MPs want single regulator for cyber security in financial services

Image

Andrew Tyrie, chair of the Treasury committee, is calling for more action to protect the financial services sector from cyber attacks, suggesting the current approach is ‘opaque’ involving too many different regulators and with insufficient use of critical intelligence information provided by GCHQ

In a letter to Ciaran Martin, chief executive of the National Cyber Security Centre, Tyrie said: ‘The committee has serious concerns in the cyber area: the opaque lines of accountability between the relevant authorities, particularly the regulators on the one hand and intelligence agencies on the other, and a very high degree of reliance on information from the intelligence community.

‘It is essential that the intelligence community gives the regulators the technical and practical support they need to do their job. This means making sure that financial cyber crime has a high priority, and is not subordinate to other work. Failure to do so would inhibit the ability of financial institutions to maintain an adequate level of protection for millions of consumers.’

Tyrie pointed out that responsibility is currently shared between the Financial Conduct Authority (FCA) and the Prudential Regulation Authority (PRA) as well as GVHQ, which he noted may be prioritising state sponsored cyber crime and terrorism above commercial cyber crime and fraud.

‘It is for consideration whether a single point of responsibility for cyber risk in the financial services sector is now required. Certainly, as millions of customers are exposed to the risks of cyber crime, a higher level of scrutiny and accountability for existing arrangements is needed,’ he said.

Referencing the attack on Tesco Bank in November 2016, Tyrie said: ‘This is just the latest in a long list of failures and breaches of banking IT systems, exposing many thousands of customers to uncertainty and disruption.

‘At the beginning of the year, I wrote to the regulators urging them to take action to ensure that banks improve the resilience and security of their systems, and their IT expertise.’

Tyrie said he wanted to know what steps the National Cyber Security Centre, which was formed earlier this year, will be taking to advise banks on the need to upgrade legacy systems and infrastructure to deal with cyber attacks.

The Treasury committee letter to Ciaran Martin is here.

Pat Sweet | Reporter, Accountancy Daily [2010-2021]

Pat Sweet was the former online reporter at Accountancy Daily and contributor to the monthly Accountancy magazine, pub...

View profile and articles

0
Be the first to vote

Rate this article

Related Articles
Subscribe