Cyber Risk vs Third Party Risk: Two Categories, One Overlap
Cyber risk and third party risk are not two versions of one idea. Cyber risk is a property of a threat, meaning somebody acting deliberately against systems and data. Third party risk is a property of a relationship, meaning something the institution depends on being run by somebody else. Neither is one of the seven event categories. Both cut across all seven, and a single incident can be either, both or neither.
Two words turn up on the same slide in almost every operational risk pack written anywhere, usually joined by an and, and the joining is where the trouble starts. On a close reading they are not parallel at all. One of them describes a kind of threat. The other describes a kind of arrangement. Both can be held in mind at once about the same event, and they yield two different, both correct, answers. A definition written against a contrast tends to describe the contrast rather than the subject. So each of the two is defined completely on its own below, with the other kept out of the room, before any comparison begins.
Vindhya Commercial Bank Limited, an invented mid-sized Indian commercial bank, supplies every incident, figure, committee and policy number worked below. Its record for the twelve numbered months of this case carries thirteen operational risk incidents, numbered I1 to I13, and five near misses, numbered N1 to N5. A distinction that cannot sort a real list of events is not a distinction, it is a preference. The bank's record is where both words get tested.
What is cyber risk actually a property of?
A front door shows the shape of the idea, and that shape is the same at every scale. A household worries about somebody trying the lock. The household does not worry equally about every bad thing that could happen to the house. A pipe bursting is bad, a power cut is bad, and neither of them involves anybody wanting anything from the household. Somebody trying the lock is a different species of problem. There is a person on the other end, choosing, adapting and trying again when the first attempt fails. A separate species is marked out not by the door and not by the loss, but by an intent that responds to whatever the household does.
Cyber riskThe risk of somebody acting deliberately against an institution's systems and data. is the risk of somebody acting deliberately against an institution's systems and data. Each of the three pieces carries weight, and dropping any of them produces a definition that sorts events wrongly. Take that sentence apart into its three pieces.
The first piece is the actor. There is one. Something has to be done by somebody. The requirement of an actor is what separates cyber risk from a disk that simply stops or a cable cut by a road crew. The second piece is the intent, and the word deliberately is doing all the work. An employee who fat-fingers a payment file has caused a failure of the same systems, and it is not this. The third piece is the object, and the object is systems and data rather than money, buildings or people. The money that eventually leaves is a consequence. Money leaves through a payment line like any other loss, so an exposure defined by the money will never be found in a record.
The definition leaves out as much as it puts in, and the omissions matter just as much. The definition names no method, no tool, no technique and no channel. How anything works technically belongs to a different subject, and an exposure with its controls is a different conversation again. The definition also does not say the actor is outside. At this invented bank, near miss N5 is a privileged access account belonging to somebody who had left. The account stayed live for 46 days and was found by the access review before it was used. Nobody used it. So the record shows a route that existed and no deliberate act at all. A route is exposure and an act is an event, and the difference is worth holding on to. Registers that have merged the two carry the route as though it were a loss. The loss the route was meant to describe then sits under no line of its own.
If the actor is somebody else and the intent is not the institution's to choose, what can the institution act on? Only its own side. Its own defences, its own arrangement of who can reach what, its own detection. The institution cannot reduce the number of people in the world who would like to get in, and it cannot negotiate with them. Cyber risk is therefore an exposure the institution can only shrink from its own side of the door, and every control it has is a statement about itself rather than about the threat. Nothing in that account requires a supplier, a contract or an outsourcing arrangement. The absence is the first sign that the second word asks a different question.
What is third party risk actually a property of?
Now put the door away entirely and think about a wedding. The household is not cooking. A caterer was chosen after two others were considered, a price was agreed, a menu was written down, and on the day four hundred people will eat food that nobody in the household has ever cooked. Nothing about that involves anybody acting against the household. The caterer wants the evening to go well, has every reason to want it, and may still turn up ninety minutes late because a van broke down. The guests will experience the lateness. The exposure exists not because anybody meant harm but because the doing of the thing sits in somebody else's hands, and the household kept every consequence while handing over the doing.
Third party riskThe risk arising because something the institution depends on is run by somebody it contracted with. is the risk arising because something the institution depends on is run by somebody it contracted with. Take this one apart too. Its three pieces are completely different from the previous three.
The first piece is dependence. The institution needs the thing. If it could shrug and carry on, there is no exposure worth a policy. The second piece is the contract, and it is what makes the other side a third party rather than merely somebody in the world. Somebody was selected, terms were agreed, and an obligation runs in both directions. The third piece is the location of the doing. The activity happens on the other side of that contract, on somebody else's premises, by somebody else's people, on somebody else's arrangements, and the institution watches rather than operates.
