SlideShare une entreprise Scribd logo
1  sur  36
Cyber Risk
Monitoring
for Chief Risk Officers
Decisions made in Mizuho’s Boardroom by 25 CROs & CISOs about how
to drive Operational Resilience in 2020 through better 3rd Party Risk Management
We brought together 25 CROs and CISOs
2
To debate how to monitor cyber risk at suppliers in 2020
Bank of China Bank of England PRA
FSCS ILAG Raphaels Bank
Deutsche Bank JP Morgan Reassure
Brit Bus. Bank LendInvest Rothesay Life
Citibank Facebook Rothschild Bank
CAF Bank Oak North Shawbrook Bank
Bottomline Pay.UK Turkey Bank
Met Friendly QBE Insurance Westpac Group
Leaders from these firms debated their plans for 2020, in anticipation
of the PRA consultation on Outsourcing & 3rd Party Risk Management.
We held a Structured Debate via a Simulation
3
Our 25 CROs & CISOs were appointed to a hypothetical organisation
Congratulations!
You’re now in charge of monitoring cyber risk across the
extended enterprise at “ACME Financial”
Decisions to be made by 25 CROs and CISOs
4
Our 25 experts broke into 5 groups to address these 4 questions
1) WHAT to call their project, to monitor & mitigate cyber risk
across their Outsourcing & 3rd Party suppliers during 2020
2) WHO to include in the project team that will monitor cyber risk (job titles)
3) WHEN to achieve key milestones (SMART objectives) in the project
4) HOW to report the live cyber risk today, on each supplier
For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
Sample suppliers used for the Simulation
5
Our CROs and CISOs pretended that these 10 companies supply ACME Financial
Adecco Concur Dentons G4S Gemalto
Recruitment Expense Management Legal Security Information Services
Metsi Pega Skanska Sungard Workday
IT Services Customer Relationship Management Construction Business Continuity ERP
Expert Insight 1: WHAT to call your Project
6
“To measure, monitor & mitigate 3rd party risk in 2020”
VENDOR
Outsourcing & 3rd Party Risk Management
7
Context: draft Supervisory Statement published on 5th December 2019
For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
“Banks should
gradually build an
Outsourcing
Register which
should be complete
by 31 Dec 2021.”
“Online, real-time
reporting tools are
strongly
encouraged.”
Outsourcing & 3rd Party Risk Management
7
Context: draft Supervisory Statement published on 5th December 2019
For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
“Banks should
gradually build an
Outsourcing
Register which
should be complete
by 31 Dec 2021.”
“Online, real-time
reporting tools are
strongly
encouraged.”
8
Expert Insight 2: WHO is in your team?
“To measure, monitor & mitigate 3rd party risk in 2020”
Our experts debated WHO should be in their team to measure,
monitor & mitigate cyber risk across their 3rd Parties.
9
Expert Insight 2: WHO is in your team?
“To measure, monitor & mitigate 3rd party risk in 2020”
10
Expert Insight 2: WHO is in your team?
“To measure, monitor & mitigate 3rd party risk in 2020”
CEO COO
3rd Party Oversight
Provider
Chair Risk Committee Product Commercial
CFO CRO
Compliance /
Financial Crime
Operational Resilience Contracts Procurement
CIO CTO Business + Operations Operational Risk DPO
Supplier
Relationship
CISO Auditor Communications Business Continuity Legal Project Manager
11
Expert Insight 2: WHO is in your team?
“To measure, monitor & mitigate 3rd party risk in 2020”
CEO COO
3rd Party Oversight
Provider
Chair Risk Committee Product Commercial
CFO CRO
Compliance /
Financial Crime
Operational Resilience Contracts Procurement
CIO CTO Business + Operations Operational Risk DPO
Supplier
Relationship
CISO Auditor Communications Business Continuity Legal Project Manager
Delegates named 24 JOB TITLES they wanted in their Project Team for 2020.
But some titles received just 1-2 votes, eg “CEO” nominated only by Caleidoscope,
“CFO” was nominated only by ScreamCastle.
12
Expert Insight 2: WHO is in your team?
“To measure, monitor & mitigate 3rd party risk in 2020”
Delegates named 24 JOB TITLES they wanted in their Project Team for 2020.
But some titles received just 1-2 votes, eg “CEO” nominated only by Caleidoscope,
“CFO” was nominated only by ScreamCastle.
11 people should be in your team, said Caleidoscope, See2020 & ScreamCastle.
Project Tango suggested 12 individuals, while Hawkeye said 8 individuals.
The 11 job titles that most experts thought should be in the Project Team were:
CRO; COO; CISO; CTO; DPO; Legal; Procurement/Contracts; Project Manager.
Operational Resilience; 3rd Party Oversight Provider; Communications.
13
Expert Insight 2: WHO is in your team?
“To measure, monitor & mitigate 3rd party risk in 2020”
The 11 job titles that most experts thought should be in the Project Team were:
CRO; COO; CISO; CTO; DPO; Legal; Procurement/Contracts; Project Manager.
Operational Resilience; 3rd Party Oversight Provider; Communications.
One team grouped their project
members into a hierarchy,
with reports pushed up to the
C-Level from project managers
In operational resilience.
14
Expert Insight 2: WHO is in your team?
“To measure & mitigate cyber risk across 3rd parties”
We are honoured to be the “3rd Party Oversight Provider” to some of you already.
We recommend: have 1 person in your 2nd line “own” your Cyber Risk Dashboard, with
monthly exception reports to C-Level. Then let suppliers view themselves on Dashboard.
Decisions to be made by 25 CROs and CISOs
15
Our 25 experts broke into 5 groups to address these 4 questions
