Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk Management Program · CoreTrack
1Risk, Treasury & Financial Control
iRisk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
iiEnterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
iiiRisk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
ivCredit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
vMarket Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
viLiquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
viiOperational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
viiiRisk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
ixTreasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
xFinancial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
xiOperational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

Cyber Risk vs Third Party Risk: Two Categories, One Overlap

Cyber risk and third party risk are not two versions of one idea. Cyber risk is a property of a threat, meaning somebody acting deliberately against systems and data. Third party risk is a property of a relationship, meaning something the institution depends on being run by somebody else. Neither is one of the seven event categories. Both cut across all seven, and a single incident can be either, both or neither.

Two words turn up on the same slide in almost every operational risk pack written anywhere, usually joined by an and, and the joining is where the trouble starts. On a close reading they are not parallel at all. One of them describes a kind of threat. The other describes a kind of arrangement. Both can be held in mind at once about the same event, and they yield two different, both correct, answers. A definition written against a contrast tends to describe the contrast rather than the subject. So each of the two is defined completely on its own below, with the other kept out of the room, before any comparison begins.

Vindhya Commercial Bank Limited, an invented mid-sized Indian commercial bank, supplies every incident, figure, committee and policy number worked below. Its record for the twelve numbered months of this case carries thirteen operational risk incidents, numbered I1 to I13, and five near misses, numbered N1 to N5. A distinction that cannot sort a real list of events is not a distinction, it is a preference. The bank's record is where both words get tested.

What is cyber risk actually a property of?

A front door shows the shape of the idea, and that shape is the same at every scale. A household worries about somebody trying the lock. The household does not worry equally about every bad thing that could happen to the house. A pipe bursting is bad, a power cut is bad, and neither of them involves anybody wanting anything from the household. Somebody trying the lock is a different species of problem. There is a person on the other end, choosing, adapting and trying again when the first attempt fails. A separate species is marked out not by the door and not by the loss, but by an intent that responds to whatever the household does.

Cyber riskThe risk of somebody acting deliberately against an institution's systems and data. is the risk of somebody acting deliberately against an institution's systems and data. Each of the three pieces carries weight, and dropping any of them produces a definition that sorts events wrongly. Take that sentence apart into its three pieces.

The first piece is the actor. There is one. Something has to be done by somebody. The requirement of an actor is what separates cyber risk from a disk that simply stops or a cable cut by a road crew. The second piece is the intent, and the word deliberately is doing all the work. An employee who fat-fingers a payment file has caused a failure of the same systems, and it is not this. The third piece is the object, and the object is systems and data rather than money, buildings or people. The money that eventually leaves is a consequence. Money leaves through a payment line like any other loss, so an exposure defined by the money will never be found in a record.

The definition leaves out as much as it puts in, and the omissions matter just as much. The definition names no method, no tool, no technique and no channel. How anything works technically belongs to a different subject, and an exposure with its controls is a different conversation again. The definition also does not say the actor is outside. At this invented bank, near miss N5 is a privileged access account belonging to somebody who had left. The account stayed live for 46 days and was found by the access review before it was used. Nobody used it. So the record shows a route that existed and no deliberate act at all. A route is exposure and an act is an event, and the difference is worth holding on to. Registers that have merged the two carry the route as though it were a loss. The loss the route was meant to describe then sits under no line of its own.

If the actor is somebody else and the intent is not the institution's to choose, what can the institution act on? Only its own side. Its own defences, its own arrangement of who can reach what, its own detection. The institution cannot reduce the number of people in the world who would like to get in, and it cannot negotiate with them. Cyber risk is therefore an exposure the institution can only shrink from its own side of the door, and every control it has is a statement about itself rather than about the threat. Nothing in that account requires a supplier, a contract or an outsourcing arrangement. The absence is the first sign that the second word asks a different question.

CYBER RISK, DEFINED ON ITS OWN TERMS A property of a threat. Read all three parts before comparing it with anything else. PART ONE THE ACTOR Somebody, not something. A person is choosing, and will try again when the first attempt fails. Not this: a disk that stops. PART TWO THE INTENT Deliberate, not accidental. The act is aimed. That is what makes the exposure adapt to the controls. Not this: a mistyped file. PART THREE THE OBJECT Systems and data, not the money. Money leaving is a consequence, and it leaves by an ordinary route. Not this: a fall in a price. WHAT THE INSTITUTION CAN ACT ON, AND IT IS ONLY ITS OWN SIDE Its own defences. Its own arrangement of who can reach what. Its own detection. It cannot reduce how many people in the world would like to get in, and it cannot negotiate with any of them. Every control it holds is a statement about itself.
Cyber risk resolves into an actor, an intent and an object, and dropping any one of the three produces a definition that sorts a real loss record wrongly.
Derivatives Foundation Bootcamp — Fin Maverick

What is third party risk actually a property of?

Now put the door away entirely and think about a wedding. The household is not cooking. A caterer was chosen after two others were considered, a price was agreed, a menu was written down, and on the day four hundred people will eat food that nobody in the household has ever cooked. Nothing about that involves anybody acting against the household. The caterer wants the evening to go well, has every reason to want it, and may still turn up ninety minutes late because a van broke down. The guests will experience the lateness. The exposure exists not because anybody meant harm but because the doing of the thing sits in somebody else's hands, and the household kept every consequence while handing over the doing.

