore focused on how banks would respond to and recover from a cyberattack, rather than on how they would prevent it.

Detecting and addressing deficiencies in supervised banks’ operational resilience frameworks, including those stemming from cyber risks, is one of the ECB’s SSM supervisory priorities for 2024-2026. This reflects the recent surge in cyber incidents that supervised banks have reported to ECB – an increase that partly stems from rising geopolitical tensions and challenges posed by the digitalisation of the banking sector.

The stress test involved 109 banks directly supervised by the ECB. All banks had to answer a questionnaire and submit documentation for the supervisors to analyse, while a sample of 28 banks was chosen to undergo more extensive testing. The latter were asked to perform an actual IT recovery test and provide evidence that it had been successful, in addition they were also visited on site by supervisors. The sample covered different business models and geographical locations to reflect the wider euro area banking system and ensure sufficient coordination with other supervisory activities.

To test their response to the scenario, banks had to show their ability to:

  • activate their crisis response plans, including internal crisis management procedures and business continuity plans;
  • communicate with all external stakeholders such as customers, service providers and law enforcement agents;
  • run an analysis to identify what services would be affected and how;
  • implement mitigation measures, including workarounds that would help the bank to operate during the time needed to fully recover IT systems.

To test their ability to recover from the scenario, banks had to show they could:

  • activate their recovery plans, including restoring backed-up data and aligning with critical third-party service providers on how to respond to the incident;
  • ensure that affected areas were recovered and up and running;
  • implement lessons learnt, for example by reviewing their response and recovery plans.

The ECB is committed to continuing to work with the banks it supervises to strengthen their cyber resilience framework. To this end, it will further encourage banks to keep working on meeting supervisory expectations by, among other things, ensuring they have in place adequate business continuity, communication and recovery plans, which should consider a wide enough range of cyber risk scenarios. Banks should also be able to meet their own recovery objectives, properly assess dependencies on critical third-party ICT service providers, and adequately estimate direct and indirect losses from a cyberattack.

The outcome of the exercise will feed into the 2024 SREP, which assesses banks’ individual risk profiles. The cyber resilience stress test is not focused on banks’ capital, so its results will not affect banks’ Pillar 2 Guidance. Supervisors have provided individual feedback to each bank and will follow up with them accordingly. In some cases, banks have already improved or plan to remedy the shortcomings pinpointed during the exercise.

For media queries, please contact Clara Martín Marqués, tel.: +49 69 1344 17919.

Notes

  • The ECB conducts supervisory stress tests on an annual basis in line with Article 100 of the Capital Requirements Directive, and every two years participates in an EU-wide stress test coordinated by the European Banking Authority. In those years where there is no EU-wide stress test, the ECB conducts a targeted stress test exercise which focuses on a specific topic of interest, such as the sensitivity analysis of interest rate risk in the banking book in 2017, the sensitivity analysis of liquidity risk in 2019, and the climate risk stress test in 2022.
  • The ECB currently directly supervises 113 banks. The 109 banks that participated in the cyber resilience stress test were those under direct ECB supervision at the time the exercise was launched, with a few exclusions for bank-specific reasons such as restructuring or change of significance status.

CONTACT

European Central Bank

Directorate General Communications

  • Sonnemannstrasse 20
  • 60314 Frankfurt am Main, Germany
  • +49 69 1344 7455
  • media@ecb.europa.eu

Reproduction is permitted provided that the source is acknowledged.

Media contacts

ECB concludes cyber resilience stress test (2024)
Top Articles
Airbnb Long Term Rentals: A Guide For Hosts And Guests - Glory of the Snow
Exploring Airbnb Long-Term Rentals: Your Comprehensive Guide for 2023
Overton Funeral Home Waterloo Iowa
Top Scorers Transfermarkt
Amtrust Bank Cd Rates
Www.metaquest/Device Code
Mileage To Walmart
Botanist Workbench Rs3
Kristine Leahy Spouse
craigslist: south coast jobs, apartments, for sale, services, community, and events
Mail Healthcare Uiowa
Big Y Digital Coupon App
Love Compatibility Test / Calculator by Horoscope | MyAstrology
Caroline Cps.powerschool.com
Sams Gas Price Fairview Heights Il
Yesteryear Autos Slang
Craigslist Pets Southern Md
Programmieren (kinder)leicht gemacht – mit Scratch! - fobizz
272482061
8664751911
R Cwbt
Zalog Forum
Hdmovie 2
Barber Gym Quantico Hours
Grimes County Busted Newspaper
Unionjobsclearinghouse
Bennington County Criminal Court Calendar
Il Speedtest Rcn Net
Milwaukee Nickname Crossword Clue
Jesus Calling Feb 13
Kqelwaob
Babydepot Registry
Kids and Adult Dinosaur Costume
Fbsm Greenville Sc
Craigslist Ludington Michigan
4083519708
Terrier Hockey Blog
Pitchfork's Top 200 of the 2010s: 50-1 (clips)
Weapons Storehouse Nyt Crossword
19 Best Seafood Restaurants in San Antonio - The Texas Tasty
Craiglist Hollywood
Invalleerkracht [Gratis] voorbeelden van sollicitatiebrieven & expert tips
Vérificateur De Billet Loto-Québec
'The Nun II' Ending Explained: Does the Immortal Valak Die This Time?
Yourcuteelena
The Great Brian Last
Lorton Transfer Station
Enjoy Piggie Pie Crossword Clue
Grand Park Baseball Tournaments
Buildapc Deals
Craigslist.raleigh
Inloggen bij AH Sam - E-Overheid
Latest Posts
Article information

Author: Jonah Leffler

Last Updated:

Views: 6326

Rating: 4.4 / 5 (45 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Jonah Leffler

Birthday: 1997-10-27

Address: 8987 Kieth Ports, Luettgenland, CT 54657-9808

Phone: +2611128251586

Job: Mining Supervisor

Hobby: Worldbuilding, Electronics, Amateur radio, Skiing, Cycling, Jogging, Taxidermy

Introduction: My name is Jonah Leffler, I am a determined, faithful, outstanding, inexpensive, cheerful, determined, smiling person who loves writing and wants to share my knowledge and understanding with you.