1) WHAT to call their project, to monitor & mitigate cyber risk
across their Outsourcing & 3rd Party suppliers during 2020
2) WHO to include in the project team that will monitor cyber risk (job titles)
3) WHEN to achieve key milestones (SMART objectives) in the project
4) HOW to report the live cyber risk today, on each supplier
For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
3: WHEN to achieve key milestones
“To monitor & mitigate cyber risk across suppliers in 2020”
Our experts debated WHEN to achieve key milestones to
measure, monitor & mitigate cyber risk across their 3rd parties,
by setting SMART objectives.
16
17
3: WHEN to achieve key milestones
“To monitor & mitigate cyber risk across suppliers in 2020”
• Specific Goal is to Understand +
Improve Critical 3rd Party Risk
• Measured inline with Risk Appetite,
with MI, Audits, Scorecard, TI
• Achieved through monthly reviews of
risk-based priorities
• Relevant Scorecard reported to Exco
on suppliers outside risk appetite
• Timed to achieve goal in 12 months
18
3: WHEN to achieve key milestones
“To monitor & mitigate cyber risk across suppliers in 2020”
Q1:
• Define Appetite
• Identify & Prioritise key suppliers
(risk based)
Q2:
• Assess Cyber Resilience of Key
Suppliers
• Manage / Remediate
• Ongoing Monitoring & Reporting
19
3: WHEN to achieve key milestones
“To monitor & mitigate cyber risk across suppliers in 2020”
Q1:
• Define Appetite
• Identify & Prioritise key suppliers
(risk based)
Q2:
• Assess Cyber Resilience of Key
Suppliers
• Manage / Remediate
• Ongoing Monitoring & Reporting
20
3: WHEN to achieve key milestones
“To monitor & mitigate cyber risk across suppliers in 2020”
For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
21
3: WHEN to achieve key milestones
“To monitor & mitigate cyber risk across suppliers in 2020”
For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
Concur
Metsi
Skanska
WorkDay
Gemalto
Dentons
Adecco
Decisions to be made by 25 CROs and CISOs
22
Our 25 experts broke into 5 groups to address these 4 questions
1) WHAT to call their project, to monitor & mitigate cyber risk
across their Outsourcing & 3rd Party suppliers during 2020
2) WHO to include in the project team that will monitor cyber risk (job titles)
3) WHEN to achieve key milestones (SMART objectives) in the project
4) HOW to report the live cyber risk today, on each 3rd Party and supplier
For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
23
4: HOW to report live risk by Supplier?
“To monitor & mitigate cyber risk across suppliers in 2020”
23For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
24
4: HOW to report live risk by Supplier?
“To monitor & mitigate cyber risk across suppliers in 2020”
25
3: WHEN to achieve key milestones
“To monitor & mitigate cyber risk across suppliers in 2020”
For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
26
3: WHEN to achieve key milestones
“To monitor & mitigate cyber risk across suppliers in 2020”
For your cyber dashboard, email Lewis.Varga@CyberRescue.co.ukFor your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
27
3: WHEN to achieve key milestones
“To monitor & mitigate cyber risk across suppliers in 2020”
For your cyber dashboard, email Lewis.Varga@CyberRescue.co.ukFor your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
28
3: WHEN to achieve key milestones
“To monitor & mitigate cyber risk across suppliers in 2020”
For your cyber dashboard, email Lewis.Varga@CyberRescue.co.ukFor your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
29
3: WHEN to achieve key milestones
“To monitor & mitigate cyber risk across suppliers in 2020”
For your cyber dashboard, email Lewis.Varga@CyberRescue.co.ukFor your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
30
3: WHEN to achieve key milestones
“To monitor & mitigate cyber risk across suppliers in 2020”
For your cyber dashboard, email Lewis.Varga@CyberRescue.co.ukFor your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
Continuous Monitoring of our key suppliers
Barrie Millett, Group Head of Operational Resilience, Wesleyan Group
31For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
Bank of England - CQUEST
Continuous Monitoring of our key suppliers
Barrie Millett, Group Head of Operational Resilience, Wesleyan Group
32For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
Decisions to be made by 25 CROs and CISOs
33
Our 25 experts broke into 5 groups to address these 4 questions
1) WHAT to call their project, to monitor & mitigate cyber risk
across their Outsourcing & 3rd Party suppliers during 2020
2) WHO to include in the project team that will monitor cyber risk (job titles)
3) WHEN to achieve key milestones (SMART objectives) in the project
4) HOW to report the live cyber risk today, on each supplier
For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
And the Winning Team is… Hawkeye!
“To measure, monitor & mitigate 3rd party risk in 2020”
Turn your Insights into Action
35
Kevin.Duffey@CyberRescue.co.uk
Hold the date: 21st Jan at 2pm:
Managing Cyber Risk at 3rd Parties by
Implementing the PRA’s draft Supervisory Statement
expectations on Outsourcing Registers, with “Online, real-time
reporting tools” that are “strongly preferred”
Turn your Insights into Action
36
Kevin.Duffey@CyberRescue.co.uk
For more insights like this, go to:
www.linkedin.com/company/cyber-rescue-alliance/
For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk

Contenu connexe

Tendances

Deloitte stay ahed of the game
Deloitte stay ahed of the gameDeloitte stay ahed of the game
Deloitte stay ahed of the game
Franco Ferrario
 
Cyber security basics for law firms
Cyber security basics for law firmsCyber security basics for law firms
Cyber security basics for law firms
Robert Westmacott
 

Tendances (20)

Cybersecurity 2020: Your Biggest Threats and How You Can Prevent Them
Cybersecurity 2020: Your Biggest Threats and How You Can Prevent Them Cybersecurity 2020: Your Biggest Threats and How You Can Prevent Them
Cybersecurity 2020: Your Biggest Threats and How You Can Prevent Them
 
Latin america cyber security market,symantec market share internet security,m...
Latin america cyber security market,symantec market share internet security,m...Latin america cyber security market,symantec market share internet security,m...
Latin america cyber security market,symantec market share internet security,m...
 
RSA大会2009-2010分析
RSA大会2009-2010分析RSA大会2009-2010分析
RSA大会2009-2010分析
 
The Proactive Approach to Cyber Security
The Proactive Approach to Cyber SecurityThe Proactive Approach to Cyber Security
The Proactive Approach to Cyber Security
 
Deloitte stay ahed of the game
Deloitte stay ahed of the gameDeloitte stay ahed of the game
Deloitte stay ahed of the game
 
Improving cyber-security through acquisition
Improving cyber-security through acquisitionImproving cyber-security through acquisition
Improving cyber-security through acquisition
 
Challenges and Risks for the CIO from Outsourcing in the digital era
Challenges and Risks for the CIO from Outsourcing in the digital eraChallenges and Risks for the CIO from Outsourcing in the digital era
Challenges and Risks for the CIO from Outsourcing in the digital era
 
In the news
In the newsIn the news
In the news
 
Enterprise Blockchain Development Services | Blockchain Developments
Enterprise Blockchain Development Services | Blockchain DevelopmentsEnterprise Blockchain Development Services | Blockchain Developments
Enterprise Blockchain Development Services | Blockchain Developments
 
The Digital Landscape
The Digital LandscapeThe Digital Landscape
The Digital Landscape
 
Security Breach: It's not if, it's not when, it's will you know
Security Breach: It's not if, it's not when, it's will you knowSecurity Breach: It's not if, it's not when, it's will you know
Security Breach: It's not if, it's not when, it's will you know
 
Who is the next target proactive approaches to data security
Who is the next target   proactive approaches to data securityWho is the next target   proactive approaches to data security
Who is the next target proactive approaches to data security
 
Innovate for Cyber Resilience
Innovate for Cyber ResilienceInnovate for Cyber Resilience
Innovate for Cyber Resilience
 
Digital Energy 2018 Day 2
Digital Energy 2018 Day 2Digital Energy 2018 Day 2
Digital Energy 2018 Day 2
 
Cyber Risk for Construction Industry
Cyber Risk for Construction Industry Cyber Risk for Construction Industry
Cyber Risk for Construction Industry
 
ScotSecure 2020
ScotSecure 2020ScotSecure 2020
ScotSecure 2020
 
Scalar security study2017_slideshare_rev[1]
Scalar security study2017_slideshare_rev[1]Scalar security study2017_slideshare_rev[1]
Scalar security study2017_slideshare_rev[1]
 
Cyber security basics for law firms
Cyber security basics for law firmsCyber security basics for law firms
Cyber security basics for law firms
 
McAfee Labs 2017 Threats Predictions
McAfee Labs 2017 Threats PredictionsMcAfee Labs 2017 Threats Predictions
McAfee Labs 2017 Threats Predictions
 
6º Resseguro - A Evolução do Risco Cibernético e seu Impacto no Seguro - Kara...
6º Resseguro - A Evolução do Risco Cibernético e seu Impacto no Seguro - Kara...6º Resseguro - A Evolução do Risco Cibernético e seu Impacto no Seguro - Kara...
6º Resseguro - A Evolução do Risco Cibernético e seu Impacto no Seguro - Kara...
 