The word for the arrangement, when the activity is one the institution would otherwise have done itself, is outsourcingAn arrangement under which an activity the institution would otherwise do itself is performed by somebody else under contract.. Not every third party arrangement is an outsourcing and the difference matters to whoever writes the policy, but the exposure has the same shape either way.
So what can the institution act on in a relationship? Something completely different from the previous list, and it is worth writing out because people reach for the contract and stop. The institution can choose who to contract with in the first place, and that is the single most powerful lever on the list and the only one that operates before anything has gone wrong. Second, it can write terms, including a right to auditA contract term letting the institution examine how the other side actually operates, without which monitoring is a set of assertions., without which its monitoring is a folder of assertions somebody else wrote. Third, it can monitor what actually happens against what was agreed. And it can arrange an exitThe arrangement for taking an activity back or moving it elsewhere, which is the only real limit on what a supplier can charge or withhold., meaning a worked-out way of taking the activity back or moving it. The exit is the only real limit on what the other side can eventually charge or withhold.
One more property belongs to this side and to no other, and it is the one that cannot be fixed by any single institution. If a great many institutions depend on the same provider for the same activity, each of them individually holds a sensible contract and collectively they hold something none of them chose. The exposure they hold collectively is concentration in a supplierThe exposure created when many institutions depend on the same provider, which no single contract can reduce., and the exposure lives in the pattern rather than in any one relationship, so no clause any one of them signs reduces it by a rupee. The wedding version is that every caterer in the district uses the same two ice suppliers, and how carefully the caterer was chosen makes no difference.
Both are now defined. Without looking back: what is cyber risk a property of, and what is third party risk a property of?
Where do the two questions meet in one incident?
Two complete definitions are now on the table and neither of them was written against the other. Independence is what makes an honest overlap findable, and this invented bank has exactly one incident sitting in it.
Incident I9 fell in month 9. A payment gateway hosted by an outside provider failed for 9 hours and 48,000 transactions failed with it. The gross loss was Rs 4.4 crore, Rs 1.2 crore came back from the provider, and the net loss was Rs 3.2 crore. The provider has no name in the record and is not modelled on anybody. The incident was filed in category 6, business disruption and system failures.
Run the relationship definition over it first. Did the bank depend on the thing? Yes, 48,000 transactions say so. Was it run by somebody the bank contracted with? Yes, and the Rs 1.2 crore that came back proves a contract existed with money terms in it. Was the doing on the other side of that contract? Yes. So the answer to the third party question is a clean yes on the record's own facts, with nothing added.
Running the threat definition over the same incident asks two questions. Was there an actor? Was there intent? The record says the gateway failed. The record says how long, how many transactions, what it cost and what came back. The record does not say why it failed, and a reason nobody wrote down cannot be supplied afterwards. Nothing in this case labels incident I9 an attack, and nothing in it rules an attack out either.
So what is the honest entry? Not cyber. Not not-cyber. The honest entry is a third party event whose cause is unrecorded. A reader who finds that unsatisfying has understood it correctly. The entry is unsatisfying and it is still the only one the record supports. Filing it as cyber invents a cause. Ruling cyber out invents the absence of one. Both are the same error wearing opposite signs. Ruling cyber out is the more comfortable of the two, and comfort is exactly what makes it the more dangerous. Nobody goes back to challenge a classification that made a problem look smaller.
The missing fact has a consequence for the whole distinction. One fact that nobody wrote down decides whether this single incident belongs to one lens, to both, or to one and not the other. If cyber and third party were two versions of the same idea, the classification would come out the same either way, and a missing fact could not do that. The missing fact only bites because two genuinely different questions are being asked of one event. The incident that resists the sort is the strongest evidence that the sort is real.
Was incident I9 a cyber event?
What separates them once both are on the table?
Definitions are cheap and sorting is expensive, so the test of a distinction is whether somebody with no interest in the argument can apply it to a real event and reach the same answer. Applying a distinction needs criteria written down. Six criteria do the work, numbered CT1 to CT6 so that a row can be named rather than restated each time. The six are this invented bank's own working set, and no supervisor requires any of them.
CT1 is the object, meaning the thing the exposure is about. On the threat side it is systems and data. On the relationship side it is a dependency, meaning something the institution needs which happens to be run on the far side of a contract. Systems and data on one side and a dependency on the other are not two levels of one thing. One of them is a possession, the other is an arrangement.
