• Skip to primary navigation
  • Skip to main content
  • Skip to footer
The Evolution of ESG RegulationThe Evolution of ESG RegulationThe Evolution of ESG Regulation

CUBE global

  • Products
        • RegPlatform product overviewOur enterprise product, providing regulatory intelligence for large, global financial institutions looking to tackle complex compliance.
        • RegAssure product overviewOur highly intuitive, seamless compliance product, that grows with your small or medium sized business.
        • CUBE's technology
  • Solutions
        • PrivacyGlobal governance for data privacy regulations, the world over
        • RecordsHolistic oversight of ever-growing regulations for records
        • CybersecurityAutomated workflows for up to date, relevant data on cyber
        • Technology riskEffective policies and controls to mitigate technology risk
        • Financial crime and AMLWatertight audit trails to show risk-based rationale
        • View all solutions
  • Resources
        • Resource hubLifting the lid on financial services, compliance, and regulation
        • Read

        • Case Studies
        • Blog posts
        • Reports
        • RegNews
        • Brochures
        • Find

        • Compliance Corner
        • Compliance confessions
        • ESG Conference
        • CUBE’s regulation game
        • Listen

        • Videos
        • Webinars
        • Podcasts
  • Partners
        • Advisory and consulting partnersEnhance your regulatory compliance offering with the entire suite of CUBE regulatory data.
        • Integration partnersCompliance is complex enough without over-complicated integration procedures.
        • Technology partnersAdd value to existing customer applications with a unified window into regulatory intelligence.
        • Partners overview
  • About us
        • About usThe story of who we are, how we got here and why we’re exceptionally proud of what we do
        • TeamThe visionaries and leaders powering CUBE’s success
        • NewsThe latest news from CUBE
        • CareersOur movement to transform regulatory data into regulatory intelligence
        • ContactWant to know more? Get in touch
  • Request a demo
Customer login
Home » Resources » The board should take cybersecurity seriously: 3 points from our webcast

January 10, 2022

Estimated reading time: 3 minutes

The board should take cybersecurity seriously: 3 points from our webcast

With cyber threats on the rise, it’s never been more challenging for multi-national banks to manage cyber-risk.

The regulatory landscape is in constant flux. This can make it a continual challenge for time-poor compliance officers in multi-jurisdictional financial institutions to stay on top of the latest trends: from recent enforcements to new legislation.

Yet gaps in their knowledge could have serious repercussions. That’s where our series of bite-sized 10-minute webcasts comes in. Each time we’ll be discussing the most important breaking news for compliance professionals, with experts from CUBE and the wider industry.

Our latest RegTech in 10… webcast featured some fascinating insights from Alexander Duisberg, Partner at international law firm Bird & Bird, and CUBE’s own EMEA Business Manager, David Noble.

Managing change better

This edition focused on the highly topical area of managing regulatory change for cybersecurity. With threats on the rise and an ever-growing patchwork of legislative requirements to manage, it’s never been more challenging for multi-national firms to manage cyber-related risk. In fact, the average cost of cybercrime for financial institutions has jumped by $1.4 million over the past year to reach $13m, according to an Accenture report from earlier this year.

The GDPR has been the focus of attention for so long that it’s easy to forget there are plenty of other regulations that firms need to stay on top of. As we discussed in the webcast, a proposed law in Germany, in particular, could add extra complexity if it is approved later this year.

Here are the top three takeaways from the discussion:

  1. It’s time for boards to step up The time when cybersecurity issues could be delegated to the CISO is long gone, according to Duisberg. In some countries, like Germany, board members can be held personally liable for serious security breaches. But more broadly, any major incident can have a huge impact on corporate reputation, which makes cyber very much a board-level issue today, he said. The advent of huge fines for serious infractions of the GDPR and NIS Directive only serves to reinforce the fact that senior leaders should assume a high degree of responsibility when it comes to mitigating cyber risk.
  2. Germany offers a snapshot into the future The forthcoming IT Security Act (IT-Sicherheitsgesetz) promises a major revision to Germany’s cybersecurity laws, mandating new best practice requirements on IT providers in any layer of the critical infrastructure supply chain, plus organizations of “public interest” like media firms. Although Duisberg was at pains to point out that the law has yet to be approved, he claimed the GDPR-like fines proposed as part of the legislation mark a major step change in national cyber laws. Although the IT Security Act may cost firms in the short-term, anything that tries to improve baseline security standards should be welcomed as a sign of a maturing industry, he said.
  3. Regulatory change management needs to be automated We’re rapidly approaching the third decade of the 21st century but many compliance programs are still stuck in the past, according to CUBE’s David Noble. He argued that tracking and understanding the impact of regulatory changes is still too ad hoc and inefficient – often managed in spreadsheets and email. This makes it difficult to map the relationship between external regulations and internal policies and controls.

Any regulatory content needs to be well categorized, understood at a granular level and properly attributed to specific areas of the business. But this is hard with ad hoc approaches. The good news is that much of the work leading up to an impact assessment can be automated by compliance teams, freeing up valuable resources to focus on higher value tasks, he argued.

Watch the 10-minute webcast

Related resources
View all resources
A hand writing Asset Management
Blogs

Compliance in the asset management industry

Person stopping domino stones from falling over , which has risk written on it.
Blogs

How to protect financial institutions from collapse

Sylvia Yarbough whispers to a colleague about the key to customer complaints
Blogs

Compliance Confessionals – How does a CCO stay organized?

resilience
Blogs

Get ready for new digital resilience obligations


Want CUBE updates and latest industry news sent straight to your inbox?

Footer

Add CUBE logo here

  • Products
    • Partners
    • Solutions
  • Resource hub
    • Blogs
    • Reports
    • Brochures
    • Compliance Corner
    • Webinars
    • Podcasts
    • Videos
  • Behind CUBE
    • About us
    • Meet the team
    • Careers
    • News US
    • Contact us
  • The legal bits
    • Privacy policy
    • Cookie policy
    • Terms of use
    • Accessibility
Follow us:
  • LinkedIn
  • Twitter
  • YouTube

© 2023 CUBE Content Governance Global Limited

  • English
  • US