New Banking and Insurance Cybersecurity Rules Define Major Incident Thresholds and Liability

Deep News
07/10

On July 10th, the National Financial Regulatory Administration released a draft of the "Cybersecurity Management Measures for the Banking and Insurance Industries" for public consultation. This document, comprising eight chapters and seventy-two articles, marks the first time systematic regulations for cybersecurity management at institutions such as banks, insurance companies, and financial holding companies have been established in the form of departmental rules. The most notable aspect is the four-tier classification standard for cybersecurity incidents detailed in the appendix, which provides quantitative answers to questions like how long a bank's critical information system must be paralyzed during business hours to be considered "significant," "major," or "particularly major."

Defining Incident Severity

According to the appendix titled "Cybersecurity Incident Classification Standards for the Banking and Insurance Industries," incidents are categorized into four levels based on factors such as the scope of impact, the importance of the system, and the duration of business interruption.

A Level 3 (Significant) cybersecurity event is defined as an incident where a critical information system, during business hours, causes business operations to fail in one province (autonomous region, or municipality directly under the central government) for 30 minutes or more but less than 3 hours. Alternatively, it includes incidents where the leakage, illegal acquisition, or illegal use of important or sensitive data constitutes a significant data security event.

A Level 2 (Major) cybersecurity event occurs when a critical information system, during business hours, causes business interruption in two or more provinces for 30 minutes or more but less than 3 hours, or causes business interruption in one province for 3 hours or more but less than 6 hours. It also includes incidents where the leakage or destruction of important data constitutes a major data security event.

A Level 1 (Particularly Major) cybersecurity event is triggered when a critical information system, during business hours, causes business interruption in two or more provinces for 3 hours or more, or causes business interruption in one province for 6 hours or more. It also covers incidents involving the large-scale leakage of sensitive-level or higher data, constituting a particularly major data security event.

A Level 4 (General) cybersecurity event encompasses all other incidents that cause a certain impact on an organization or individual, or constitute a general data security event.

Strict Reporting Timelines

Accompanying the classification standards are stringent reporting deadlines. Article 45 stipulates that for Level 3 (Significant) or higher cybersecurity incidents, financial institutions must report to the National Financial Regulatory Administration or its local offices within 2 hours, followed by a formal written report within 24 hours. For incidents involving critical information infrastructure, reports for significant or higher-level events must be made to regulators and public security departments within 1 hour at the latest. For particularly major events, progress updates must be submitted every 2 hours until the incident is resolved. Institutions that conceal, omit, falsify, or intentionally delay reports will face serious accountability and disciplinary action.

Comprehensive Risk Management Requirements

Beyond incident classification and reporting, the measures require financial institutions to establish a cybersecurity governance framework. This framework designates the institution's principal responsible person as the primary leader for cybersecurity and mandates integrating cybersecurity risks into comprehensive risk management. Institutions must comply with national cybersecurity classification protection systems and commercial cryptography evaluation requirements. They are required to conduct a cybersecurity risk assessment and an internet penetration test at least annually, and a cybersecurity audit at least once every three years. The rules also emphasize strengthening supply chain security and outsourcing management. Operators of critical information infrastructure must possess domestic operational maintenance capabilities and maintain a 7x24-hour monitoring and command center, conducting realistic drills for high-risk scenarios annually.

Clarifying Ambiguity

Previously, decisions on whether and when to report banking system failures were often contentious due to vague standards. The new regulations, with clear time thresholds like "30 minutes," "3 hours," and "6 hours," define event levels precisely. This clarity not only facilitates institutions in self-assessing and classifying incidents but also enhances regulatory oversight, enforceability, and operability. It is conducive to preventing the escalation of cybersecurity risks into financial and societal risks.

免責聲明:投資有風險,本文並非投資建議,以上內容不應被視為任何金融產品的購買或出售要約、建議或邀請,作者或其他用戶的任何相關討論、評論或帖子也不應被視為此類內容。本文僅供一般參考,不考慮您的個人投資目標、財務狀況或需求。TTM對信息的準確性和完整性不承擔任何責任或保證,投資者應自行研究並在投資前尋求專業建議。

熱議股票

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10