VoxTalks Economics
VoxTalks Economics

S1 Ep28: Regulating cyber risk

How should banks and their regulators manage cyber risk? A new discussion paper from the CEPR sets out six principles from an economist's point of view. Anil Kashyap of the University of Chicago and Anne Wetherilt of the Bank of England tell Tim Phillips what they are recommending.

Featured Speakers

Tim Phillips HostAnil Kashyap GuestAnne Wetherilt Guest

Topics Discussed

Episode Summary

Executive Summary: The episode examines cyber risk as a systemic threat to banking, arguing that regulators must go beyond firm-level security to ensure the financial system can keep delivering critical services during severe, prolonged, and potentially hidden cyber attacks. Anne Wetherilt and Anil Kashyap outline six principles for regulation: assume successful attacks are inevitable, prepare for system-wide disruption, use macroprudential oversight, conduct cyber stress tests, set impact tolerances for critical functions, and encourage diversity in key software/cloud dependencies.

Main Topics: Why cyber risk is different from other shocks (Priority: 5/5): The hosts explain that cyber events differ from storms or terrorist attacks because they are malicious, often inevitable, can remain hidden for long periods, and evolve as attackers adapt. Cyber risk as a systemic financial stability issue (Priority: 5/5): The discussion emphasizes that cyber incidents can spread across interconnected banks and infrastructure, threatening the delivery of critical economic functions, not just individual firms. Limits of firm-level self-protection (Priority: 4/5): Banks have incentives to protect themselves, but finite resources and optimistic assumptions about external support mean supervisors must push them to plan for extreme scenarios. Microprudential principles for banks (Priority: 4/5): The paper argues firms should assume attacks will succeed eventually and prepare for disruption, including realistic planning for recovery and external support under broad attacks. Macroprudential oversight and stress testing (Priority: 5/5): Regulators should assess system-wide resilience, define impact tolerances for critical functions, and run cyber stress tests using severe but plausible scenarios. Reducing concentration in third-party dependencies (Priority: 4/5): The authors warn that reliance on dominant software or cloud providers creates hidden systemic vulnerabilities, so firms should have backups and diversify service providers. International coordination (Priority: 3/5): Because cyber risk is global, the speakers stress that national regulation is necessary but insufficient, and that coordination with international bodies such as the G7 is important.

Key Arguments: Cyber risk is special because attacks are intentional, likely inevitable, potentially invisible for long periods, and constantly evolving. The impact of a cyber shock can be widespread and its timing uncertain due to the interconnectedness of the financial system. Banks cannot rely only on self-interest because they have finite resources and may incorrectly assume outside help will always be available. Supervisors should make firms plan for prolonged, system-wide disruptions to critical services, not just isolated firm-level outages. Macroprudential regulation must look at the role of each firm within the broader financial system to ensure critical services continue to support the economy. Cyber stress testing should use severe but plausible scenarios to test whether firms can recover critical functions within required timeframes. Concentration in external services such as software and cloud providers is a systemic vulnerability that regulation should address through resilience planning and diversification incentives. Cyber risk is international, so domestic regulators should coordinate with global counterparts rather than treat it as a purely national issue.

Data Points: CEPR discussion paper: 13324 - The report discussed in the episode is identified as CEPR discussion paper 13324. Pilot of cyber stress testing: 2019 - Anne Wetherilt says the cyber stress testing program was being developed and a pilot was planned for 2019. Number of principles discussed: 6 - The interview refers to six principles for regulating cyber risk across microprudential and macroprudential oversight. Group of Seven: 7 economies - Anil Kashyap notes that the G7 economies have been actively working on cyber-risk issues.

Pivotal Quotes: "successful high-impact event is a matter of when rather than if" — Anil Kashyap: Explaining why cyber attacks should be treated as inevitable rather than hypothetical. "prepare for a prolonged system-wide disruption" — Tim Phillips / discussion framing: Introducing the regulatory principle that banks must plan for long-duration outages affecting the whole system. "delivery of critical economic functions" — Anne Wetherilt: Describing the core objective of cyber regulation: preserving essential services to the real economy during disruption.

Implications: Banks should plan for inevitable, system-wide cyber disruption, not just isolated breaches. Regulators must test resilience, reduce concentration risk, and coordinate internationally to protect critical financial services.

🔓 Sign Up for Unlimited Episode Search

About VoxTalks Economics

Learn about groundbreaking new research, commentary and policy ideas from the world's leading economists.

View all episodes from VoxTalks Economics