Similaire à Cyber Risk Measurement: what 25 CISOs & CROs plan for 2020

Adaptive & Unified Approach to Risk Management & Compliance-via-ccf
Adaptive & Unified Approach to Risk Management & Compliance-via-ccfAdaptive & Unified Approach to Risk Management & Compliance-via-ccf
Adaptive & Unified Approach to Risk Management & Compliance-via-ccf
awish11
 
CTEK-Investor-Presentation-May-2021-1.pptx
CTEK-Investor-Presentation-May-2021-1.pptxCTEK-Investor-Presentation-May-2021-1.pptx
CTEK-Investor-Presentation-May-2021-1.pptx
ZharfanHanif
 
Securing the C-Suite: Cybersecurity Perspectives from the Boardroom
Securing the C-Suite: Cybersecurity Perspectives from the BoardroomSecuring the C-Suite: Cybersecurity Perspectives from the Boardroom
Securing the C-Suite: Cybersecurity Perspectives from the Boardroom
IBM Security
 
Securing Fintech: Threats, Challenges & Best Practices
Securing Fintech: Threats, Challenges & Best PracticesSecuring Fintech: Threats, Challenges & Best Practices
Securing Fintech: Threats, Challenges & Best Practices
Ulf Mattsson
 

Similaire à Cyber Risk Measurement: what 25 CISOs & CROs plan for 2020 (20)

Navigating COVID's Impact on the Financial Services Industry
Navigating COVID's Impact on the Financial Services IndustryNavigating COVID's Impact on the Financial Services Industry
Navigating COVID's Impact on the Financial Services Industry
 
Insur Tech Adelaide slides
Insur Tech Adelaide slidesInsur Tech Adelaide slides
Insur Tech Adelaide slides
 
MMV Webinar 3. Cybersecurity Perspectives. March 2018
MMV Webinar 3. Cybersecurity Perspectives. March 2018MMV Webinar 3. Cybersecurity Perspectives. March 2018
MMV Webinar 3. Cybersecurity Perspectives. March 2018
 
Simmethod growth and value creation sales index
Simmethod growth and value creation sales indexSimmethod growth and value creation sales index
Simmethod growth and value creation sales index
 
Adaptive & Unified Approach to Risk Management & Compliance-via-ccf
Adaptive & Unified Approach to Risk Management & Compliance-via-ccfAdaptive & Unified Approach to Risk Management & Compliance-via-ccf
Adaptive & Unified Approach to Risk Management & Compliance-via-ccf
 
2022 Banking Outlook By BBA - MediaSci
2022 Banking Outlook By BBA - MediaSci2022 Banking Outlook By BBA - MediaSci
2022 Banking Outlook By BBA - MediaSci
 
The Fight for Dominance & The Technology Battlefield in Asset Management
The Fight for Dominance & The Technology Battlefield in Asset ManagementThe Fight for Dominance & The Technology Battlefield in Asset Management
The Fight for Dominance & The Technology Battlefield in Asset Management
 
Simmethod why and benefits, vmware and cisco case studies
Simmethod why and benefits, vmware and cisco case studiesSimmethod why and benefits, vmware and cisco case studies
Simmethod why and benefits, vmware and cisco case studies
 
The Mortgage Treasury Business - Fixed or Floating?
The Mortgage Treasury Business - Fixed or Floating?The Mortgage Treasury Business - Fixed or Floating?
The Mortgage Treasury Business - Fixed or Floating?
 
CB-Insights_The_State_of_Regtech_Q3-17_Briefing.pdf
CB-Insights_The_State_of_Regtech_Q3-17_Briefing.pdfCB-Insights_The_State_of_Regtech_Q3-17_Briefing.pdf
CB-Insights_The_State_of_Regtech_Q3-17_Briefing.pdf
 
CTEK-Investor-Presentation-May-2021-1.pptx
CTEK-Investor-Presentation-May-2021-1.pptxCTEK-Investor-Presentation-May-2021-1.pptx
CTEK-Investor-Presentation-May-2021-1.pptx
 
Solvency II Data Management Handbook
Solvency II Data Management HandbookSolvency II Data Management Handbook
Solvency II Data Management Handbook
 
Coso erm for cloud computing
Coso erm for cloud computingCoso erm for cloud computing
Coso erm for cloud computing
 
Predicting surety claims
Predicting surety claimsPredicting surety claims
Predicting surety claims
 