Third party riskThe risk arising because something the institution depends on is run by somebody it contracted with. is the risk arising because something the institution depends on is run by somebody it contracted with. Take this one apart too. Its three pieces are completely different from the previous three.

The first piece is dependence. The institution needs the thing. If it could shrug and carry on, there is no exposure worth a policy. The second piece is the contract, and it is what makes the other side a third party rather than merely somebody in the world. Somebody was selected, terms were agreed, and an obligation runs in both directions. The third piece is the location of the doing. The activity happens on the other side of that contract, on somebody else's premises, by somebody else's people, on somebody else's arrangements, and the institution watches rather than operates.

The word for the arrangement, when the activity is one the institution would otherwise have done itself, is outsourcingAn arrangement under which an activity the institution would otherwise do itself is performed by somebody else under contract.. Not every third party arrangement is an outsourcing and the difference matters to whoever writes the policy, but the exposure has the same shape either way.

So what can the institution act on in a relationship? Something completely different from the previous list, and it is worth writing out because people reach for the contract and stop. The institution can choose who to contract with in the first place, and that is the single most powerful lever on the list and the only one that operates before anything has gone wrong. Second, it can write terms, including a right to auditA contract term letting the institution examine how the other side actually operates, without which monitoring is a set of assertions., without which its monitoring is a folder of assertions somebody else wrote. Third, it can monitor what actually happens against what was agreed. And it can arrange an exitThe arrangement for taking an activity back or moving it elsewhere, which is the only real limit on what a supplier can charge or withhold., meaning a worked-out way of taking the activity back or moving it. The exit is the only real limit on what the other side can eventually charge or withhold.

One more property belongs to this side and to no other, and it is the one that cannot be fixed by any single institution. If a great many institutions depend on the same provider for the same activity, each of them individually holds a sensible contract and collectively they hold something none of them chose. The exposure they hold collectively is concentration in a supplierThe exposure created when many institutions depend on the same provider, which no single contract can reduce., and the exposure lives in the pattern rather than in any one relationship, so no clause any one of them signs reduces it by a rupee. The wedding version is that every caterer in the district uses the same two ice suppliers, and how carefully the caterer was chosen makes no difference.

THIRD PARTY RISK, DEFINED ON ITS OWN TERMS A property of a relationship. Nobody in this picture is acting against anybody. ONE THE INSTITUTION Depends on the thing. Cannot shrug and carry on without it. Keeps the consequence. TWO THE CONTRACT Somebody was chosen. Terms were agreed. Obligations run both ways along this line. THREE THE SUPPLIER Runs the activity, on its own premises, with its own people. Holds the doing. FOUR THE CUSTOMER Meets the service and never meets the chain behind it. WHAT THE INSTITUTION CAN ACT ON, AND THE FIRST ONE IS THE STRONGEST SELECTION before anything has gone wrong CONTRACT TERMS including a right to examine the operation MONITORING what happens against what was agreed EXIT a worked-out way of taking the thing back The doing moved along the chain. The consequence did not move at all. And if many institutions choose the same supplier, no single contract touches that.
Third party risk resolves into dependence, a contract and the doing sitting elsewhere, and the institution acts through selection, terms, monitoring and exit rather than through defences.
Try it out

Both are now defined. Without looking back: what is cyber risk a property of, and what is third party risk a property of?

Where do the two questions meet in one incident?

Two complete definitions are now on the table and neither of them was written against the other. Independence is what makes an honest overlap findable, and this invented bank has exactly one incident sitting in it.

Incident I9 fell in month 9. A payment gateway hosted by an outside provider failed for 9 hours and 48,000 transactions failed with it. The gross loss was Rs 4.4 crore, Rs 1.2 crore came back from the provider, and the net loss was Rs 3.2 crore. The provider has no name in the record and is not modelled on anybody. The incident was filed in category 6, business disruption and system failures.

Run the relationship definition over it first. Did the bank depend on the thing? Yes, 48,000 transactions say so. Was it run by somebody the bank contracted with? Yes, and the Rs 1.2 crore that came back proves a contract existed with money terms in it. Was the doing on the other side of that contract? Yes. So the answer to the third party question is a clean yes on the record's own facts, with nothing added.

Running the threat definition over the same incident asks two questions. Was there an actor? Was there intent? The record says the gateway failed. The record says how long, how many transactions, what it cost and what came back. The record does not say why it failed, and a reason nobody wrote down cannot be supplied afterwards. Nothing in this case labels incident I9 an attack, and nothing in it rules an attack out either.

So what is the honest entry? Not cyber. Not not-cyber. The honest entry is a third party event whose cause is unrecorded. A reader who finds that unsatisfying has understood it correctly. The entry is unsatisfying and it is still the only one the record supports. Filing it as cyber invents a cause. Ruling cyber out invents the absence of one. Both are the same error wearing opposite signs. Ruling cyber out is the more comfortable of the two, and comfort is exactly what makes it the more dangerous. Nobody goes back to challenge a classification that made a problem look smaller.