CT2 is the actor. On the threat side there is somebody working against the institution who adapts when blocked. An adapting opponent is why controls on that side have to be renewed rather than installed. On the relationship side there is a counterparty behaving perfectly normally who fails, or is late, or goes out of business, and nobody meant anything by any of it. The van broke down. A control designed for an opponent and a control designed for an ordinary failure are not the same control, and this is the row that decides which one is needed.
CT3 is what the institution actually controls, and this is where practitioners split most often. On the threat side there is one lever with several handles: the institution's own side of the door. On the relationship side there are four levers, and they arrive in a sequence that matters more than the list suggests. Selection comes first and is the only one that operates before anything has gone wrong. Contract terms come second. Monitoring is third and is only as real as the right to look. Exit is fourth and is the quiet one that governs the other three. A relationship that cannot be left is a relationship whose terms will drift. Notice that no lever on the relationship side is a defence and no lever on the threat side is a contract. The mismatch of levers is by itself enough to show the two exposures are not versions of each other.
CT4 is where each one shows up in the loss record, and the answer for both is the same and is surprising enough that the next section is given over to it entirely: neither has a category of its own.
CT5 is which policy carries it. At this invented bank the answer is policy PL7, information security, on one side and policy PL8, outsourcing and third party, on the other. Two documents. Two owners. Two review cycles. A reader who thinks the two exposures are versions of each other has to explain why this bank wrote them up twice.
CT6 is which committee sees it, and here the invented record produces an asymmetry rather than a pair. Committee G8, the information security committee, has six members, meets quarterly and reports into committee G6 rather than into the board. For outsourcing and third party arrangements, the record names policy PL8 and names no committee at all. The missing committee is a fact about this invented case rather than an omission, and it stays visible.
Which committee at this invented bank receives information security, and which receives outsourcing and third party?
Which of the seven event categories does each one live in?
One question catches almost everybody, and the answer changes what somebody has to do on a Monday morning, so it is worth setting up properly. Suppose the chief risk officer asks for this bank's total cyber losses for the year. Which column gets added up?
The loss record is sorted into seven event categories. The seven categories are the Basel Committee's, published at the Bank for International Settlements: internal fraud, external fraud, employment practices and workplace safety, clients products and business practices, damage to physical assets, business disruption and system failures, and execution delivery and process management. Every one of the bank's thirteen incidents sits in exactly one of them, and the seven together account for the year's Rs 43.8 crore of net loss with nothing left over.
Now look for cyber on that list. Cyber is not there. Look for third party. Also not there. The absence is not an oversight in the scheme, it is the scheme working as intended: the seven categories sort events by what kind of failure produced them, not by what kind of exposure they came out of. Neither cyber nor third party is an event category, so neither one has a column and neither one has a total that can be read off anything.
Both of them are instead a lensA way of cutting a loss record that is not one of its categories, so its total has to be built by reading rather than by summing a column.: a way of cutting the record that is not one of its categories. A lens crosses the categories rather than living inside one. At this invented bank, incident I7, a phishing campaign against internet banking customers that reached 312 customers, sits in category 2, external fraud. Incident I9, the gateway outage, sits in category 6, business disruption and system failures. Two events that a threat lens and a relationship lens each pick up, filed two categories apart. The categories are answering a third question altogether.
The practical consequence is a piece of work, and it is worth naming as work rather than as a definition. Any total for either lens has to be built by reading the incidents one by one and deciding, event by event, whether the lens catches it. Reading thirteen incidents one by one is somebody's afternoon. The reading produces a number nobody can reproduce unless the rule behind it is written down alongside. And it is exactly why the merged heading is so attractive and so destructive: merging looks like it saves the afternoon, and what it actually does is delete both answers.
The chief risk officer asks for this invented bank's total cyber losses for the year. Which of the seven categories should be summed?
Which incidents in this record are one, which are the other, and which are both?
Sorting a real list is the exercise that makes a distinction stick, and it is also the exercise that exposes the places where a distinction runs out. Both things happen here, so read the sort and then read what does not sort.
On the threat side with no relationship in it, the clearest case is incident I7. In month 7 a phishing campaign against internet banking customers reached 312 customers, who were reimbursed. Gross Rs 1.8 crore, Rs 0.3 crore recovered, net Rs 1.5 crore, filed in category 2, external fraud. Somebody acted deliberately. Nobody the bank contracted with is anywhere in the event. Beside it sits near miss N5 from month 10, the privileged access account belonging to a leaver that stayed live 46 days and was found by the access review before it was used. Near miss N5 produced no loss, appears in no loss record and belongs to no category. A route that existed and was never travelled is treated exactly that way.