How to Connect Your Server Room to the Board Room – Before a Data Breach Occurs
How to Connect Your Server Room to the Board Room – Before a Data Breach OccursHow to Connect Your Server Room to the Board Room – Before a Data Breach Occurs
How to Connect Your Server Room to the Board Room – Before a Data Breach Occurs
 
Securing the C-Suite: Cybersecurity Perspectives from the Boardroom
Securing the C-Suite: Cybersecurity Perspectives from the BoardroomSecuring the C-Suite: Cybersecurity Perspectives from the Boardroom
Securing the C-Suite: Cybersecurity Perspectives from the Boardroom
 
Top Issues for Bank Directors in 2019
Top Issues for Bank Directors in 2019Top Issues for Bank Directors in 2019
Top Issues for Bank Directors in 2019
 
Securing Fintech: Threats, Challenges & Best Practices
Securing Fintech: Threats, Challenges & Best PracticesSecuring Fintech: Threats, Challenges & Best Practices
Securing Fintech: Threats, Challenges & Best Practices
 
A New Year’s Ransomware Resolution
A New Year’s Ransomware ResolutionA New Year’s Ransomware Resolution
A New Year’s Ransomware Resolution
 
Responding to Cybersecurity Threats: What SMEs and Professional Accountants N...
Responding to Cybersecurity Threats: What SMEs and Professional Accountants N...Responding to Cybersecurity Threats: What SMEs and Professional Accountants N...
Responding to Cybersecurity Threats: What SMEs and Professional Accountants N...
 

Plus de Kevin Duffey

Plus de Kevin Duffey (20)

Cyber Insights from 100 surveys
Cyber Insights from 100 surveysCyber Insights from 100 surveys
Cyber Insights from 100 surveys
 
Cyber TPRM - the journey ahead
Cyber TPRM - the journey aheadCyber TPRM - the journey ahead
Cyber TPRM - the journey ahead
 
Ensuring Cyber Resilience in the Finance Sector
Ensuring Cyber Resilience in the Finance SectorEnsuring Cyber Resilience in the Finance Sector
Ensuring Cyber Resilience in the Finance Sector
 
Breaches Anticipated in 2022 - November 1st, 2022
Breaches Anticipated in 2022 - November 1st, 2022Breaches Anticipated in 2022 - November 1st, 2022
Breaches Anticipated in 2022 - November 1st, 2022
 
Best Cyber Insights of 2022, from over 200 surveys
Best Cyber Insights of 2022, from over 200 surveysBest Cyber Insights of 2022, from over 200 surveys
Best Cyber Insights of 2022, from over 200 surveys
 
Breaches Anticipated in 2022 as Cyber Security Posture so Low
Breaches Anticipated in 2022 as Cyber Security Posture so LowBreaches Anticipated in 2022 as Cyber Security Posture so Low
Breaches Anticipated in 2022 as Cyber Security Posture so Low
 
Cyber Insurance - Best Insights of June 2022.pptx
Cyber Insurance - Best Insights of June 2022.pptxCyber Insurance - Best Insights of June 2022.pptx
Cyber Insurance - Best Insights of June 2022.pptx
 
Best Cyber Risk Insights from 100 reports published in year to March 2022
Best Cyber Risk Insights from 100 reports published in year to March 2022Best Cyber Risk Insights from 100 reports published in year to March 2022
Best Cyber Risk Insights from 100 reports published in year to March 2022
 
Breaches Anticipated - because firms have weak cyber security visible to hac...
Breaches Anticipated  - because firms have weak cyber security visible to hac...Breaches Anticipated  - because firms have weak cyber security visible to hac...
Breaches Anticipated - because firms have weak cyber security visible to hac...
 
Cyber insurance insights - 17th feb 2022
Cyber insurance insights - 17th feb 2022Cyber insurance insights - 17th feb 2022
Cyber insurance insights - 17th feb 2022
 
Breaches anticipated in 2021 - Published 14th Jjune 2021
Breaches anticipated in 2021 - Published 14th Jjune 2021Breaches anticipated in 2021 - Published 14th Jjune 2021
Breaches anticipated in 2021 - Published 14th Jjune 2021
 
Cyber Resilience across Subsidiaries and Suppliers
Cyber Resilience across Subsidiaries and SuppliersCyber Resilience across Subsidiaries and Suppliers
Cyber Resilience across Subsidiaries and Suppliers
 
London First - cyber attack simulation - 22nd May 2018
London First - cyber attack simulation - 22nd May 2018London First - cyber attack simulation - 22nd May 2018
London First - cyber attack simulation - 22nd May 2018
 
Cyber Attack Simulation for 450 Executives
Cyber Attack Simulation for 450 ExecutivesCyber Attack Simulation for 450 Executives
Cyber Attack Simulation for 450 Executives
 
Equifax Breach - Lessons - Cyber Rescue - 16th may 2018
Equifax Breach - Lessons - Cyber Rescue - 16th may 2018Equifax Breach - Lessons - Cyber Rescue - 16th may 2018
Equifax Breach - Lessons - Cyber Rescue - 16th may 2018
 
Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...
Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...
Cyber attack response from the CEO perspective - Tallinn Estonia - Short Simu...
 