The missing fact has a consequence for the whole distinction. One fact that nobody wrote down decides whether this single incident belongs to one lens, to both, or to one and not the other. If cyber and third party were two versions of the same idea, the classification would come out the same either way, and a missing fact could not do that. The missing fact only bites because two genuinely different questions are being asked of one event. The incident that resists the sort is the strongest evidence that the sort is real.

ONE INCIDENT, BOTH DEFINITIONS RUN OVER IT SEPARATELY Incident I9 at the invented bank. Every figure below is the bank's own and invented. WHAT THE RECORD ACTUALLY SAYS, IN FULL Month 9, category 6. A payment gateway hosted by an outside provider failed for 9 hours and 48,000 transactions failed. Gross Rs 4.4 crore, Rs 1.2 crore recovered from the provider, net Rs 3.2 crore. The provider is unnamed and invented. No cause is stated. THE RELATIONSHIP QUESTION Is the thing run by somebody else? YES Dependence: 48,000 transactions say so. Contract: the Rs 1.2 crore that came back proves one existed, with money terms in it. Doing: on the far side of that contract. THE THREAT QUESTION Was somebody acting deliberately? THE RECORD DOES NOT SAY Actor: not stated. Intent: not stated. The row holds duration, count and money. It holds no cause at all, so filing it as cyber and ruling cyber out both invent one. THE HONEST ENTRY: A THIRD PARTY EVENT WHOSE CAUSE IS UNRECORDED
Incident I9 answers the relationship question yes on the record's own facts and leaves the threat question unanswerable, because no cause was ever written down.
Try it out

Was incident I9 a cyber event?

Debt Capital Markets Bootcamp — Fin Maverick

What separates them once both are on the table?

Definitions are cheap and sorting is expensive, so the test of a distinction is whether somebody with no interest in the argument can apply it to a real event and reach the same answer. Applying a distinction needs criteria written down. Six criteria do the work, numbered CT1 to CT6 so that a row can be named rather than restated each time. The six are this invented bank's own working set, and no supervisor requires any of them.

CT1 is the object, meaning the thing the exposure is about. On the threat side it is systems and data. On the relationship side it is a dependency, meaning something the institution needs which happens to be run on the far side of a contract. Systems and data on one side and a dependency on the other are not two levels of one thing. One of them is a possession, the other is an arrangement.

CT2 is the actor. On the threat side there is somebody working against the institution who adapts when blocked. An adapting opponent is why controls on that side have to be renewed rather than installed. On the relationship side there is a counterparty behaving perfectly normally who fails, or is late, or goes out of business, and nobody meant anything by any of it. The van broke down. A control designed for an opponent and a control designed for an ordinary failure are not the same control, and this is the row that decides which one is needed.

CT3 is what the institution actually controls, and this is where practitioners split most often. On the threat side there is one lever with several handles: the institution's own side of the door. On the relationship side there are four levers, and they arrive in a sequence that matters more than the list suggests. Selection comes first and is the only one that operates before anything has gone wrong. Contract terms come second. Monitoring is third and is only as real as the right to look. Exit is fourth and is the quiet one that governs the other three. A relationship that cannot be left is a relationship whose terms will drift. Notice that no lever on the relationship side is a defence and no lever on the threat side is a contract. The mismatch of levers is by itself enough to show the two exposures are not versions of each other.

CT4 is where each one shows up in the loss record, and the answer for both is the same and is surprising enough that the next section is given over to it entirely: neither has a category of its own.

CT5 is which policy carries it. At this invented bank the answer is policy PL7, information security, on one side and policy PL8, outsourcing and third party, on the other. Two documents. Two owners. Two review cycles. A reader who thinks the two exposures are versions of each other has to explain why this bank wrote them up twice.

CT6 is which committee sees it, and here the invented record produces an asymmetry rather than a pair. Committee G8, the information security committee, has six members, meets quarterly and reports into committee G6 rather than into the board. For outsourcing and third party arrangements, the record names policy PL8 and names no committee at all. The missing committee is a fact about this invented case rather than an omission, and it stays visible.

SIX CRITERIA, CT1 TO CT6, LAID AGAINST BOTH The invented bank's own working set. Every row gives two different answers. CRITERION CYBER RISK THIRD PARTY RISK CT1 THE OBJECT what the exposure is about Systems and data. The money is a consequence, not the object. A dependency. Something needed, run on the far side of a contract. CT2 THE ACTOR who is on the other end Somebody acting against the bank, who adapts when blocked. A counterparty acting normally and failing. Nobody meant it. CT3 WHAT IS HELD the levers available The bank's own defences, its map of access, its own detection. One lever, several handles. Selection, contract terms, monitoring, exit. Four levers, and the first one runs first. CT4 WHERE IT SHOWS its place in the record No category of its own. Incident I7 is filed in category 2. No category of its own. Incident I9 is filed in category 6. CT5 WHICH POLICY which document reaches it Policy PL7, information security. Its own owner, its own cycle. Policy PL8, outsourcing and third party. A separate document. CT6 WHICH TABLE who receives the reporting Committee G8. Six members, quarterly, reporting into committee G6, not the board. The record names none at all. Policy PL8 has no stated recipient, and that is a finding. All six criteria, both policies and both committee facts belong to the invented bank. None is a requirement from any authority.
On all six criteria the two exposures give different answers, and the last row shows one lens with a committee and the other with a policy and no stated recipient.
Try it out

Which committee at this invented bank receives information security, and which receives outsourcing and third party?

