Global fintech and funding innovation ecosystem

Global Governance Insights on Emerging Risks

Bleu Azur Consulting | June 17, 2018

Direct and indirect costs of cyberattacks - Global Governance Insights on Emerging RisksA HEIGHTENED FOCUS ON RESPONSE AND RECOVERY

Over a third of directors of US public companies now discuss cybersecurity at every board meeting. Cyber risks are being driven onto the agenda by

  • high-profile data breaches,
  • distributed denial of services (DDoS) attacks,
  • and rising ransomware and cyber extortion attacks.

The concern about cyber risks is justified. The annual economic cost of cyber-crime is estimated at US$1.5 trillion and only about 15% of that loss is currently covered by insurance.

MMC Global Risk Center conducted research and interviews with directors from WCD to understand the scope and depth of cyber risk management discussions in the boardroom. The risk of cyberattack is a constantly evolving threat and the interviews highlighted the rising focus on resilience and recovery in boardroom cyber discussions. Approaches to cyber risks are maturing as organizations recognize them as an enterprise business risk, not just an information technology (IT) problem.

However, board focus varies significantly across industries, geographies, organization size and regulatory context. For example, business executives ranked cyberattacks among the top five risks of doing business in the Asia Pacific region but Asian organizations take 1.7 times longer than the global median to discover a breach and spend on average 47% less on information security than North American firms.

REGULATION ON THE RISE

Tightening regulatory requirements for cybersecurity and breach notification across the globe such as

  • the EU GDPR,
  • China’s new Cyber Security Law,
  • and Australia’s Privacy Amendment,

are also propelling cyber onto the board agenda. Most recently, in February 2018, the USA’s Securities and Exchange Commission (SEC) provided interpretive guidance to assist public companies in preparing disclosures about cybersecurity risks and incidents.

Regulations relating to transparency and notifications around cyber breaches drive greater discussion and awareness of cyber risks. Industries such as

  • financial services,
  • telecommunications
  • and utilities,

are subject to a large number of cyberattacks on a daily basis and have stringent regulatory requirements for cybersecurity.

See:  Bithumb $31 Million Crypto Exchange Hack: What We Know (And Don’t)

Kris Manos, Director, KeyCorp, Columbia Forest Products, and Dexter Apache Holdings, observed, “The manufacturing sector is less advanced in addressing cyber threats; the NotPetya and WannaCry attacks flagged that sector’s vulnerability and has led to a greater focus in the boardroom.” For example, the virus forced a transportation company to shut down all of its communications with customers and also within the company. It took several weeks before business was back to normal, and the loss of business was estimated to have been as high as US$300 million. Overall, it is estimated that as a result of supply chain disruptions, consumer goods manufacturers, transport and logistics companies, pharmaceutical firms and utilities reportedly suffered, in aggregate, over US$1 billion in economic losses from the NotPetya attacks. Also, as Cristina Finocchi Mahne, Director, Inwit, Italiaonline, Banco Desio, Natuzzi and Trevi Group, noted, “The focus on cyber can vary across industries depending also on their perception of their own clients’ concerns regarding privacy and data breaches.”

LESSONS LEARNED: UPDATE RESPONSE PLANS AND EVALUATE THIRD-PARTY RISK

The high-profile cyberattacks in 2017, along with new and evolving ransomware onslaughts, were learning events for many organizations. Lessons included the need to establish relationships with organizations that can assist in the event of a cyberattack, such as l

  • aw enforcement,
  • regulatory agencies and recovery service providers
  • including forensic accountants and crisis management firms.

Many boards need to increase their focus on their organization’s cyber incident response plans. A recent global survey found that only 30% of companies have a cyber response plan and a survey by the National Association of Corporate Directors (NACD) suggests that only 60% of boards have reviewed their breach response plan over the past 12 months. Kris Manos noted, “[If an attack occurs,] it’s important to be able to quickly access a response plan. This also helps demonstrate that the organization was prepared to respond effectively.”

Experienced directors emphasized the need for effective response plans alongside robust cyber risk mitigation programs to ensure resilience, as well as operational and reputation recovery. As Jan Babiak, Director, Walgreens Boots Alliance, Euromoney Institutional Investor, and Bank of Montreal, stressed, “The importance of the ’respond and recover’ phase cannot be overstated, and this focus needs to rapidly improve.”

