Page 2 sur 6
could also do the same at their level, taking into consideration the forthcoming
G7 CEG Fundamental elements.
Finally coordination should be cross-authorities, with national security
agencies. As discussed in Panel 1, those agencies have the role to protect
the countries’ critical economic sectors, including the financial sector, against
cyber-attacks. Financial authorities have the role to supervise the financial
sector’s capacity to manage its risks, including cyber risks. Both authorities
have a mutual interest in coordination.
B. Three concrete areas to improve our coordination
I. Regulation and supervision
I would like to start with the issue of regulation, which was addressed by panel
2. One difficulty with regulation is about reaching a balanced situation.
Regulation is needed, irrespective of the level of institutions’ awareness and
self-discipline… But, too much regulation may lead to a decrease in selfdiscipline and turn institutions’ effort into a compliance exercise.
Since 2015, cybersecurity issues attract an increasing level of attention, and
regulators have produced a large number of regulatory texts, both at national
and international levels. This was called for to trigger the appropriate response
and efforts from the industry. It helped the sector to reinforce its safeguards.
Nevertheless, we must ask ourselves whether the multiplication of new
regulations can have a counterproductive effect. From the panelists’
interventions, two issues need to be addressed:
• First, we should avoid the possible proliferation of texts by standardsetters for banking, payments, securities services, insurance and/or
financial markets. The FSB has already provided such evidence in a
stock-taking exercise performed in 2017. Regulators are paying
attention to cyber risks, and while they share the same objectives,
regulatory texts tend to differ across regulators and as a result add to
firms’ burden in terms of compliance with these various regulations, with