AGL 40.00 Decreased By ▼ -0.16 (-0.4%)
AIRLINK 129.53 Decreased By ▼ -2.20 (-1.67%)
BOP 6.68 Decreased By ▼ -0.01 (-0.15%)
CNERGY 4.63 Increased By ▲ 0.16 (3.58%)
DCL 8.94 Increased By ▲ 0.12 (1.36%)
DFML 41.69 Increased By ▲ 1.08 (2.66%)
DGKC 83.77 Decreased By ▼ -0.31 (-0.37%)
FCCL 32.77 Increased By ▲ 0.43 (1.33%)
FFBL 75.47 Increased By ▲ 6.86 (10%)
FFL 11.47 Increased By ▲ 0.12 (1.06%)
HUBC 110.55 Decreased By ▼ -1.21 (-1.08%)
HUMNL 14.56 Increased By ▲ 0.25 (1.75%)
KEL 5.39 Increased By ▲ 0.17 (3.26%)
KOSM 8.40 Decreased By ▼ -0.58 (-6.46%)
MLCF 39.79 Increased By ▲ 0.36 (0.91%)
NBP 60.29 No Change ▼ 0.00 (0%)
OGDC 199.66 Increased By ▲ 4.72 (2.42%)
PAEL 26.65 Decreased By ▼ -0.04 (-0.15%)
PIBTL 7.66 Increased By ▲ 0.18 (2.41%)
PPL 157.92 Increased By ▲ 2.15 (1.38%)
PRL 26.73 Increased By ▲ 0.05 (0.19%)
PTC 18.46 Increased By ▲ 0.16 (0.87%)
SEARL 82.44 Decreased By ▼ -0.58 (-0.7%)
TELE 8.31 Increased By ▲ 0.08 (0.97%)
TOMCL 34.51 Decreased By ▼ -0.04 (-0.12%)
TPLP 9.06 Increased By ▲ 0.25 (2.84%)
TREET 17.47 Increased By ▲ 0.77 (4.61%)
TRG 61.32 Decreased By ▼ -1.13 (-1.81%)
UNITY 27.43 Decreased By ▼ -0.01 (-0.04%)
WTL 1.38 Increased By ▲ 0.10 (7.81%)
BR100 10,407 Increased By 220 (2.16%)
BR30 31,713 Increased By 377.1 (1.2%)
KSE100 97,328 Increased By 1781.9 (1.86%)
KSE30 30,192 Increased By 614.4 (2.08%)

The Securities and Exchange Commission of Pakistan (SECP) Monday issued the SEC Guidelines on Cyber Security Framework for the Insurance Sector, 2020 (Guidelines) specifying guiding principles for adoption of suitable cyber security measures to protect companies' data.

According to the guidelines issued by the SECP, the SECP recognizes that while cyber security is necessary for all insurers, there is no one-size-fits-all prescription for insurers; rather it is dependent on the nature, size and complexity of the insurers business.

The insurers need to take into account the underlying cyber risk at the time of formulation of risk management policy by the Board of Directors (the "Board") of the insurer, as part of significant policy as required under the clause (xi) of the Code of Corporate Governance for Insurers, 2016.

The Chief Information Security Officer (CISO) and the Risk Management Department (or function) will jointly identify, assess, quantify, monitor, and control the nature, significance and interdependencies of the cyber risks, and will be required to develop a cyber security strategy and framework to be put in place for mitigation of inherent cyber risk, the SECP said.

The SECP has directed the insurance companies that the insurers will formulate a sound cyber security framework in order to anticipate, withstand, detect, prevent and respond to cyber attacks, in line with international standards and best practices.

Few guiding principles in respect of formulation of cyber security framework are given in this section.

The insurers should establish systematic monitoring processes to rapidly detect cyber incidents, and periodically evaluate the effectiveness of identified controls, including through network monitoring, testing, audits, and exercises.

The SECP states that the insurers, as a starting point, shall consider existing core technical standards on cyber security such as the National Institute of Standards and Technology (NIST) Cyber security Framework, and Information Systems Audit and Control Association (ISACA)'s COBIT ("Control Objectives for Information and Related Technologies"), and the International Organisation for Standardisation (ISO) 27000 series, which consist of a set of standards and best practices to manage cyber risks.

In 2017, the Financial Stability Board (FSB) had also published a Stocktake of Publicly Released Cyber Security Regulations, Guidance and Supervisory Practices to discuss cyber security in the financial sector.

Further, International Association of Insurance Supervisors (IAIS) has published Application Paper on Supervision of Insurer Cyber security, November 2018 which focuses on supervision (ie, from regulatory perspective) of insurers' cyber security.

An insurer should implement an adaptive cyber security framework that evolves with the dynamic nature of cyber risks and allows the insurer to identify, assess, and manage security threats and vulnerabilities for the purpose of implementing appropriate safeguards into its systems.

Insurers should implement cyber risk management practices that go beyond reactive controls and include proactive protection against future cyber events.

The SECP guided that the insurers should work towards achieving or acquiring predictive capabilities, capturing data from multiple internal and external sources, and defining a baseline for behavioural and system activity, including through outsourcing such expertise.

An insurer should systematically identify and distil key lessons from cyber events that have occurred within and outside the organization in order to advance its resilience capabilities.

An insurer should actively monitor technological developments and keep abreast of new cyber risk management processes that can more effectively counter existing and newly developed forms of cyber attack.

An insurer should consider acquiring such technology and know-how to maintain its cyber security, including through outsourcing such expertise, the SECP added.

The insurers should be able to implement incident response policies and other controls to facilitate effective incident response, and among other things, these controls should clearly address decision-making responsibilities, define escalation procedures, and establish processes for communicating with internal and external stakeholders, the SECP directed the insurance companies.

Copyright Business Recorder, 2020

Comments

Comments are closed.