Equifax breach - how to lose friends and customers...
Equifax breach - how to lose friends and customers...Equifax breach - how to lose friends and customers...
Equifax breach - how to lose friends and customers...
 
The Security Director's Practical Guide to Cyber Security
The Security Director's Practical Guide to Cyber SecurityThe Security Director's Practical Guide to Cyber Security
The Security Director's Practical Guide to Cyber Security
 
Cyber Police in Greece helping CEOs
Cyber Police in Greece helping CEOsCyber Police in Greece helping CEOs
Cyber Police in Greece helping CEOs
 
Vodafone security priorities in Greece
Vodafone security priorities in GreeceVodafone security priorities in Greece
Vodafone security priorities in Greece
 

Dernier

Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
dlhescort
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
amitlee9823
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
daisycvs
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
dollysharma2066
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Sheetaleventcompany
 

Dernier (20)

Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
 
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
Cheap Rate Call Girls In Noida Sector 62 Metro 959961乂3876
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort ServiceEluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
 
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors Data
 
PHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation Final
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceMalegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
 
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLJAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
JAYNAGAR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investors
 

Cyber Risk Measurement: what 25 CISOs & CROs plan for 2020

  • 1. Cyber Risk Monitoring for Chief Risk Officers Decisions made in Mizuho’s Boardroom by 25 CROs & CISOs about how to drive Operational Resilience in 2020 through better 3rd Party Risk Management
  • 2. We brought together 25 CROs and CISOs 2 To debate how to monitor cyber risk at suppliers in 2020 Bank of China Bank of England PRA FSCS ILAG Raphaels Bank Deutsche Bank JP Morgan Reassure Brit Bus. Bank LendInvest Rothesay Life Citibank Facebook Rothschild Bank CAF Bank Oak North Shawbrook Bank Bottomline Pay.UK Turkey Bank Met Friendly QBE Insurance Westpac Group Leaders from these firms debated their plans for 2020, in anticipation of the PRA consultation on Outsourcing & 3rd Party Risk Management.
  • 3. We held a Structured Debate via a Simulation 3 Our 25 CROs & CISOs were appointed to a hypothetical organisation Congratulations! You’re now in charge of monitoring cyber risk across the extended enterprise at “ACME Financial”
  • 4. Decisions to be made by 25 CROs and CISOs 4 Our 25 experts broke into 5 groups to address these 4 questions 1) WHAT to call their project, to monitor & mitigate cyber risk across their Outsourcing & 3rd Party suppliers during 2020 2) WHO to include in the project team that will monitor cyber risk (job titles) 3) WHEN to achieve key milestones (SMART objectives) in the project 4) HOW to report the live cyber risk today, on each supplier For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
  • 5. Sample suppliers used for the Simulation 5 Our CROs and CISOs pretended that these 10 companies supply ACME Financial Adecco Concur Dentons G4S Gemalto Recruitment Expense Management Legal Security Information Services Metsi Pega Skanska Sungard Workday IT Services Customer Relationship Management Construction Business Continuity ERP
  • 6. Expert Insight 1: WHAT to call your Project 6 “To measure, monitor & mitigate 3rd party risk in 2020” VENDOR
  • 7. Outsourcing & 3rd Party Risk Management 7 Context: draft Supervisory Statement published on 5th December 2019 For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk “Banks should gradually build an Outsourcing Register which should be complete by 31 Dec 2021.” “Online, real-time reporting tools are strongly encouraged.” Outsourcing & 3rd Party Risk Management 7 Context: draft Supervisory Statement published on 5th December 2019 For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk “Banks should gradually build an Outsourcing Register which should be complete by 31 Dec 2021.” “Online, real-time reporting tools are strongly encouraged.”
  • 8. 8 Expert Insight 2: WHO is in your team? “To measure, monitor & mitigate 3rd party risk in 2020” Our experts debated WHO should be in their team to measure, monitor & mitigate cyber risk across their 3rd Parties.
  • 9. 9 Expert Insight 2: WHO is in your team? “To measure, monitor & mitigate 3rd party risk in 2020”
  • 10. 10 Expert Insight 2: WHO is in your team? “To measure, monitor & mitigate 3rd party risk in 2020” CEO COO 3rd Party Oversight Provider Chair Risk Committee Product Commercial CFO CRO Compliance / Financial Crime Operational Resilience Contracts Procurement CIO CTO Business + Operations Operational Risk DPO Supplier Relationship CISO Auditor Communications Business Continuity Legal Project Manager
  • 11. 11 Expert Insight 2: WHO is in your team? “To measure, monitor & mitigate 3rd party risk in 2020” CEO COO 3rd Party Oversight Provider Chair Risk Committee Product Commercial CFO CRO Compliance / Financial Crime Operational Resilience Contracts Procurement CIO CTO Business + Operations Operational Risk DPO Supplier Relationship CISO Auditor Communications Business Continuity Legal Project Manager Delegates named 24 JOB TITLES they wanted in their Project Team for 2020. But some titles received just 1-2 votes, eg “CEO” nominated only by Caleidoscope, “CFO” was nominated only by ScreamCastle.
  • 12. 12 Expert Insight 2: WHO is in your team? “To measure, monitor & mitigate 3rd party risk in 2020” Delegates named 24 JOB TITLES they wanted in their Project Team for 2020. But some titles received just 1-2 votes, eg “CEO” nominated only by Caleidoscope, “CFO” was nominated only by ScreamCastle. 11 people should be in your team, said Caleidoscope, See2020 & ScreamCastle. Project Tango suggested 12 individuals, while Hawkeye said 8 individuals. The 11 job titles that most experts thought should be in the Project Team were: CRO; COO; CISO; CTO; DPO; Legal; Procurement/Contracts; Project Manager. Operational Resilience; 3rd Party Oversight Provider; Communications.