On the relationship side with no threat in it, the record gives incident I9 and nothing else. No other incident in the thirteen turns on something a supplier failed to do. One relationship event in thirteen is not a comforting finding. The record states no inventory of suppliers at all, so the count measures what was written down rather than what the bank depends on. A single sighting is a sighting and never a population.
Incident I4 deserves naming here precisely because it looks like a relationship event and is not one. In month 4 a third party insurance product was sold to 1,840 customers without the disclosure the bank's own procedure required, and premiums were refunded: gross Rs 5.2 crore, net Rs 5.2 crore, filed in category 4. A third party is unmistakably present. But nothing the third party did or failed to do caused the loss. The bank's own disclosure step was not performed. Test it against the definition rather than against the vocabulary. The exposure has to arise because the activity is run by somebody else, and the activity that failed here was run by the bank. So the presence of a supplier in a story is not the test, and anybody sorting on the word rather than on the definition will file this one wrongly.
And now the two events that genuinely resist the sort. Both resist for the same reason, and that reason is worth more than the sort itself. Incident I9 resists on the threat side: the record states a duration, a transaction count and three money columns, and states no cause, so it cannot be placed. Incident I1 resists on the same side. In month 1, card-not-present fraud on the debit card portfolio cost the bank Rs 6.4 crore gross, Rs 1.6 crore came back and the net loss was Rs 4.8 crore, and it is filed in category 2, the same category as incident I7. Card-not-present fraud is a fraud, so somebody acted deliberately, and it was worked remotely rather than over a counter. The threat lens actually asks whether the deliberate act reached the bank through its systems and data. Incident I1's entry does not say. The record simply never made that classification. Nothing in this case labels any incident cyber, so every cyber number in this guide is a reading of the record and never a fact about it.
How much did cyber cost this invented bank in the year?
A committee actually asks for a total, and the seven categories make that total impossible to reach by summing. Build it by reading instead, and watch what happens.
Read narrowly and the answer is incident I7 alone, at Rs 1.5 crore of net loss. Rs 1.5 crore is 3.4 per cent of the year's Rs 43.8 crore. Read the two category 2 frauds alike, on the ground that both were deliberate and both were worked remotely, and the answer is Rs 4.8 crore plus Rs 1.5 crore, being Rs 6.3 crore. Rs 6.3 crore is 14.4 per cent of the year. The two frauds are the whole of category 2, so the wide reading of the threat lens is exactly category 2's net loss for the year, at Rs 6.3 crore, and it happens to coincide with a category total without being one.
Rs 6.3 crore divided by Rs 1.5 crore is 4.2 exactly, so the two readings differ by a factor of 4.2. A factor of 4.2 is not a rounding argument or a presentation quibble. The factor is the difference between a lens that looks like a rounding error in a year and a lens that looks like a seventh of it, on one record, with no figure moved. A lens total is not wrong until it is stated without its reading rule. Stripped of the rule it stops being reproducible, and a figure nobody can reproduce is not even wrong.
An honest treatment prints both totals and names the reading beside each, rather than picking one. Printing both is not fence-sitting. The alternative is to print one number, watch it get quoted in a paper next quarter with the rule stripped off, and have a committee compare it against a figure somebody else built by a different reading. Two totals with their rules attached are more useful than one total with none, and the step by step method for assessing a third party, covered separately, has to start from a stated rule for exactly the same reason.
The case is dense with collisions, and one of them needs naming before the lens totals are left behind. Rs 4.4 crore appears twice in this guide as two entirely different objects: it is incident I9's gross loss, and it is also category 7's whole net loss for the year across three incidents. Rs 3.2 crore is likewise incident I9's net loss and also incident I3's. Every figure above is attached to a named object, and a bare number in a loss record should be treated with suspicion.
The record holds two category 2 frauds, incident I1 at Rs 4.8 crore net and incident I7 at Rs 1.5 crore net. What is this invented bank's cyber total for the year?
Why an external party in a fraud is not a third party
There is one more sorting mistake worth killing before it spreads, and careful people make it. The mistake turns on an ordinary English word. The relationship lens uses the phrase third party. A loss record uses the phrase external party. The two phrases look like synonyms and are not, and the record at this invented bank contains the cleanest possible example of the difference.
