TLP WHITE - FINAL Entities that fail to recognize this concept may exhibit an imbalance by having an over reliance on perimeter controls, at the detriment of clearly defined and regularly exercised responses (Element 5) and a viable, tested contingency plan for the resumption of operations (Element 6). Outcome 4: An adaptive cyber security approach is adopted. Both cyber threats and the vulnerabilities which they exploit continue to emerge and evolve. Correspondingly, entities need to be adaptive and avoid a static fortress mentality to ensure their cybersecurity procedures reflect the ever changing landscape within which they operate. Building on Element 5 (response) and Element 6 (recovery), incident response mechanisms need to be well-rehearsed such that economic functions can continue to operate through disruption or stress, whether at the entity, sector, cross-sector or international levels. As disruptions may impact the financial sector in unexpected ways, flexibility is key in reactive functions. Coupled with Element 4 (monitoring), it is the agility and experience to rapidly identify and contain disruptions that largely influence the resulting impacts. Related, the overall focus should be on fostering an environment of continuous improvement and learning as part of the cybersecurity program. Outcome 5: There is a culture that drives secure behaviors. Building on Element 7 (information sharing) and Element 8 (continuous learning), a continuous focus on skills and behaviors is essential for embedding effective cybersecurity into the fabric of an organization. In many cybersecurity incidents, flawed procedures or human factors play a key role (e.g. leveraging weak passwords, social engineering, poor security awareness, etc.). Effective cybersecurity strategies consider aspects of people and processes on an equal footing with technical solutions, and reflect this in investment decisions taken. Training and awareness are equally important, targeted at the end user, employee, and senior management. In a world where individuals often trade security for convenience, the manipulation of human psychology is as relevant as an adversary's technological sophistication. Each individual understands that they have a role to play. Effective cybersecurity relies on engaging and educating people, and enabling them to handle information safely. Cybersecurity training and awareness can enhance technical knowledge as well as offer opportunities to change behaviors. Effective training aims for genuine and measurable change, shaping culture in a meaningful way, rather than seeking compliance with a set of policies. The adage that people are considered as the weakest link is reversed, instead promoted as the most valuable asset. PART B: Promoting effective cybersecurity assessments As entities embed the G7FE and strive to achieve the desired outcomes outlined above, there is a necessity to conduct regular assessments to measure the effectiveness of their cybersecurity programs. Cybersecurity assessment can be defined as the systematic collection, review, and use of information on the cybersecurity practices and controls of individual financial sector entities (private or public) or sector participants collectively for the purposes of: (i) judging performance, measured against intended outcomes; and (ii) providing feedback and setting out areas for improvement, including remedial actions. 3

Select target paragraph3