The Malta Independent 3 August 2026, Monday
View E-Paper

Strengthening business resilience to overcome technological risks

Sunday, 26 July 2020, 08:27 Last update: about 7 years ago

Ademola Obasola

Technology advancements have necessitated the need to continuously improve on the safeguarding of Information Technology dependent platforms from the risks associated with them. Such risks could come in the form of security breaches, human errors, failure of systems, unforeseen natural disasters or pandemics such as the COVID-19, as well as zero-day errors from vendor-designed systems that might not have manifested at the time of production.

The Malta Financial Services Authority’s (MFSA) position in releasing the ‘Guidance on Technology Arrangements, ICT and Security Risk Management, and Outsourcing Arrangements’ for consultation to the public, stems from the need to readjust the financial services industry in Malta with the expectations of the European Supervisory Authorities (ESAs).  This position also aligns with the Authority’s stance to continuously help businesses to strengthen their resilience in combatting risks that might emanate from their technological processes. The Guidance document is cross-sectoral. It highlights technology as a key business driver and further provides guidance on its arrangement in organisations, management of security risks associated with it and handling of outsourcing arrangements - which is the new norm for businesses these days.

The Guidance document issued by the MFSA has become necessary especially in the light of the recent attacks on big organisations by attackers who seek loopholes and vulnerabilities in Information Technology systems with the intent to compromise them for various reasons. In recent times, breaches on such organisations as a result of their technology being compromised, have resulted in huge financial losses, loss of confidential data, loss of clientele, business disruptions as well as legal cases and regulatory fines. In this regard, it is essential for businesses to prioritise identification of risks associated with their technology in a timely manner and, ensure that appropriate measures and controls are put in place to reduce the likelihood of adverse events, or to ensure that, if such an event occurs, its impact is contained.

Furthermore, failures or breaches that impact Information Technology systems do not depend solely on inadequate controls on internal systems. Outsourced services interfacing with internal systems are sometimes neglected and inadequately monitored. This brings to fore the risks that are associated with outsourcing some Information Technology processes, especially when businesses fail to ensure that appropriate oversight is dedicated to the same. Outsourcing has come to stay and the additional benefits it brings to businesses cannot be over-emphasised. The onus to monitor outsourced services (including performance and risks that comes with it) rests with the management body, and this responsibility cannot be delegated to an external party.

The principle-based Guidance document, which is at consultation stage, expresses MFSA’s expectations from regulated entities and is projected to become a reference guide for their Information and Communications Technology. Public consultation is open until Friday 28 August 2020 and interested parties are invited to send their feedback , ask questions and/or make any suggestions concerning the Guidelines, to [email protected]. The Guidance document can be downloaded from the MFSA website: https://www.mfsa.mt/publications/policy-and-guidelines/consultations/

 

Ademola Obasola  is an Analyst, Supervisory ICT Risk and Cybersecurity at the MFSA


 

  • don't miss