Bank of England highlights cyber response and recovery practices for systemic firms
Key Takeaways
- 01The Bank of England has published effective practices for cyber response and recovery capabilities at systemic firms and financial market infrastructures.
- 02The paper aims to support the continued development of organisations’ ability to manage cyber incidents and restore operations.
- 03It reflects practices observed across the sector rather than introducing a new mandatory compliance regime.
- 04Systemic organisations can use the publication as a reference point when reviewing cyber incident-response and recovery arrangements.
The Bank of England has published a paper on effective cyber response and recovery practices observed among systemic firms and financial market infrastructures.
The publication is intended to share approaches that can help important financial-sector organisations continue to develop their ability to respond to and recover from cyber incidents. Cyber response covers actions taken to contain and manage an attack, while recovery focuses on restoring systems, services and operations.
The paper draws on practices already observed across firms and market infrastructures that are important to the financial system. It highlights the continuing evolution of their cyber resilience capabilities rather than establishing a new rule or prescribed compliance framework.
For affected firms and financial market infrastructures, the publication provides a regulatory reference point for assessing whether their incident-response and recovery arrangements remain effective. It may be particularly relevant to governance, recovery planning, testing and the ability to restore critical services following a significant cyber event.