Directors need to review how the organization will communicate and report breaches. Response plans should include preliminary drafts of communications to all stakeholders including customers, suppliers, regulators, employees, the board, shareholders, and even the general public. The plan should also consider legal requirements around timelines to report breaches so the organization is not hit with financial penalties that can add to an already expensive and reputationally damaging situation. Finally, the response plan also needs to consider that normal methods of communication (websites, email, etc.) may be casualties of the breach. A cyber response plan housed only on the corporate network may be of little use in a ransomware attack.

Other lessons included the need to focus on cyber risks posed by third-party suppliers, vendors and other impacts throughout the supply chain. Shirley Daniel, Director, American Savings Bank, and Pacific Asian Management Institute, noted, “Such events highlight vulnerability beyond your organization’s control and are raising the focus on IT security throughout the supply chain.” Survey data suggests that about a third of organizations do not assess the cyber risk of vendors and suppliers. This is a critical area of focus as third-party service providers (e.g., software providers, cloud services providers, etc.) are increasingly embedded in value chains.

More:  The growing cost of cybersecurity

FRUSTRATIONS WITH OVERSIGHT

Most directors expressed frustrations and challenges with cyber risk oversight even though the topic is frequently on meeting agendas. Part of the challenge is that director-level cyber experts are thin on the ground; most boards have only one individual serving as the “tech” or “cyber” person. A Spencer Stuart survey found that 41% of respondents said their board had at least one director with cyber expertise, with an additional 7% who are in the process of recruiting one. Boards would benefit from the addition of experienced individuals who can identify the connections between cybersecurity and overall company strategy.

A crucial additional challenge is obtaining clarity on the organization’s overall cyber risk management framework. (See Exhibit 1: Boards Need More Information on Cyber Investments.) Olga Botero, Director, Evertec, Inc., and Founding Partner, C&S Customers and Strategy, observed, “There are still many questions unanswered for boards, including:

  • How good is our security program?
  • How do we compare to peers?

There is a big lack of benchmarking on practices.” Anastassia Lauterbach, Director, Dun & Bradstreet, and member of Evolution Partners Advisory Board, summarized it well, “Boards need a set of KPIs for cybersecurity highlighting their company’s

  • unique business model,
  • legacy IT,
  • supplier and partner relationships,
  • and geographical scope.”

Nearly a quarter of boards are dissatisfied with the quality of management-provided information related to cybersecurity because of insufficient transparency, inability to benchmark and difficulty of interpretation.

EFFECTIVE OVERSIGHT IS BUILT ON A COMPREHENSIVE CYBER RISK MANAGEMENT FRAMEWORK

Organizations are maturing from a “harden the shell” approach to a protocol based on understanding and protecting core assets and optimizing resources. This includes the application of risk disciplines to assess and manage risk, including quantification and analytics. (See Exhibit 2: Focus Areas of a Comprehensive Cyber Risk Management Framework.) Quantification shifts the conversation from a technical discussion about threat vectors and system vulnerabilities to one focused on maximizing the return on an organization’s cyber spending and lowering its total cost of risk.

Cyber risk management process - Global Governance Insights on Emerging Risks

See:  FSB warns of third-party FinTech risk

Directors also emphasized the need to embed the process in an overall cyber risk management framework and culture. “The culture must emphasize openness and learning from mistakes. Culture and cyber risk oversight go hand in hand,” said Anastassia Lauterbach. Employees should be encouraged to flag and highlight potential cyber incidents, such as phishing attacks, as every employee plays a vital role in cyber risk management. Jan Babiak noted, “If every person in the organization doesn’t view themselves as a human firewall, you have a soft underbelly.” Mary Beth Vitale, Director, GEHA and CoBiz Financial, Inc., also noted, “Much of cyber risk mitigation is related to good housekeeping such as timely patching of servers and ongoing employee training and alertness.”

Boards also need to be alert. “Our board undertakes the same cybersecurity training as employees,” noted Wendy Webb, Director, ABM Industries. Other boards are putting cyber updates and visits to security centers on board “offsite” agendas.

