Cyberattack-Prone Banks Risk Over Half of Profits in Singapore

In this article (5)
Banks that lack measures to withstand cyberattacks risk up to 65 percent of their quarterly profits, according to a recent stress test study by the Monetary Authority of Singapore.
Direct and indirect impact from cyberattacks against banks is estimated to cause losses of 35-65 percent and 20-50 percent of quarterly profits, respectively. According to the study, profit declines are attributable to reputational impact, funds were stolen, legal charges and marketing expenses.
The stress tests revealed likely vulnerabilities from theft and disruption-related cyberattacks. Examples of theft-related attacks include hacking of ATMs to dispense cash and bank payment systems. Disruption-related impact includes denial-of-service (DoS) attacks to prevent access to the internet and mobile banking apps or disruption to internal payment processing systems. Damage or corruption of client data was also cited as another example of a cyberattack.
The aforementioned figures reflect costs without contingency measures and when included, risks are significantly improved with banks expected to lose quarterly profits of 20-35 percent and 12-25 percent from direct and indirect impact, respectively. In order to reduce risks from cyberattacks, banks have adopted multiplied layers of security controls to protect data and funds; added DoS mitigation measures such as clean pipe services; and backed up critical data regularly.
In-house measures aside, it is also heeding greater attention to third-party service providers. Periodic audits are made to verify the ongoing effectiveness of existing security and business continuity measures are in place for a switch to an alternative provider or to in-house operations in the event of a disruption.
Questions & Answers
Q.What is the maximum percentage of quarterly profits a bank could lose from cyberattacks without contingency measures?
What is the maximum percentage of quarterly profits a bank could lose from cyberattacks without contingency measures?
Without contingency measures, banks risk losing up to 65 percent of their quarterly profits from direct cyberattack impact, and up to 50 percent from indirect impact. These figures reflect the potential financial exposure.
Q.What types of cyberattacks did the stress test identify as likely vulnerabilities?
What types of cyberattacks did the stress test identify as likely vulnerabilities?
The stress tests revealed vulnerabilities from theft-related and disruption-related cyberattacks. Examples include hacking ATMs or payment systems, denial-of-service attacks affecting online access, and damage or corruption of client data.
Q.How do banks reduce the risks associated with cyberattacks?
How do banks reduce the risks associated with cyberattacks?
Banks reduce risks by adopting multiple layers of security, adding denial-of-service mitigation like clean pipe services, and regularly backing up critical data. They also pay close attention to third-party service providers.
Q.What impact do contingency measures have on the potential profit losses from cyberattacks?
What impact do contingency measures have on the potential profit losses from cyberattacks?
With contingency measures, the risks are significantly improved. Direct impact losses are reduced to 20-35 percent of quarterly profits, while indirect impact losses are expected to be 12-25 percent.
Reader pulse
Are banks adequately prepared for cyberattacks?
16,140 votes so far