  • 13. 13 Expert Insight 2: WHO is in your team? “To measure, monitor & mitigate 3rd party risk in 2020” The 11 job titles that most experts thought should be in the Project Team were: CRO; COO; CISO; CTO; DPO; Legal; Procurement/Contracts; Project Manager. Operational Resilience; 3rd Party Oversight Provider; Communications. One team grouped their project members into a hierarchy, with reports pushed up to the C-Level from project managers In operational resilience.
  • 14. 14 Expert Insight 2: WHO is in your team? “To measure & mitigate cyber risk across 3rd parties” We are honoured to be the “3rd Party Oversight Provider” to some of you already. We recommend: have 1 person in your 2nd line “own” your Cyber Risk Dashboard, with monthly exception reports to C-Level. Then let suppliers view themselves on Dashboard.
  • 15. Decisions to be made by 25 CROs and CISOs 15 Our 25 experts broke into 5 groups to address these 4 questions 1) WHAT to call their project, to monitor & mitigate cyber risk across their Outsourcing & 3rd Party suppliers during 2020 2) WHO to include in the project team that will monitor cyber risk (job titles) 3) WHEN to achieve key milestones (SMART objectives) in the project 4) HOW to report the live cyber risk today, on each supplier For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
  • 16. 3: WHEN to achieve key milestones “To monitor & mitigate cyber risk across suppliers in 2020” Our experts debated WHEN to achieve key milestones to measure, monitor & mitigate cyber risk across their 3rd parties, by setting SMART objectives. 16
  • 17. 17 3: WHEN to achieve key milestones “To monitor & mitigate cyber risk across suppliers in 2020” • Specific Goal is to Understand + Improve Critical 3rd Party Risk • Measured inline with Risk Appetite, with MI, Audits, Scorecard, TI • Achieved through monthly reviews of risk-based priorities • Relevant Scorecard reported to Exco on suppliers outside risk appetite • Timed to achieve goal in 12 months
  • 18. 18 3: WHEN to achieve key milestones “To monitor & mitigate cyber risk across suppliers in 2020” Q1: • Define Appetite • Identify & Prioritise key suppliers (risk based) Q2: • Assess Cyber Resilience of Key Suppliers • Manage / Remediate • Ongoing Monitoring & Reporting
  • 19. 19 3: WHEN to achieve key milestones “To monitor & mitigate cyber risk across suppliers in 2020” Q1: • Define Appetite • Identify & Prioritise key suppliers (risk based) Q2: • Assess Cyber Resilience of Key Suppliers • Manage / Remediate • Ongoing Monitoring & Reporting
  • 20. 20 3: WHEN to achieve key milestones “To monitor & mitigate cyber risk across suppliers in 2020” For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
  • 21. 21 3: WHEN to achieve key milestones “To monitor & mitigate cyber risk across suppliers in 2020” For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk Concur Metsi Skanska WorkDay Gemalto Dentons Adecco
  • 22. Decisions to be made by 25 CROs and CISOs 22 Our 25 experts broke into 5 groups to address these 4 questions 1) WHAT to call their project, to monitor & mitigate cyber risk across their Outsourcing & 3rd Party suppliers during 2020 2) WHO to include in the project team that will monitor cyber risk (job titles) 3) WHEN to achieve key milestones (SMART objectives) in the project 4) HOW to report the live cyber risk today, on each 3rd Party and supplier For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
  • 23. 23 4: HOW to report live risk by Supplier? “To monitor & mitigate cyber risk across suppliers in 2020” 23For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
  • 24. 24 4: HOW to report live risk by Supplier? “To monitor & mitigate cyber risk across suppliers in 2020”
  • 25. 25 3: WHEN to achieve key milestones “To monitor & mitigate cyber risk across suppliers in 2020” For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
  • 26. 26 3: WHEN to achieve key milestones “To monitor & mitigate cyber risk across suppliers in 2020” For your cyber dashboard, email Lewis.Varga@CyberRescue.co.ukFor your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
  • 27. 27 3: WHEN to achieve key milestones “To monitor & mitigate cyber risk across suppliers in 2020” For your cyber dashboard, email Lewis.Varga@CyberRescue.co.ukFor your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
  • 28. 28 3: WHEN to achieve key milestones “To monitor & mitigate cyber risk across suppliers in 2020” For your cyber dashboard, email Lewis.Varga@CyberRescue.co.ukFor your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
  • 29. 29 3: WHEN to achieve key milestones “To monitor & mitigate cyber risk across suppliers in 2020” For your cyber dashboard, email Lewis.Varga@CyberRescue.co.ukFor your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
  • 30. 30 3: WHEN to achieve key milestones “To monitor & mitigate cyber risk across suppliers in 2020” For your cyber dashboard, email Lewis.Varga@CyberRescue.co.ukFor your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
  • 31. Continuous Monitoring of our key suppliers Barrie Millett, Group Head of Operational Resilience, Wesleyan Group 31For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk Bank of England - CQUEST
  • 32. Continuous Monitoring of our key suppliers Barrie Millett, Group Head of Operational Resilience, Wesleyan Group 32For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
  • 33. Decisions to be made by 25 CROs and CISOs 33 Our 25 experts broke into 5 groups to address these 4 questions 1) WHAT to call their project, to monitor & mitigate cyber risk across their Outsourcing & 3rd Party suppliers during 2020 2) WHO to include in the project team that will monitor cyber risk (job titles) 3) WHEN to achieve key milestones (SMART objectives) in the project 4) HOW to report the live cyber risk today, on each supplier For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk
  • 34. And the Winning Team is… Hawkeye! “To measure, monitor & mitigate 3rd party risk in 2020”
  • 35. Turn your Insights into Action 35 Kevin.Duffey@CyberRescue.co.uk Hold the date: 21st Jan at 2pm: Managing Cyber Risk at 3rd Parties by Implementing the PRA’s draft Supervisory Statement expectations on Outsourcing Registers, with “Online, real-time reporting tools” that are “strongly preferred”
  • 36. Turn your Insights into Action 36 Kevin.Duffey@CyberRescue.co.uk For more insights like this, go to: www.linkedin.com/company/cyber-rescue-alliance/ For your cyber dashboard, email Lewis.Varga@CyberRescue.co.uk

