Page 3 sur 6 little marginal gain. Clarity would be enhanced by reducing the multiple variations in the formulation of requirements across institutions. In turn, regulators’ efforts would be streamlined and their experts employed more effectively. How can we better coordinate regulation? Obviously, a “principle-based” regulation on cybersecurity is preferable, rather than increasingly prescriptive standards, too rigidly “rules-based”. Supervision completes regulation. Principle-based regulation would give supervisors some room for manoeuvre to modulate their expectations to the risk profile of the institutions. • But then, we should also pay attention to the risk of regulatory arbitrage. Regulatory differences can create opportunities. If not all regulations are aligned, some private actors could (re)locate their IT systems in less-demanding jurisdictions. This is the reason why we need homogeneity among international regulatory texts with the largest outreach. Who could lead this coordination role on cybersecurity regulation? The G7 expert group has been extremely successful in producing “Fundamental elements”, but this group has no standard-setting role and its texts can only guide regulators in their work. I believe the FSB is best placed to engage the dialogue with the various standard-setters to foster the alignment of their texts, as well as to conduct global outreach, and limit the proliferation of working groups. II. Information Cyber threats are increasing, but adequate and consistent measurement is challenging. I would like therefore to make two proposals: About incident reporting. Many reporting obligations on cyber incidents have emerged, requested by various authorities. But these incident reports give little

Select target paragraph3