Common Size and Trend Analysis — free micro-course from Fin Maverick

Which of the seven event categories does each one live in?

One question catches almost everybody, and the answer changes what somebody has to do on a Monday morning, so it is worth setting up properly. Suppose the chief risk officer asks for this bank's total cyber losses for the year. Which column gets added up?

The loss record is sorted into seven event categories. The seven categories are the Basel Committee's, published at the Bank for International Settlements: internal fraud, external fraud, employment practices and workplace safety, clients products and business practices, damage to physical assets, business disruption and system failures, and execution delivery and process management. Every one of the bank's thirteen incidents sits in exactly one of them, and the seven together account for the year's Rs 43.8 crore of net loss with nothing left over.

Now look for cyber on that list. Cyber is not there. Look for third party. Also not there. The absence is not an oversight in the scheme, it is the scheme working as intended: the seven categories sort events by what kind of failure produced them, not by what kind of exposure they came out of. Neither cyber nor third party is an event category, so neither one has a column and neither one has a total that can be read off anything.

Both of them are instead a lensA way of cutting a loss record that is not one of its categories, so its total has to be built by reading rather than by summing a column.: a way of cutting the record that is not one of its categories. A lens crosses the categories rather than living inside one. At this invented bank, incident I7, a phishing campaign against internet banking customers that reached 312 customers, sits in category 2, external fraud. Incident I9, the gateway outage, sits in category 6, business disruption and system failures. Two events that a threat lens and a relationship lens each pick up, filed two categories apart. The categories are answering a third question altogether.

The practical consequence is a piece of work, and it is worth naming as work rather than as a definition. Any total for either lens has to be built by reading the incidents one by one and deciding, event by event, whether the lens catches it. Reading thirteen incidents one by one is somebody's afternoon. The reading produces a number nobody can reproduce unless the rule behind it is written down alongside. And it is exactly why the merged heading is so attractive and so destructive: merging looks like it saves the afternoon, and what it actually does is delete both answers.

SEVEN CATEGORIES. NEITHER LENS IS ONE OF THEM. Category labels are the Basel Committee's, named and not taught. The incidents are the invented bank's. 1 internal fraud I5, I13 2 external fraud I1, I7 3 employment practices and workplace safety I11 4 clients, products and business practices I4, I12 5 damage to physical assets I8 6 business disruption and system failures I3, I9 7 execution, delivery and process management I2, I6, I10 THE THREAT LENS Not a category. Cuts across all seven. Incident I7 is filed in category 2. Near miss N5 is filed in no category at all, because it cost nothing and is not a loss. No column to sum. Build it by reading. THE RELATIONSHIP LENS Not a category. Cuts across all seven. Incident I9 is filed in category 6, two categories away from incident I7, because the categories answer a third question. No column to sum. Build it by reading. Thirteen incidents, 2 + 2 + 1 + 2 + 1 + 2 + 3 = 13, and the seven category net losses add to the year's Rs 43.8 crore at this invented bank.
Neither lens is one of the seven categories, so each one cuts across all of them and a total for either has to be built by reading rather than summed.
Try it out

The chief risk officer asks for this invented bank's total cyber losses for the year. Which of the seven categories should be summed?

Common Size and Trend Analysis teaches you to make three years of statements comparable and see what moved.

Which incidents in this record are one, which are the other, and which are both?

Sorting a real list is the exercise that makes a distinction stick, and it is also the exercise that exposes the places where a distinction runs out. Both things happen here, so read the sort and then read what does not sort.

On the threat side with no relationship in it, the clearest case is incident I7. In month 7 a phishing campaign against internet banking customers reached 312 customers, who were reimbursed. Gross Rs 1.8 crore, Rs 0.3 crore recovered, net Rs 1.5 crore, filed in category 2, external fraud. Somebody acted deliberately. Nobody the bank contracted with is anywhere in the event. Beside it sits near miss N5 from month 10, the privileged access account belonging to a leaver that stayed live 46 days and was found by the access review before it was used. Near miss N5 produced no loss, appears in no loss record and belongs to no category. A route that existed and was never travelled is treated exactly that way.

On the relationship side with no threat in it, the record gives incident I9 and nothing else. No other incident in the thirteen turns on something a supplier failed to do. One relationship event in thirteen is not a comforting finding. The record states no inventory of suppliers at all, so the count measures what was written down rather than what the bank depends on. A single sighting is a sighting and never a population.

Incident I4 deserves naming here precisely because it looks like a relationship event and is not one. In month 4 a third party insurance product was sold to 1,840 customers without the disclosure the bank's own procedure required, and premiums were refunded: gross Rs 5.2 crore, net Rs 5.2 crore, filed in category 4. A third party is unmistakably present. But nothing the third party did or failed to do caused the loss. The bank's own disclosure step was not performed. Test it against the definition rather than against the vocabulary. The exposure has to arise because the activity is run by somebody else, and the activity that failed here was run by the bank. So the presence of a supplier in a story is not the test, and anybody sorting on the word rather than on the definition will file this one wrongly.

