The Global Financial Markets Association ("GFMA") published a blueprint for firms to implement cybersecurity testing programs in a manner consistent with regulatory obligations.

In the report, the GFMA explained that coordination between firms and regulators is essential to establishing and maintaining effective testing programs. To facilitate a consistent and transparent approach for conducting such testing, the GFMA detailed a "Testing Lifecycle" with four phases:

  • Threat Intelligence: Firms coordinate with regulators to ascertain threats that will inform threat scenarios.
  • Planning: Firms coordinate with regulators to establish expectations and determine a scope of testing that is tailored to the individual firm's processes and functions.
  • Testing: Firms drive operational planning, execute testing scenarios and review results.
  • Analysis and Response: Firms identify and address vulnerabilities, and report results to regulators and firm executives.

Adherence to the framework, the GFMA asserted, will help firms to comply with supervisory requirements while also increasing cybersecurity protections and resiliency.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.