MAS amends rules on managing tech risks

Financial firms should analyse and share threat intelligence within the ecosystem.

The Monetary Authority of Singapore (MAS) has revised its guidelines for managing technology risks to fight against growing cyber threats, a statement read.

This comes after a recent spate of attacks on supply chains, which targeted multiple IT service providers through the exploitation of widely used network management software.

It included stronger risk mitigation strategies, such as establishing a robust process for the analysis and sharing of cyber threat intelligence within the financial ecosystem and conducting cyber exercises to stress test defences by simulating attack tactics, techniques, and procedures used by real-world attackers.

In addition, due to growing reliance on third party service providers, MAS suggests that FIs should exercise strong oversight of arrangements with third party service providers to ensure system resilience and maintain data confidentiality and integrity.

Moreover, boards and senior management should ensure that a chief information officer and a chief information security officer should account for managing technology and cyber risk, and the boards should include members with the relevant knowledge of such risks.

Join Singapore Business Review community
A NOTE FROM SINGAPORE BUSINESS REVIEW

The people you want to reach are already in this room.

Every quarter, SBR lands on the desks of the founders, CFOs, and directors running Asia's most consequential companies. Every day, they open our newsletter and read our website. It's a room that took twenty years to build — and it's the one most of our partners are trying to get into.

The good news is that the door is open. We work with companies on thought leadership articles, sponsored content, industry summits across Southeast Asia, regional awards programmes, podcasts, and media placements in print and digital. The shape of the right partnership depends on what you're trying to do, which is why we'd rather start with a conversation than send a rate card.


If you have something this room should know about, tell us. We'll tell you honestly whether we can help, and how.

No rate cards until we understand the brief. It's a better use of everyone's time.