And now the two events that genuinely resist the sort. Both resist for the same reason, and that reason is worth more than the sort itself. Incident I9 resists on the threat side: the record states a duration, a transaction count and three money columns, and states no cause, so it cannot be placed. Incident I1 resists on the same side. In month 1, card-not-present fraud on the debit card portfolio cost the bank Rs 6.4 crore gross, Rs 1.6 crore came back and the net loss was Rs 4.8 crore, and it is filed in category 2, the same category as incident I7. Card-not-present fraud is a fraud, so somebody acted deliberately, and it was worked remotely rather than over a counter. The threat lens actually asks whether the deliberate act reached the bank through its systems and data. Incident I1's entry does not say. The record simply never made that classification. Nothing in this case labels any incident cyber, so every cyber number in this guide is a reading of the record and never a fact about it.

THE RECORD SORTED: ONE, THE OTHER, AND BOTH Thirteen incidents and five near misses at the invented bank. Every figure is the bank's own. THE THREAT LENS REACHES THIS FAR THE RELATIONSHIP LENS REACHES THIS FAR THREAT LENS ONLY INCIDENT I7 month 7, category 2, external fraud phishing reaching 312 customers Rs 1.8 crore gross, Rs 1.5 crore net NEAR MISS N5 month 10, no category at all privileged access live 46 days found before use, so no loss INCIDENT I1 ON A WIDE READING ONLY month 1, category 2, card-not- present fraud, Rs 4.8 crore net the record does not place it BOTH LENSES MEET HERE INCIDENT I9 month 9, category 6, disruption gateway run by an outside provider 9 hours, 48,000 failed, Rs 3.2 cr net RELATIONSHIP: YES THREAT: NOT RECORDED The cause was never written down, so it is settled neither way and files it as a relationship event whose cause is unrecorded. RELATIONSHIP LENS ONLY THE RECORD SHOWS NONE AT ALL No other incident in the thirteen turns on a supplier failing, and the case states no supplier inventory at all. AND NOT INCIDENT I4 A third party product was sold to 1,840 customers, and what failed was the bank's own disclosure step. Rs 5.2 crore net, category 4. TWO INCIDENTS RESIST THE SORT, AND BOTH RESIST IT FOR THE SAME REASON Incident I9: the record states duration, count and money, and states no cause. Incident I1: a deliberate remote fraud, and the record never says how the act reached the bank. The case labels no incident cyber, so both placements are readings and neither is a fact.
The record sorts into a threat side, a relationship side and one overlap, and two incidents resist the sort because the record never wrote down the fact that would settle them.

How much did cyber cost this invented bank in the year?

A committee actually asks for a total, and the seven categories make that total impossible to reach by summing. Build it by reading instead, and watch what happens.

Read narrowly and the answer is incident I7 alone, at Rs 1.5 crore of net loss. Rs 1.5 crore is 3.4 per cent of the year's Rs 43.8 crore. Read the two category 2 frauds alike, on the ground that both were deliberate and both were worked remotely, and the answer is Rs 4.8 crore plus Rs 1.5 crore, being Rs 6.3 crore. Rs 6.3 crore is 14.4 per cent of the year. The two frauds are the whole of category 2, so the wide reading of the threat lens is exactly category 2's net loss for the year, at Rs 6.3 crore, and it happens to coincide with a category total without being one.

Rs 6.3 crore divided by Rs 1.5 crore is 4.2 exactly, so the two readings differ by a factor of 4.2. A factor of 4.2 is not a rounding argument or a presentation quibble. The factor is the difference between a lens that looks like a rounding error in a year and a lens that looks like a seventh of it, on one record, with no figure moved. A lens total is not wrong until it is stated without its reading rule. Stripped of the rule it stops being reproducible, and a figure nobody can reproduce is not even wrong.

An honest treatment prints both totals and names the reading beside each, rather than picking one. Printing both is not fence-sitting. The alternative is to print one number, watch it get quoted in a paper next quarter with the rule stripped off, and have a committee compare it against a figure somebody else built by a different reading. Two totals with their rules attached are more useful than one total with none, and the step by step method for assessing a third party, covered separately, has to start from a stated rule for exactly the same reason.

The case is dense with collisions, and one of them needs naming before the lens totals are left behind. Rs 4.4 crore appears twice in this guide as two entirely different objects: it is incident I9's gross loss, and it is also category 7's whole net loss for the year across three incidents. Rs 3.2 crore is likewise incident I9's net loss and also incident I3's. Every figure above is attached to a named object, and a bare number in a loss record should be treated with suspicion.

THE SAME LENS, TWO READINGS, ONE RECORD Net loss in Rs crore at the invented bank. Bar length is drawn to scale at 90 pixels a crore. NARROW READING incident I7 alone I7, Rs 1.5 cr Rs 1.5 crore net, being 3.4 per cent of the year's Rs 43.8 crore. WIDE READING incidents I1 and I7 I1, Rs 4.8 crore I7, Rs 1.5 cr Rs 6.3 crore net, being 14.4 per cent of the year, and exactly category 2's net loss. 6.3 divided by 1.5 = 4.2 times, and the record chooses neither reading. Nothing in this invented case labels any incident cyber, so neither figure is a fact about the record. A lens total is only reproducible when the reading rule is printed beside it.
Read narrowly the threat lens costs this invented bank Rs 1.5 crore for the year and read widely it costs Rs 6.3 crore, a factor of 4.2 on one unchanged record.
Try it out

The record holds two category 2 frauds, incident I1 at Rs 4.8 crore net and incident I7 at Rs 1.5 crore net. What is this invented bank's cyber total for the year?

