{"id":110460,"date":"2021-01-27T20:17:23","date_gmt":"2021-01-27T20:17:23","guid":{"rendered":"https:\/\/precoinnews.com\/?p=110460"},"modified":"2021-01-27T20:17:23","modified_gmt":"2021-01-27T20:17:23","slug":"market-watchdog-fma-slams-nzx-over-cybersecurity-breaches-says-critical-gaps-remain","status":"publish","type":"post","link":"https:\/\/precoinnews.com\/business\/market-watchdog-fma-slams-nzx-over-cybersecurity-breaches-says-critical-gaps-remain\/","title":{"rendered":"Market watchdog FMA slams NZX over cybersecurity breaches, says critical gaps remain"},"content":{"rendered":"

A market watchdog has released a damning report on cyberattacks that hit the NZX over August and September last year, forcing it offline for several trading days, plus an earlier, volume-related glitch that forced it offline during April 2020.<\/p>\n

The Financial Markets Authority said the NZX had been short on technology and people skills – and that the DDoS attack was forseeable but not planned for.<\/p>\n

The FMA added that despite several steps taken by the exchange to beef up its security holes since September (see below) “there are some critical gaps remaining.”<\/p>\n

The report comes amid a rash of online attacks at a time when our government has failed to follow Australia’s move to ramp up funding cybersecurity funding. The Reserve Bank is bracing for a review of its recent data breach, which followed internal warnings over underspending that were ignored.<\/p>\n

The FMA’s review of NZX technology issues, released this morning, has found the stock exchange failed to meet its licensed market operator obligations due to insufficient technology resources.<\/p>\n

As a licensed market operator, the NZX is required to meet certain obligations under the Financial Markets Conduct Act (FMC Act). One of those obligations is to have sufficient technology resources to operate its licensed markets properly, including arrangements to ensure market disclosures are made available, the recgulator said in a statement.<\/p>\n

Scope of the problems<\/h2>\n

The FMA began a targeted review of NZX’s technology after it suffered trading volume-related system issues and outages in April 2020. The scope of the review was expanded following DDoS (Distributed Denial of Service) attacks on NZX in August 2020.<\/p>\n

The FMA also had concerns that NZX’s trading system was unable to trade securities at zero or negative yields. The volume-related issues and DDoS event repeatedly halted or disrupted market activity.<\/p>\n

Report's key findings<\/h2>\n

Overall, the FMA review found the NZX did not have adequate technology capability across its people, processes and platform to comply with market operator obligations and especially in the context of its systemic importance.<\/p>\n

Additionally, the performance of NZX’s systems did not meet regulatory requirements or expectations for fair, orderly and transparent markets, the regulator found.<\/p>\n

In respect of NZX’s trading volume-related issues, the FMA review concluded fundamental tools and practices were either lacking, insufficiently robust or not fully utilised, the report said.<\/p>\n

NZX aware of limitations, not not accept responsibility<\/h2>\n

NZX was aware of the capacity limitations of its core back end processing system, particularly as daily trading volumes had increased in the last three years, the FMA said.<\/p>\n

FMA chief executive Rob Everett said market participants gave feedback that NZX did not accept responsibility for known systemic issues and was slow to act:<\/p>\n

“The feedback from market participants mirrors our own observations and is a major concern that needs to be addressed by the NZX board and executive, Everett said.<\/p>\n

“The failure to properly consider the broader ecosystem in which the exchange operates, and to fully engage with industry feedback and concerns, were contributing factors to the volume-related issues.”<\/p>\n

Insufficient crisis planning<\/h2>\n

The FMA review found NZX’s crisis management planning and procedures were basic.<\/p>\n

While the NZX said the DDoS attack (where automated bots overwhelmed its servers) was on a huge scale and unforeseeable, the regulator disagreed, saying, “A DDoS attack was foreseeable.” The FMA review said an attack of sufficient magnitude to take down servers – and with them, the NZX’s market announcement platform – was at least possible and should have been planned for. NZX self-rated its IT security profile at a basic maturity level, indicating that a number of best practices had not been adopted.<\/p>\n

Actions required<\/h2>\n

NZX is required to develop a formal action plan to address the issues raised by the FMA. The market regulator has met with the NZX Board to discuss its findings and received assurances that the NZX Board takes responsibility for making the necessary investment and to address the issues highlighted in the report.<\/p>\n

Earlier (see below), NZX warned that bolstering its defences could lead to costs that have to be passed on to clients.<\/p>\n

The FMA report said NZX had a “small” inhouse IT team – appropriate for a normal small-to-medium business, but not one running critical infrastructure.<\/p>\n

It was consumed by day-to-day tasks and small incremental upgrades, lacking the capacity to address areas such as performance monitoring, continuous version management of software, failover planning and risk management.<\/p>\n

The FMA said next steps need to nclude recruiting a chief risk officer, a head of network architecture and a head of IT security.<\/p>\n

The exchanges chief information officer, David Godfrey, quit on September 28, the day after a daylight savings blunder that came on top of the earlier DDoS attack and clearing outages.<\/p>\n

No reason was given for his departure. An NZX spokesman said Godfrey’s abrupt exit – before recruitment for a successor had begun – was not related to the various IT problems.<\/p>\n

“We are confident that NZX understands our concerns,” said Everett said.<\/p>\n

“We look forward to finalising NZX’s action plan and monitoring its progress over coming months.”<\/p>\n

Toothless watchdog<\/h2>\n

Sanctions for a breach of NZX’s statutory obligations are limited, the NZX said in its report.<\/p>\n

However, given the commitments received from the NZX and the actions plans already initiated by NZX following its internal and external reviews, the FMA considers the requirement to produce a detailed, time-bound action plan will be sufficient.<\/p>\n

The FMA acknowledged NZX has already taken significant steps to improve its systems and processes.<\/p>\n

But the watchdog also said it would closely engage with NZX on the action plan and continue increasing oversight on NZX’s technology until the regulator has confidence all issues have been addressed.<\/p>\n

The FMA will publicly report on NZX’s progress in the annual NZX Obligations Review, to be released in June 2021.<\/p>\n

NZX chief executive Mark Peterson said in statement soon after the FMA report was released, “NZX accepts that it did not meet the high standards it sets for itself in key areas of technology resources. We also agree that improvements are required and we are committed to delivering these improvements via an action plan that will be agreed with the FMA. We will work constructively with the FMA through that process and engage closely with the broader capital markets technology ecosystem.”<\/p>\n

Security upgrade costs could be passed-on<\/h2>\n

In a December 21 update, NZX said it will continue to bolster its IT and cybersecurity systems over the coming months – and that related costs are “likely” to be passed on to its clients.<\/p>\n

This comes after another year that has seen several hot local IPO prospects, including Laybuy and Aroa Biosurgery, ultimately opting to list across the Tasman.<\/p>\n

The exchange said: “NZX accepts that it did not meet its own high standards in certain areas of its technology systems,” after suffering a sustained cyberattack over August and September, and problems with its clearing system earlier in the year.<\/p>\n

In a statement, the exchange did not put a figure on the ongoing security upgrade, but did offer that “there is no impact on the FY2020 earnings guidance”.<\/p>\n

In a December 2 update, NZX said it expected ebitda for its 2020 financial year (which coincides with the calendar year) to be “around the top of the guidance range of $30 million to $33.5 million”.<\/p>\n

The exchange won’t comment on any impact to its FY2021 guidance until it delivers its FY2020 full-year report on February 17.<\/p>\n

Read More<\/h3>\n