Share

FIRSTonline Banner

Cybersecurity: Bankitalia, Consob and Ivass offer new voluntary tests for banks, insurance companies and more

Companies can undergo cybersecurity tests through a new structure – The authorities have adopted the national TIBER-IT Guide, which implements the European models

Cybersecurity: Bankitalia, Consob and Ivass offer new voluntary tests for banks, insurance companies and more

Bankitalia, Consob e Ivass they built a new structure to help financial companies improve theirs cybersecurity. It is called TIBER Cyber ​​Team Italy (TCT) and is a center of expertise whose functioning is ensured by experts from the three authorities.

Basically, financial entities can decide to undergo a cybersecurity test using the TCT: just get in touch with the structure by sending an email to [email protected].

The TIBER-IT National Guide

The initiative is linked to the fact that the Bank of Italy, Consob and Ivass have adopted the TIBER-IT national guide, thus implementing at national level the reference model for conducting advanced cybersecurity tests of the Threat-Led Penetration Testing (TLPT) type, harmonized at European level.

Help content

In particular, the Guide performs three functions:

  1. defines the methodology and operating model for conducting TLPT-type tests by Italian financial entities;
  2. identifies the phases in which the test process is divided;
  3. defines the roles and activities of the various actors involved (authorities, testers and external suppliers).

The goals

“In continuity with the aims of the joint strategy for the cyber security of the Italian financial sector issued by the Bank of Italy and Consob – reads a joint note from the three authorities – the adoption of the Guide makes it possible to improve the cyber resilience of the system financial situation and, in this way, its overall stability".

The recipients

The Guide is not addressed only to Italian banks and insurance companies, but also to other types of financial entities:

  • market infrastructure;
  • payment system operators;
  • managers of instrumental technological or network infrastructures;
  • trading venues;
  • payment institutions and e-money institutions;
  • financial intermediaries;

Each company can freely decide whether to undergo the test "and is responsible for managing all the risks related to its execution, which is done by companies chosen by the entity that undergoes the test - continues the note - The three authorities direct the programming tests in line with the evolution of the risk scenarios and the relevance of the financial entities for the continuity of service of the sector”.

comments