Why an external party in a fraud is not a third party

There is one more sorting mistake worth killing before it spreads, and careful people make it. The mistake turns on an ordinary English word. The relationship lens uses the phrase third party. A loss record uses the phrase external party. The two phrases look like synonyms and are not, and the record at this invented bank contains the cleanest possible example of the difference.

Incident I13 is the largest net loss of this bank's year. A trade finance officer and an external partySomebody outside the institution who is not contracted to do anything for it, which is a different object from a third party. issued 9 letters of credit against forged shipping documents over fourteen months ending in month 8. The scheme came to light when a beneficiary bank claimed. Gross Rs 22.4 crore, Rs 7.0 crore recovered, net Rs 15.4 crore. One event in thirteen carried 35.2 per cent of the year's Rs 43.8 crore. A member of staff was inside it, so incident I13 is filed in category 1, internal fraud.

Somebody outside the bank was in it too. So is incident I13 a third party event? Run the relationship definition over it honestly, one clause at a time. Was this person selected by the bank against criteria? No. Was a contract signed under which they performed an activity for the bank? No. Were they onboarded, given a criticality rating, monitored against service terms, subjected to a right to audit, given an exit arrangement? None of it. The phrase third party is not a synonym for outsider, it is the name of a relationship the institution entered on purpose, and somebody who defrauds the bank has entered no relationship the bank chose.

If that sounds like an argument about vocabulary, watch what it decides. Policy PL7 at this bank carries information security, with its own owner and its own review cycle. Policy PL8 carries outsourcing and third party arrangements, a separate document with a separate owner. Neither one reaches incident I13. There was no attack on a system and no contracted supplier, so filing this event under either heading would put Rs 15.4 crore in front of a reader who then hunts for a control failure that is not there. The operational risk policy PL5 reaches it, and so does committee G6. Committee G6 receives incidents I1 to I13 monthly. Getting the noun right is how an event lands on the table that can do something about it.

INCIDENT I13, AND THE WORD IT IS NOT The invented bank's largest net loss of the year. Every figure below is the bank's own and invented. Month 8, category 1, internal fraud. A trade finance officer and an external party issued 9 letters of credit against forged shipping documents over fourteen months ending in month 8. Found when a beneficiary bank claimed. Gross Rs 22.4 crore, Rs 7.0 crore recovered, net Rs 15.4 crore, being 35.2 per cent of the year's Rs 43.8 crore. A THIRD PARTY IS SOMEBODY WHO WAS 1. selected against the bank's criteria 2. contracted to perform an activity for it 3. onboarded, rated and monitored 4. given terms, a right to audit and an exit Four clauses, and the bank chose every one of them. THE EXTERNAL PARTY IN INCIDENT I13 WAS 1. not selected 2. not contracted 3. not onboarded and not monitored 4. given no terms and no exit Nought out of four, so the relationship lens is empty here. Policy PL7, information security: does not reach it. Policy PL8, outsourcing and third party: does not reach it. Policy PL5, operational risk, reaches it, and committee G6 receives it with the other twelve incidents.
All four clauses of the third party definition answer no for incident I13, so the largest loss of the year belongs to neither lens.
Try it out

Incident I13 involved a bank officer and an external party. Does the external party make it a third party incident?

Breaking Into Quants Bootcamp — Fin Maverick

What does the contract actually move?

Asked what to do about a dependence on somebody else, almost anybody answers within about four seconds: put it in the contract. Putting it in the contract is a good answer and a partial one. The record at this invented bank measures exactly how partial it is, and a measurement is more useful than an argument.

Incident I9 carried a gross loss of Rs 4.4 crore and Rs 1.2 crore came back from the provider, being 27.3 per cent of the gross. The Rs 1.2 crore came back because of a recovery clauseA contract term under which the other side bears part of a loss, which transfers money and transfers nothing else., a term under which the other side bears part of what went wrong. So the contract worked. Now turn it into a dial and ask what a better one would have been worth.

The year's Rs 43.8 crore less this incident's Rs 3.2 crore leaves Rs 40.6 crore, so the other twelve incidents of the year carry Rs 40.6 crore between them, and nothing on that dial touches them. So the year's total is Rs 40.6 crore plus whatever incident I9 books, and incident I9 books Rs 4.4 crore less whatever the clause returns. Recover nothing and the incident costs Rs 4.4 crore and the year reads Rs 45.0 crore. Recover every rupee and the incident costs nothing and the year reads Rs 40.6 crore. Against limit L11, the bank's own rolling twelve month cap of Rs 60.0 crore set by committee G2, that is 75.0 per cent at one end and 67.7 per cent at the other. The entire negotiating range of that clause, from a contract that returns nothing to a contract that returns everything, is 7.3 percentage points of a limit that is nowhere near being reached at either end.

Hold that beside what people expect the contract to be doing. A great deal of effort goes into indemnity wording, and on this event the whole span of possible outcomes moves the bank's headline operational loss utilisation from the high sixties to the mid seventies and crosses nothing at all.

