decisions could affect each other’s ability to maintain critical and other functions, services, and
activities.
Element 6: Recovery.
Resume operations responsibly, while allowing for continued remediation, including by (a)
eliminating harmful remnants of the incident; (b) restoring systems and data to normal and
confirming normal state; (c) identifying and mitigating all vulnerabilities that were exploited;
(d) remediating vulnerabilities to prevent similar incidents; and (e) communicating appropriately
internally and externally.
Once operational stability and integrity are assured, prompt and effective recovery of operations
should be based on prioritization of critical economic and other functions and in accordance
with objectives set by the relevant public authorities. Maintaining trust and confidence in the
financial sector significantly improves when entities and public authorities have the ability to
mutually assist each other in the resumption and recovery of critical functions, processes, and
activities. Therefore, before an incident occurs, establishing and testing contingency plans for
essential activities and key processes, such as funding, can contribute to a faster and more
effective recovery.
Element 7: Information Sharing.
Engage in the timely sharing of reliable, actionable cybersecurity information with internal and
external stakeholders (including entities and public authorities within and outside the financial
sector) on threats, vulnerabilities, incidents, and responses to enhance defenses, limit damage,
increase situational awareness, and broaden learning.
Sharing technical information, such as threat indicators or details on how vulnerabilities were
exploited, allows entities to remain up-to-date in their defenses and learn about emerging
methods used by attackers. Sharing broader insights among entities, between entities and public
authorities, and among public authorities deepens collective understanding of how attackers may
exploit sector-wide vulnerabilities that could potentially disrupt critical economic functions and
endanger financial stability. Given its importance, entities and public authorities should identify
and address impediments to information sharing.
Element 8: Continuous Learning.
Review the cybersecurity strategy and framework regularly and when events warrant—including
its governance, risk and control assessment, monitoring, response, recovery, and information
sharing components—to address changes in cyber risks, allocate resources, identify and
remediate gaps, and incorporate lessons learned.
Cyber threats and vulnerabilities evolve rapidly, as do best practices and technical standards to
address them. The composition of the financial sector also changes over time, as new types of
entities, products, and services emerge, and third-party service providers are increasingly relied
upon. Entity-specific, as well as sector-wide, cybersecurity strategies and frameworks need
periodic review and update to adapt to changes in the threat and control environment, enhance
user awareness, and to effectively deploy resources. Other sectors, such as energy and
telecommunications, present external dependencies; therefore, entities and public authorities
should consider developments in these sectors as part of any review process.
3