Periodic exercises can help to identify weaknesses, test cyber resilience, and evaluate the adequacy of response and recovery. Where possible, the incident response plan should be exercised among entities, third parties and relevant partners. The incident response plan should be reviewed to take into account organizational changes and lessons learned. Element 4: Contingency Planning and Exit Strategies Entities have appropriate contingency plans and exit strategies in place to address situations where third parties fail to meet cyber-related performance expectations or pose cyber risks outside the entity’s risk appetite. Entities should develop and maintain viable contingency plans and exit strategies that assure the entities’ ability to deliver critical functions. Scenarios affecting the cyber risk of the entity may include the following: a material third-party operational event, changes in the third party’s ability to operate, changes to the third party’s commercial or business strategy, and/or performance. Considerations may include transferring the service(s) back to the entity or to another third party. An entity should evaluate options best suited for its operations and to best promote the safety and soundness of the financial system and limit consumer harm. Contingency plans and exit strategies should be tested as appropriate and to the extent feasible. Entities should also understand and validate the existence of their critical third parties’ contingency plans, in addition to the governance policies and standards supporting these plans and strategies. System-wide Monitoring of Cyber Risk and Cross-Sector Coordination Management Element 5: Monitoring for Potential Systemic Risks Third-party relationships across the financial sector are monitored and sources of third-party cyber risk with potential systemic implications are assessed. Third-party cyber risk assessment goes beyond individual entities. Where a third party provides a critical function to a systemically important entity, or where multiple entities use common third parties (concentration risk), third-party cyber risks could have systemic implications. These potentially systemic risks should be identified and assessed so that these risks can be managed. Even where a third party does not provide a critical function to a systemically important entity, if the same third party provides services to multiple entities, it may lead to a concentration risk. Similarly, the supply of multiple functions by one third party could lead to aggregated or compound risk. Entities should identify, assess and monitor concentration risk from their perspective concerning their use of third parties and share relevant information with their relevant authorities. Relevant authorities should try to identify, assess and monitor concentration and potential systemic risks both at the entity and sector levels, as appropriate. For systemic and concentration risk approaches, relevant authorities should consider implementing appropriate measures to manage these risks and improve information sharing, such as the aggregation of third-party information across entities and the identification of where single points of failure, third-party concentrations, or transmission channels may occur. Entities may consider substituting a third party to mitigate said risks. In order to make such measures effective, entities, third parties and relevant authorities are encouraged to improve information sharing on third-party relationships across the financial sector. TLP WHITE: Subject to standard copyright rules, this document may be distributed freely, without restriction. 5

Select target paragraph3