And now the part that matters more than the money. Whatever value that dial is set to, the service was unavailable for 9 hours and 48,000 transactions failed. Both figures are identical at nought per cent recovery and at a hundred. A recovery clause transfers money and transfers nothing else, so the customer on the other end of a failed transaction had exactly the same nine hours under the best contract anybody could write as under the worst one. Third party risk is therefore not settled in the indemnity section. The indemnity settles who pays. Selection, monitoring and a tested exit are the only levers that touch whether the 9 hours happen at all, and none of them is a clause about money.

One thing the record does not say: whether that Rs 1.2 crore came back as a share of the loss or as a fixed cap. On this event the two cannot be told apart. Rs 1.2 crore is both 27.3 per cent of Rs 4.4 crore and a flat figure. The two behave completely differently once the loss grows. A share keeps pace and a cap stops where it was written. The dial below is built on the share reading and says so on its face.

THE WHOLE RANGE OF THE RECOVERY CLAUSE, AND WHAT IT NEVER REACHES The invented bank's year of net operational loss at five settings of the recovery share on incident I9. Read on the share basis. Utilisation runs from 75.0 per cent to 67.7 per cent across the entire dial, a span of 7.3 percentage points. LIMIT L11, THE BANK'S OWN CAP, Rs 60.0 CRORE No setting of the clause comes near it. Rs 45.0 cr 75.0% v = 0 Rs 43.8 cr 73.0% v = 27.3 WHAT THIS BANK GOT Rs 42.8 cr 71.3% v = 50 Rs 41.7 cr 69.5% v = 75 Rs 40.6 cr 67.7% v = 100 IDENTICAL AT ALL FIVE SETTINGS: 9 hours unavailable, 48,000 failed transactions. The clause moves rupees. It does not move the outage, and the outage is what the customers had.
Across the clause's entire range the year swings from Rs 45.0 crore to Rs 40.6 crore and never approaches limit L11, while the outage does not move at all.
Try it out

Before the dial below. The bank recovered 27.3 per cent from the provider. If the contract had returned every rupee instead, what happens to the 9 hours and the 48,000 failed transactions?

Play with it

The recovery dial on incident I9

Move the share the contract returns from nought to a hundred per cent. Watch three things move together and two things refuse to move at all.

Recovery share
27.3%
Incident I9 net
Rs 3.2 cr
The year, net
Rs 43.8 cr
Limit L11 used
73.0%

Recovering 27.3 per cent from the third party, this incident books Rs 3.2 crore and the year reads Rs 43.8 crore at 73.0 per cent of limit L11, while the outage stays at 9 hours and 48,000 failed transactions.

THE RECOVERY DIAL, LIVE Invented bank, invented figures. The recovery is read as a share of the gross loss and settled to the nearest lakh. v = 27.3% 0 25 50 75 100 recovery share v, per cent of the Rs 4.4 crore gross on incident I9 THE YEAR, NET OPERATIONAL LOSS, ALL THIRTEEN INCIDENTS LIMIT L11, Rs 60.0 CRORE Rs 43.8 crore 73.0% of limit L11 9 hours the service was unavailable, and this does not move 48,000 transactions failed, and this does not move either Settings tried so far: 1. Both readings above have stayed the same at every one of them.
Recovery share vIncident I9 netThe year, netLimit L11 used
0 per centRs 4.4 croreRs 45.0 crore75.0%
27.3 per cent, what this bank gotRs 3.2 croreRs 43.8 crore73.0%
50 per centRs 2.2 croreRs 42.8 crore71.3%
75 per centRs 1.1 croreRs 41.7 crore69.5%
100 per centnilRs 40.6 crore67.7%
Constant at every row9 hours48,000 failedno crossing

The five solved points, so a reader who never touches the control still gets both findings. The other twelve incidents carry Rs 40.6 crore and no setting of this dial touches them. Nothing on this range reaches limit L11 of Rs 60.0 crore.

Educational illustration. Assumptions on screen. The recovery is modelled as a share of the loss. A contract that caps recovery at a fixed rupee amount behaves completely differently as the loss grows, and this invented case does not say which of the two this contract was, so the panel names the question rather than settling it. At the default setting incident I9 books Rs 3.2 crore, and incident I3's net loss is the same figure, so both readings name the incident rather than the bare number.

Try it out

The contract returned Rs 1.2 crore of the Rs 4.4 crore. What does the record not say about that contract, and why would it matter on a bigger loss?

The failure: one line on a committee paper reading cyber and third party risk

Merging the two headings is the mistake, and it does not look like a mistake when it is made. Somebody building a pack has limited rows. Two headings that both feel technical and both feel modern get pushed onto one line, and the line gets a number beside it. Nobody objects. The number looks like information.

Work out what that line can be asked. The merged line cannot answer how much of the year came from somebody acting deliberately against the bank. The relationship events are folded into it. The same line cannot answer how much of the operation sits in other people's hands. The threat events are folded in too. Merging the two is not a simplification of the reporting, it is the deletion of both answers. The deletion is silent. The merged line still prints a figure, and a figure reads as though somebody measured something.