Notes de l'éditeur

  1. Cyber Risk Monitoring for Chief Risk Officers - with UK Finance and 25 banks 22 Banks, 4 Insurers and 3 other financial institutions sent their CRO, CISO and Operational Resilience leads to participate in this review of how to measure & monitor cyber risk across the extended enterprise.
  2. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  3. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  4. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  5. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  6. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  7. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  8. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  9. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  10. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  11. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  12. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  13. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  14. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  15. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  16. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  17. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  18. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  19. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  20. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  21. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  22. Hello and welcome. I’m Ian Burgess, Head of Cyber Policy at UK Finance, the official trade body of Britain’s banks and financial services sector. I’m delighted to be hosting this event, with Kevin Duffey, CEO of the Cyber Rescue Alliance. Thank you for participating, under Chatham House rules. There are no fire drills planned for today. If the alarm goes off, please leave the building calmly, using the stairs that are clearly marked outside this boardroom. Cyber Attacks threaten operational resilience & reputation. So Chief Risk Officers need timely and objective insights, to drive evidence-based discussions in the Boardroom. Today is an opportunity to to share insights with our peers. Your votes and conclusions will be recorded anonymously, and made available so you can share with colleagues. Kevin will explain how we will encourage interaction.
  23. We’ve just started using the automated workflows that come with the dashboard, to - send our bespoke questionnaire - to all the key individuals - as frequently as we need - with automated reminders and scoring
  24. This is a preview of the new Bank of England, PRA/FCA questionnaire, CQUEST in the platform. For all of the 48 questions, we and our suppliers can just indicate on the left, the level of maturity we have against that particular control. A for a high maturity. D for a low maturity. But the fabulous thing is that the questionnaire provides external measurement to supplement the self-reported score. I won’t go into the detail now, but the point is that it’s possible to move to evidenced-based discussion, relying on objective measurement rather than just an honor system. We’re all on a journey to improve operational resilience, so let me hand back to Kevin Duffey, to drive our conversation forward.