Continue to the full article --> here

 

Click for News:

latest news - Global Governance Insights on Emerging Risks

 

Crypto Regulation | April 15, 2025 Trump Repeals IRS Crypto Reporting Rule. Here's Why Fintechs in Canada Should Pay Attention On April 10, 2025, U.S. President Trump signed a bill cancelling a key IRS crypto reporting rule that would have required decentralized finance (DeFi) platforms to report customer transactions to the tax agency. See:  UK FCA Plans Full Crypto Licensing Regime by 2026 The IRS' rule was called "Gross Proceeds Reporting by Brokers That Regularly Provide Services Effectuating Digital Asset Sales", which expanded the scope of traditional broker definitions to include DeFi apps like Uniswap and Metamask, and had an effective date of February 28, 2025.  However, the IRS provided a transition period given the reporting complexities involved, so the rule was set to apply to digital asset sales occurring after January 1, 2027.  But with Trump's bill nullifying the IRS rule, the implementation is now cancelled and the rule is officially gone. What does this mean for fintechs, crypto startups, and regulators in Canada? What Changed? The IRS crypto reporting rule was part of a broader push to increase tax compliance among crypto users but industry argued that it wasn't manageable because DeFi platforms don't control their user's data.  ...
Freepik cancelled - Global Governance Insights on Emerging Risks
Markets and Economy | April 15, 2025 Jamie Dimon’s 2024 Letter Outlines Global Risks and Advice for Leaders On April 7 2025, CEO Jamie Dimon of JPMorgan Chase published his annual 2024 letter to shareholders (58 page PDF), which is widely read by business and policy leaders around the globe.  This year's edition, his messages are especially urgent.  He describes a world of rising risks, and big decisions ahead with profound implications that stretch beyond simply Wall Street.  Below are 5 insights that fintech founders, investors and Canadian decision makers need to know: 1. The U.S. Dollar’s Strength is At Risk “History has shown that as countries become weaker, their currency loses reserve currency status.” Dimon issued a clear warning that's rarely said out loud by execs of America’s biggest banks.  That is the U.S. dollar’s global dominance is fading because it's strength relies on TRUST in U.S. institutions, alliances, and policy, BUT that trust is now eroding. Last week, the U.S. dollar dropped significantly reaching a 3 year low against major global currencies.  The decline is largely due to the Trump administration's escalating tariffs and trade tensions on imports from several countries, such as China, Canada and European nations.  ...
Jamie Dimon Chairman and CEO JP Morgan Chase - Global Governance Insights on Emerging Risks
Financing | April 14, 2025 Plaid’s $575 Million Series D Signals a Deeper Strategy in Fintech Data and Embedded AI Financial infrastructure provider, Plaid, announced on April 3 2025, that they raised $575 million Series D at a valuation of $6.1 billion valuation led by Frank Templeton, BlackRock, Fidelity, and others including existing investors such as NEA and Ribbit Capital.  While the valuation is significantly lower than it's 2021 peak of $13.4 billion, Plaid's latest round is a story of consolidation of it's role at the heart of embedded finance, and not of decline. Plaid is a backbone of embedded finance with a footprint that spans more than 8,000 apps, including many widely used fintech tools and providers in Canada and the U.S.  For Canadian fintech companies, this raise hints at where industry is heading and who will control its most critical pipes. A Profitable Platform in a Tough Market Unlike most fintech firms still chasing break-even, Plaid finished off 2024 with positive operating margins, strong ash flows and a 25% yoy revenue increase.  In Plaid's letter to shareholders, 2025, CEO and Cofounder Zach Perret explained that it has a usage based billing model where Plaid earns revenue when an ...
Freepik pawns consolidation - Global Governance Insights on Emerging Risks
Leadership | April 14, 2025 Why Embracing Uncertainty Can Help Founders Gain Insight (During Chaos) In an economic climate where geopolitical tensions are high and markets volatile with inflation spikes and policy u-turns, founders and innovators that embrace uncertainty can gain an edge.  Uncertainty isn't a side effect of innovation, it's the starting line.  Inspired from Deepak Chopra's recent article on the power of uncertainty, this article looks at the impact of embracing the unknown and how it can sharpen decision-making, unlock creativity, and help build resilience during times of rapid change and uncertainty. Key Actionable Insights 1. Uncertainty Isn't the Enemy...It's the Edge Chopra argues that trying to eliminate uncertainty kills creativity.  When everything is 'the exact same', it breeds complacency.  We've all experienced this.  During some routine periods, a founder may feel that time is passing by very quickly.  Yet during times of great change, novelty, innovation, a founder may feel that time is going by slowly.  Fintech leaders who stay agile during times of ambiguity can separate themselves from those who stall in the face of uncertainty.  Put differently, successful founders don't just survive during chaos, they scan for signals of change/chaos that others can miss, often ...