The governance at this invented bank makes it worse rather than better. Committee G8, information security, has six members, meets quarterly and reports into committee G6 rather than into the board. For outsourcing and third party arrangements the case names policy PL8 and no committee at all. So one lens already has a table that meets four times a year and speaks at second hand, and the other has a document with no stated recipient. Fold them into one row and the row belongs to whichever of those two arrangements is stronger. Here that is committee G8, the one that at least meets. The weaker question is the one that quietly stops being asked, and it is the question about who is holding the operation.

WHAT THE MERGED LINE STOPS BEING ABLE TO SAY Built on the invented bank's own record. The merged figure below is struck on the narrow reading of the threat lens. CYBER AND THIRD PARTY RISK ..................................................... Rs 4.7 crore Incident I7 at Rs 1.5 crore plus incident I9 at Rs 3.2 crore, and the line does not say that is the reading. QUESTION ONE, THE THREAT LENS How much of the year came from somebody acting deliberately against this bank? NOT RECOVERABLE FROM THE LINE ABOVE QUESTION TWO, THE RELATIONSHIP LENS How much of the operation sits in the hands of people this bank contracted with? NOT RECOVERABLE FROM THE LINE ABOVE Committee G8, information security: six members, quarterly, reporting into committee G6 rather than the board. Policy PL8, outsourcing and third party: the invented case names no committee for it at all. One lens has a table and the other has a document, so a merged row belongs to the lens that meets.
A merged line prints a figure and answers neither of the two questions the two lenses exist to produce for a committee.
Try it out

A committee paper carries one line reading cyber and third party risk with a single figure beside it. What two questions can that paper no longer answer?

How this gets used by somebody who has to act on it

Take an analyst reading a bank from the outside, with the annual report and nothing else. The disclosure says operational risk losses for the year were Rs 43.8 crore against an internal cap of Rs 60.0 crore, and somewhere there is a paragraph about technology and outsourcing. The analyst cannot audit any of it. The analyst can ask which questions the bank has arranged itself to answer, and the answer is visible from the outside more often than people expect. A bank that reports a threat number and a dependence number separately has two functions doing two different jobs. A bank that reports one merged line has disclosed that somebody folded two questions into one row, and it is fair to ask what else got folded.

Then there is the person inside who has to act. If the number in front of that person is a threat number, the actions available are all on the institution's own side of the door: access, detection, architecture, the review that found near miss N5 after 46 days. If the number is a dependence number, none of those actions touch it, and the ones that do are selection, contract terms, monitoring and a tested exit. The two lenses are not two ways of describing an exposure, they are two different action lists, and a reader who cannot tell which number is in front of them cannot pick a list.

And take the everyday version. The shape is the same. A household that has its salary from one employer and its cooking gas from one supplier has two completely different worries. Somebody breaking in is one kind of problem and the gas not arriving is another, and no amount of insurance against burglary makes the gas arrive. Insurance moves money after the fact, and a recovery clause does exactly that for incident I9. Neither ever moved the 9 hours.

Where the rule comes from

Naming the bodies, and where to find them

A threat lens, a relationship lens and six criteria are the same in any country, so everything above is written without a jurisdiction in it. The obligations differ by country, and outsourcing is one of the most closely governed subjects in operational risk, so only the bodies that set the obligations are named below.

The operational risk framework and the seven event categories the sort above leans on originate with the Basel Committee on Banking Supervision, whose work is published by the Bank for International Settlements at bis.org. The Basel framework is the origin, and it obliges no Indian bank by itself. The binding requirements for an Indian bank on outsourcing, third party arrangements, information security and cyber security come from the Reserve Bank of India at rbi.org.in, where the current position is found. Where the institution is a market intermediary rather than a bank, the relevant body is the Securities and Exchange Board of India at sebi.gov.in.

Requirements, materiality tests, register standards, reporting timelines, thresholds, notice periods and effective dates can all move. The current text at the source is what governs, and confirming it there comes before relying on any of it.

Where the two lenses stop. Information security as a subject, meaning the properties it protects, access management, privileged access and the review cadence, is covered separately earlier in this sequence: near miss N5 appears above only as something to sort, and the 46 days are quoted rather than analysed. The step by step method for assessing a third party, from inventory and criticality through the contract to a tested exit, is the framework piece at the end of this sequence. Business continuity, disaster recovery, crisis declaration and the impact tolerance belong to the resilience sequence. The resilience sequence also holds the tolerance question about incident I9, and this invented case does not say which service that outage touched, so no tolerance breach can be computed for it. Control testing, the audit finding, the deficiency rating and remediation belong to the controls and assurance sequence. The policy set PL1 to PL9 and the committee structure G1 to G8 belong to the governance sequence and are used here and handed straight back.

Risk Management Program Bootcamp — Fin Maverick

Sources

SourceDocumentSite
Bank for International SettlementsThe Basel Committee on Banking Supervision publications setting out the operational risk framework and the seven event categories named in the sort abovebis.org
Reserve Bank of IndiaWhat an Indian bank must actually do about outsourcing, third party arrangements, information security and cyber securityrbi.org.in
Securities and Exchange Board of IndiaThe equivalent position where the institution is a market intermediary rather than a banksebi.gov.in

Vindhya Commercial Bank Limited and every incident, near miss, policy, committee and limit attached to it are invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.