September 11

Cyber Risk, Financial Stability and the Payments System

Cyber risk remains at the top of the list of risks to the financial system, and the financial system is well known as the primary target for hackers (see here, here and here). In response, financial institutions expend huge resources on protecting their information systems—by one estimate, well over $100 billion. Yet, private sector actions to prevent cyber losses fall short due to a glaring externality: since the damage is likely to spill over to other financial firms and to markets, individual firms cannot reap the full benefits of preventing cyber attacks.

To get a sense of the financial stability risks associated with cyber fragility, we need to understand the financial system in some detail. Unfortunately, financial networks are highly complex and vary significantly across markets and functions. They also evolve meaningfully over time. On top of these enormous challenges, assessing network vulnerabilities frequently requires institution- or transactions-level information that is normally not publicly available.

This brings us to the important recent work of Eisenbach, Kovner and Lee (EKL), who study the vulnerability of the U.S. large-value interbank payments system, Fedwire, to a cyber attack on one of the principal nodes of the payments network—namely, one of the top five banks. In this post, we highlight EKL’s analysis as a model for the assessment of cyber-driven network risks. We suggest how central bankers should react to a cyber attack on the payments system, and speculate about what is needed to prevent, as well as mitigate, cyber risks….

Read More

Operational Risk and Financial Stability

Recent disasters—both natural and man-made—prompt us to reflect on the relationship between operational risk and financial stability. Severe weather in sensitive locations, such as Hurricane Irma in Florida, raises questions about the resilience of the financial infrastructure. The extraordinary breach at Equifax highlights the public goods aspect of data protection, with potential implications for the availability of household credit.

At this stage, it’s important to pose the right questions about these operational shocks and, over time, to draw the right lessons. We expect that systemic financial intermediaries’ risk managers, members of their boards, their regulators, and their ultimate legislative overseers are currently in the midst of an intensive review of exposures (and that of the financial system as a whole) to these risks.

So, what is operational risk (OR)? The Basel Committee for Banking Supervision (BCBS) defines OR as “the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events”....

Read More

Why the central bank should be a leading supervisor

Should central banks be a leading supervisor, including supervising systemically important institutions? This is a question that members of the U.S. Congress periodically raise.  Our answer is unequivocally yes. As the lender of last resort, as the monetary policy authority, and as the organization responsible for overseeing the health and stability of the overall financial system—what we could call a systemic regulator—the central bank needs to be a leading supervisor....

Read More