Freepik rawpixel.com mental fitness and resilience - Global Governance Insights on Emerging Risks
April 14, 2025 If you’re running a crowdfunding campaign, visibility is key. Without the right SEO strategy, potential backers may never find your project. Below is a practical, research-backed guide to improving your campaign’s visibility through SEO. 1. Understand Your Audience First Start by knowing who you’re targeting. This helps shape your keywords, content, and messaging. Build a profile of your ideal backer Use keyword research tools like Google Trends or Ahrefs Read forum discussions and questions from your audience The more specific your understanding, the more relevant your content becomes. 2. Focus on Search Intent, Not Just Keywords Group your keywords based on what users are looking to do: Informational: “how to launch a crowdfunding campaign” Transactional: “support [campaign name]” Navigational: “[brand name] Kickstarter page” Use these keywords naturally in: Headings and subheadings Meta descriptions Blog updates and campaign FAQs Image alt text Write for people first, then optimise for search engines. For more insight into how keyword strategy aligns with intent and structure, consider following this website, which outlines foundational SEO practices that support long-term visibility. 3. Build a High-Converting, SEO-Friendly Landing Page Don’t treat your landing page as just a pitch. Make it SEO-ready: Clear, keyword-rich headline ...
Pexels Tobias Dziuba SEO - Global Governance Insights on Emerging Risks
Financing | April 11, 2025 OneVest Secures $20M in Series B to Build the Future of WealthTech in North America On January 29, 2025, Calgary and Toronto-based fintech firm OneVest announced the close of a $20 million Series B round, led by Salesforce Ventures and joined by Allianz Life Ventures, TIAA Ventures, and returning backers like OMERS Ventures, Deloitte Ventures, Fin Capital, Luge Capital, and Pivot Investment Partners. See:  OneVest’s Rapid Expansion Powered by a $17M Funding Round led by OMERS Ventures OneVest estimates that $84 trillion of wealth will be passed down from Baby Boomers to Gen X and Millennials over the coming decades, creating a massive opportunity and challenge for financial institutions. OneVest's platform is positioned to offer financial institutions, such as banks, insurers, asset managers and RIAs, a module tech platform to build or upgrade their wealth management services.  Companies ca upgrade outdated infrastructure by plugging in only the components they need, reducing time and cost to market. Amar Ahluwalia, CEO of OneVest: “We are tackling massive challenges in an industry that’s been traditionally slow to adopt new technologies. Having such esteemed investors solidifies our position to reimagine wealth management technology for enterprises across the U.S. and ...
Freepik wealth management tech - Global Governance Insights on Emerging Risks
Regulation | April 10, 2025 SEC Says Some Fully Backed, Payment-Only 'Covered Stablecoins' Aren’t Securities On April 4, 2025, the U.S. Securities and Exchange Commission (SEC) issued a statement that clarified some U.S. dollar-backed stablecoins may not be considered securities.  While the statement was welcomed and creates some breathing room for crypto and fintech projects, the announcement ignited an internal debate at the SEC and many are wondering what's next. Covered Stablecoins The SEC said certain U.S. dollar-backed stablecoins (referred to as 'Covered Stablecoins') are not considered securities if they have all of the following characteristics: Stablecoin must maintain a 1:1 fixed value equal to the U.S. dollar, without fluctuations Each stablecoin must be fully backed by an equivalent amount of high quality assets such as U.S. Treasury bills, cash, or cash equivalents that can be redeemed on demand. These assets must be held in custody and verified regularly No expectation of profit - cannot be promoted as an investment or marketed in a way that leads buyers to expect profit from simply holding the token See:  U.S. Senate Moves to Regulate Stablecoins No voting rights, control over the issuer, or shares in any profit or management decisions (no governance) ...
Freepik Covered stablecoins versus other stablecoins - Global Governance Insights on Emerging Risks
