Page 3 sur 6
little marginal gain. Clarity would be enhanced by reducing the multiple
variations in the formulation of requirements across institutions. In turn,
regulators’ efforts would be streamlined and their experts employed
more effectively.
How can we better coordinate regulation? Obviously, a “principle-based”
regulation on cybersecurity is preferable, rather than increasingly
prescriptive standards, too rigidly “rules-based”. Supervision completes
regulation. Principle-based regulation would give supervisors some
room for manoeuvre to modulate their expectations to the risk profile of
the institutions.
• But then, we should also pay attention to the risk of regulatory
arbitrage. Regulatory differences can create opportunities. If not all
regulations are aligned, some private actors could (re)locate their IT
systems in less-demanding jurisdictions. This is the reason why we
need homogeneity among international regulatory texts with the largest
outreach.
Who could lead this coordination role on cybersecurity regulation? The G7
expert group has been extremely successful in producing “Fundamental
elements”, but this group has no standard-setting role and its texts can only
guide regulators in their work. I believe the FSB is best placed to engage the
dialogue with the various standard-setters to foster the alignment of their texts,
as well as to conduct global outreach, and limit the proliferation of working
groups.
II. Information
Cyber threats are increasing, but adequate and consistent measurement is
challenging. I would like therefore to make two proposals:
About incident reporting. Many reporting obligations on cyber incidents have
emerged, requested by various authorities. But these incident reports give little