error
Subscriptions are not available for this site while you are logged into your current account.
close
Skip to main content

Loading

The page is loading.

Please wait...



      Are cyber risks dampening your drive to innovate? If so, you are not alone. In KPMG’s recent Asset Management CEO Outlook report, 77 percent of respondents said that they are concerned about their vulnerability to cyber-attacks.¹ Nearly nine-in-ten said they are worried about the potential for identity theft and data privacy.

      In part, this reflects the fact that many Wealth and Asset Management Boards now recognise that they need a much clearer quantification of their cyber risks and potential impacts. Significant supply chain concentration is leading to accumulated risk. High net worth individuals are becoming a more frequent target of hackers, with theft of wealth data increasingly enabling downstream fraud, extortion and even physical security threats. Digitisation is creating unanticipated vulnerabilities, and AI-enabled social engineering is sharpening the fraud threat.

      At the same time, the Boards are striving to get their arms around new and emerging threats like Quantum Computing. The general consensus is that Q-Day is coming; the timeline to a Post-Quantum Cryptography (PQC) world is rapidly shrinking. Quantum will almost certainly bring significant opportunities for wealth and asset managers to innovate. But it will also bring significant new risks.

      Not surprisingly, therefore, our conversations with UK Wealth and Asset Management leaders suggest many Boards want to assess whether their cyber security posture is appropriate to support the kind of innovation that they want to achieve across the front, middle and back office.

      James Hanbury

      Director, Global Lead Cyber Risk Insights

      KPMG in the UK



      Quantify the risk, understand the value

      The problem is that, all too often, Wealth and Asset Management organisations tend to describe their cyber risk in qualitative terms, usually as red-amber-green heatmaps, that simply don’t translate into financial terms that Boards can make investment decisions on. There’s no line of sight from a cyber scenario to an innovation outcome. And that makes it a comparable grey area for Boards looking to make smart risk-based decisions.

      Instead, we would suggest that cyber risk should be treated as a financial risk and governed with the same quantitative rigour as market, credit and liquidity risk. The trick is to use scenario-based quantification tied to your firm’s actual operating model and critical business services, including third-party and concentration scenarios, output that can also be aligned to severe-but-plausible testing under DORA and other regulatory expectations.

      From there, it’s all about connecting the quantification to the innovation-related decisions it should inform, including risk appetite, control investment prioritisation and cyber insurance, in order to translate cyber exposure into financial terms that feed into enterprise risk and board reporting on a continuous basis.



      Five steps to innovate with confidence

      Based on our experience working with UK Wealth and Asset Management Boards and executives to balance cyber security and innovation, here are five key steps every Board should be taking if they want their Wealth or Asset Management firm to truly innovate with confidence.

      • Quantify your cyber risks

        Putting a financial figure on cyber exposure allows Boards to properly assess the risk/reward of their various innovation initiatives based on real and comparable metrics.

      • Understand the wider impacts

        Cyber risk doesn’t just manifest as a cost to innovation, it can also influence employee confidence, risk taking and willingness to fail which, in turn, can reduce the effectiveness of innovation investments.

      • Conduct scenario planning on cyber risks

        Make resilience testing loss-driven and executive-owned. Create severe-but-plausible scenarios against your innovation strategies, with real financial impact and named decision makers.

      • Assess the third-party risks

        As you build out your innovation ecosystem, model what a critical provider failure could actually cost you and your clients and where risks may be accumulating through supplier concentration.

      • Prepare for future innovation

        Keep tabs on potentially disruptive market events (like quantum) and start managing the risks early by, for example, creating a cryptographic bill of materials that enable smart risk-based actions to be taken alongside innovation sprints.


      Get value from your innovation investments

      We believe that the firms that will lead innovation across the sector will be those that stop treating cyber as a technical cost centre and start managing it as a quantified financial risk, governed with the same discipline as other principal risks on their balance sheet.

      Quantum, AI and digitisation create real opportunities for Wealth and Asset Managers, but they also increase the cost of getting cyber decisions wrong. The firms that can quantify cyber exposure, connect it to innovation priorities and govern it as a financial risk will be better placed to invest with confidence, move faster and protect value as cyber evolves.



      Wealth and Asset Management insights

      To receive our latest insights directly to your email, simply sign up for our wealth and asset management newsletter.


      Girl looking at the graphs and charts



      MTD

      Get in touch


      Discover why organisations across the UK trust KPMG to make the difference and how we can help you to do the same.