Question to the HM Treasury:
To ask the Chancellor of the Exchequer, what discussions she has had with financial regulators on testing operational resilience against simultaneous failures affecting multiple critical third parties.
Cyber security is a top priority for the Government, and HM Treasury works with the financial regulators, industry and with international partners to strengthen the financial sector’s resilience to threats and hazards of all origins.
The financial authorities deploy a range of tools to test and ensure financial sector firms are resilient to the wide range of risks that they could face, and we also maintain robust exercising and incident response frameworks to ensure readiness for disruption and coordination across government and industry. The UK financial regulators have implemented an operational resilience framework for the UK financial sector, which sets out rules and supervisory expectations on operational resilience and risk management for financial services firms, including relating to third-party risk management. Technical advice on security and resilience is also provided by the National Cyber Security Centre and the National Protective Security Authority.
The Critical Third Party (CTP) regime complements but does not replace financial sector firms’ obligations in this area. Designated third parties will be subject to oversight by the UK financial regulators, helping to ensure they have robust arrangements in place to identify, manage and recover from operational disruption affecting critical services used across the financial sector. Through the new regime, the regulators will be able to gather information, assess resilience, and work with third parties to address risks to the continuity of critical services, including through making and enforcing CTP-specific rules where necessary. The regulators’ rules and guidance for CTPs include requirements on incident management.