Cyber resilience

Cyberattacks are a serious threat to the financial sector. Financial entities must therefore continually improve their resilience to such attacks.

Regulation on digital operational resilience for the financial sector

The Digital Operational Resilience Act (DORA) has harmonised the requirements for managing cyber risks in the financial sector across the EU. Systemically important financial entities that provide core financial services are now required, among other things, to carry out threat-led penetration testing (TLPT). In such exercises, financial entities test their resilience to cyberattacks under realistic conditions to identify weaknesses and areas for improvement. 

The TLPT method used in Austria is based on the European TIBER-EU framework.

The harmonised EU framework for realistic cybertests (TIBER-EU)

TIBER stands for “threat intelligence-based ethical red teaming”. It is a framework developed by the European System of Central Banks (ESCB) under which financial entities commission ethical hackers to carry out realistic attacks on their critical IT systems. These exercises are subject to strict security measures. The tested financial entities must undertake all necessary measures to ensure that the tests will not pose any risks to themselves or to their customers.

There is no “pass” or “fail” in such tests. Rather, they are designed to help financial entities learn from the results and improve their response to cyberattacks. 

The OeNB serves as the central hub for implementing TIBER in Austria.

Implementing TIBER-EU in Austria (TIBER-AT)

The OeNB’s TIBER Cyber Team (TCT-AT) is responsible for implementing TIBER-EU in Austria (“TIBER-AT”). TCT-AT is an independent organisational unit within IT supervision that is not involved in the operational supervision of financial entities. TCT-AT accompanies all tests in cooperation with the Financial Market Authority (FMA) or the European Central Bank (ECB), if the tests concern significant entities.

TIBER-AT takes national specificities into account, thereby facilitating a standardised implementation of TLPT. Even before TLPT became mandatory under DORA, some financial entities took part in voluntary TIBER-AT tests, gaining valuable experience and strengthening their cyber resilience.

Contact


TIBER Cyber Team Austria