Funding | April 10, 2025 Regulation Crowdfunding Markets Show Tariffs Straining Innovation Economy Regulation Crowdfunding (RegCF) has proven to be a resilient market for early stage entrepreneurs and investors alike.  When uncertainty strikes, it's often traditional venture capital that pulls back, while the community-driven model continues to offer early stage start-ups access to capital allowing them to innovate.  However, just in from Sherwood (Woodie) Neiss, NCFA Advisor and Principal at Crowdfund Capital Advisors, data shows that tariffs are starting to strain RegCF markets - from March 10 to April 9, 2025: RegCF investment volumes declined by 24% (yoy) to just $57.48 million New campaign launches dropped over 40% Number of investor checks also declined by 15% Average capital raise size dropped to $720,000 (from $1.2 million) Sherwood Neiss, Principal at Crowdfund Capital Advisors: “We’re seeing the first real signs of pullback in what has otherwise been a resilient funding ecosystem.  The numbers tell a story not of panic, but of pause. Investors and issuers alike are waiting for clarity—on costs, on policy, and on risk.” Tariffs Introduce New Risks for Early-Stage Companies In a volatile environment where U.S. tariffs are levied one day, and then paused the next, founders must now face ...
Freepik rawpixel.com risk - Global Governance Insights on Emerging Risks
Economy | April 10, 2025 Trump Temporarily Halts Tariffs for Most Countries But Keeps Pressure on Canada, Mexico, and China On April 10, 2025, President Trump announced a 90-day pause on most of the newly implemented global trade tariffs after market backlash and political pressure.  The break was extended to countries in Europe, Asia, and parts of South America, but Canada, Mexico, and China are still under tariff pressure. Strategic Pause, Not for Everyone While Trump paused the most recent tariffs for over 75 countries, U.S. tariffs still apply to Canada and Mexico primarily on cars and auto parts (25%), steel (25%), aluminum (10%), and some agricultural products like dairy, grains, and processed foods, and continue to affect cross border trade in manufacturing and farming sectors. Trump's pause also didn't apply to China  In fact, Tariffs on Chinese good were raised to 125%, as China hit back with an 84% tariff on U.S. goods and filed new complaints with the World Trade Organization. See:  Klarna Delays IPO As Markets React to Trump’s Tariffs After the tariff pause was announced, markets surged with the S&P 500 exploding 9.5%, the largest one day gain since World War II, according to Business Insider ...
Freepik tawatchai07 shipping containers - Global Governance Insights on Emerging Risks
Funding | April 9, 2025 Toronto’s Tailscale Secures $230M and $2B Valuation for Identity-First Networking On April 8 2025, Toronto-based Tailscale announced that they raised $230 million CAD Series C (about $160 million USD), valuing the company at approx $2 billion CAD.  The round was made up of U.S. investors, led by Accel, CRV, Insight Partners, Heavybit, and Uncork Capital, along with some prominent individual investors notably George Kurtz CEO of CrowdStrike (returning investor) and Anthony Casalena CEO of Squarespace.  New funds will be used to grow product and engineering teams, expand globally, and improved support for fast scaling customers. Tailscale - A Shift from IP Addresses to Identity Tailscale was founded in 2019 by former Google engineers Avery Pennarun, David Crawshaw, David Carney, and Brad Fitzpatrick, and officially launched in April 2020 to help users connect devices and apps securely without relying on traditional VPNs, IP rules, or firewalls. Tailscale uses a technology called WireGuard which is easy to setup and lets devices connect directly to each other, safely and privately.  What's unique about Tailscale is its approach to solving networking challenges.  Instead of relying on where a device is located (IP address), it focuses on who or what is connecting. This ...
Tailscale 160 million series C - Global Governance Insights on Emerging Risks

 


NCFA Jan 2018 resize - Global Governance Insights on Emerging RisksThe National Crowdfunding & Fintech Association of Canada (NCFA Canada) is a cross-Canada non-profit actively engaged with cryptocurrency, blockchain, crowdfunding, alternative finance, fintech, P2P, ICO, STO, and online investing stakeholders globally. NCFA Canada provides education, research, industry stewardship, services, and networking opportunities to thousands of members and subscribers and works closely with industry, government, academia, community and eco-system partners and affiliates to create a strong and vibrant crowdfunding and fintech industry. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: ncfacanada.org

Leave a Reply

Your email address will not be published. Required fields are marked *

sixteen − 9 =