With the digitisation and transformation of the economic and financial system, the risk of a major crisis emerging from cyberspace is to be taken seriously. This is what Christine Lagarde, President of the European Central Bank, suggested in her speech of 5 February 2020, as well as Jerome Powell, Chairman of the Federal Reserve of the United States on 12 April 2021. The latter declared: “The chances that we would have a breakdown that looked anything like that [in 2008] are very, very low. The world evolves. And the risks change as well. And I would say that the risk that we keep our eyes on the most now is cyber risk”. In a 2019 systemic risk survey conducted by the Bank of England, 61% of respondents actually expressed concern about the impact of cyber attacks on the financial system should they materialise, placing cyber risk ahead of geopolitical risk and the risk of a global economic slowdown.
Although cyber risk has gradually been taken into account in the governance and risk management framework of monetary and financial authorities (Kashyap and Wetherilt, 2019), the availability of cyber risk monitoring tools remains very limited (an exception is the study by Jamilov, Rey, and Tahoun, 2021, which offers a historical perspective on the evolution of cyber risk worldwide and within major economic sectors).
A tool for daily and real-time monitoring of cyber risk
In Lhuissier and Tripier (2021), we built a new indicator of cyber risk since 2011. The purpose of the indicator is to conduct a high-frequency, daily monitoring of cyber risk and an analysis of the different sectors of the economy concerned.
Cyber risk is defined as the combination of the probability of occurrence of cyber incidents (malevolent or non-malevolent incidents that threaten the cybersecurity of an information system or breach security procedures and rules) and their impact. In order to measure its evolution, we calculated the share of messages dedicated to cyber risk on the social network Twitter over the past ten years. More precisely, our indicator reflects the frequency of tweets, sent by English-speaking users, which contain the following words: "cyber" and "risk", "attack", or "threat". Our methodology has the following advantages: 1) it includes all the events that took place at the global level and gave rise to exchanges in English on this social network, 2) it weights the importance of one event relative to another (a major event will naturally be attributed more tweets than a minor one), and 3) it monitors the development of cyber risk on a daily basis and in real time. However, one must keep in mind the limitations of this indicator. It only covers the economic players present in this network, and moreover, they are English-speakers. In addition, we only measured the frequency of occurrence of keywords related to cyber risk, without analysing the content of the messages or the interactions of the senders of these messages.
Chart 1 shows the evolution of our cyber risk indicator from January 2011 to August 2021. The highest occurrence of messages related to cybersecurity on Twitter that we measured occurred in May 2017 during the WannaCry attack, a malware that hit hundreds of thousands of computers in hundreds of countries. The most recent major event that we identified is the May 2021 attack on Colonial Pipeline (the manager of an oil pipeline between Houston and New York) that had significant political repercussions (including the August 25 cybersecurity meeting hosted by President Joe Biden).
Certain events have repercussions on financial markets. As an example, in December 2020, the hack of SolarWinds, an IT management software company and supplier to US federal agencies and corporations, affected up to 18,000 customers and over 100 US companies. SolarWinds Corp. stock dropped by about 40% in just a few days following the attack. Although its effects did not cause any major incidents in the financial sector, such a scenario could occur in the future. Due to its very high level of digitisation and interconnection, the financial sector is particularly exposed to systemic risk, i.e. the consequences of a cyber incident spread far beyond the initially impacted entity, causing damage to the economic and financial system as a whole.
A trend-cycle decomposition of cyber risk
The indicator provides a high-frequency, daily measure of cyber risk. However, it does not provide a clear view of its trend. In order to better understand the trend of cyber risk, Chart 2 shows the number of extreme events per year, defined here as the highest index values (top 5%), as well as the long-term trend of the index stripped of extreme events.
Between 2011 and 2017, the number of extreme events increased steadily, before dropping in 2018 and 2019, and rebounding in 2020. This evolution of cyber risk can also be observed through its long-term trend. Indeed, the trend shows that increasing attention was paid to cyber security until 2017; it then picked up again from 2020 in the context of the Covid-19 health crisis. These developments can be logically explained by the growing use of information technology and the transformations in the organisation of work and production, which are increasingly remote and connected.