Incident I13 is the largest net loss of this bank's year. A trade finance officer and an external partySomebody outside the institution who is not contracted to do anything for it, which is a different object from a third party. issued 9 letters of credit against forged shipping documents over fourteen months ending in month 8. The scheme came to light when a beneficiary bank claimed. Gross Rs 22.4 crore, Rs 7.0 crore recovered, net Rs 15.4 crore. One event in thirteen carried 35.2 per cent of the year's Rs 43.8 crore. A member of staff was inside it, so incident I13 is filed in category 1, internal fraud.
Somebody outside the bank was in it too. So is incident I13 a third party event? Run the relationship definition over it honestly, one clause at a time. Was this person selected by the bank against criteria? No. Was a contract signed under which they performed an activity for the bank? No. Were they onboarded, given a criticality rating, monitored against service terms, subjected to a right to audit, given an exit arrangement? None of it. The phrase third party is not a synonym for outsider, it is the name of a relationship the institution entered on purpose, and somebody who defrauds the bank has entered no relationship the bank chose.
If that sounds like an argument about vocabulary, watch what it decides. Policy PL7 at this bank carries information security, with its own owner and its own review cycle. Policy PL8 carries outsourcing and third party arrangements, a separate document with a separate owner. Neither one reaches incident I13. There was no attack on a system and no contracted supplier, so filing this event under either heading would put Rs 15.4 crore in front of a reader who then hunts for a control failure that is not there. The operational risk policy PL5 reaches it, and so does committee G6. Committee G6 receives incidents I1 to I13 monthly. Getting the noun right is how an event lands on the table that can do something about it.
Incident I13 involved a bank officer and an external party. Does the external party make it a third party incident?
What does the contract actually move?
Asked what to do about a dependence on somebody else, almost anybody answers within about four seconds: put it in the contract. Putting it in the contract is a good answer and a partial one. The record at this invented bank measures exactly how partial it is, and a measurement is more useful than an argument.
Incident I9 carried a gross loss of Rs 4.4 crore and Rs 1.2 crore came back from the provider, being 27.3 per cent of the gross. The Rs 1.2 crore came back because of a recovery clauseA contract term under which the other side bears part of a loss, which transfers money and transfers nothing else., a term under which the other side bears part of what went wrong. So the contract worked. Now turn it into a dial and ask what a better one would have been worth.
The year's Rs 43.8 crore less this incident's Rs 3.2 crore leaves Rs 40.6 crore, so the other twelve incidents of the year carry Rs 40.6 crore between them, and nothing on that dial touches them. So the year's total is Rs 40.6 crore plus whatever incident I9 books, and incident I9 books Rs 4.4 crore less whatever the clause returns. Recover nothing and the incident costs Rs 4.4 crore and the year reads Rs 45.0 crore. Recover every rupee and the incident costs nothing and the year reads Rs 40.6 crore. Against limit L11, the bank's own rolling twelve month cap of Rs 60.0 crore set by committee G2, that is 75.0 per cent at one end and 67.7 per cent at the other. The entire negotiating range of that clause, from a contract that returns nothing to a contract that returns everything, is 7.3 percentage points of a limit that is nowhere near being reached at either end.
Hold that beside what people expect the contract to be doing. A great deal of effort goes into indemnity wording, and on this event the whole span of possible outcomes moves the bank's headline operational loss utilisation from the high sixties to the mid seventies and crosses nothing at all.
And now the part that matters more than the money. Whatever value that dial is set to, the service was unavailable for 9 hours and 48,000 transactions failed. Both figures are identical at nought per cent recovery and at a hundred. A recovery clause transfers money and transfers nothing else, so the customer on the other end of a failed transaction had exactly the same nine hours under the best contract anybody could write as under the worst one. Third party risk is therefore not settled in the indemnity section. The indemnity settles who pays. Selection, monitoring and a tested exit are the only levers that touch whether the 9 hours happen at all, and none of them is a clause about money.
One thing the record does not say: whether that Rs 1.2 crore came back as a share of the loss or as a fixed cap. On this event the two cannot be told apart. Rs 1.2 crore is both 27.3 per cent of Rs 4.4 crore and a flat figure. The two behave completely differently once the loss grows. A share keeps pace and a cap stops where it was written. The dial below is built on the share reading and says so on its face.
Before the dial below. The bank recovered 27.3 per cent from the provider. If the contract had returned every rupee instead, what happens to the 9 hours and the 48,000 failed transactions?
The recovery dial on incident I9
Move the share the contract returns from nought to a hundred per cent. Watch three things move together and two things refuse to move at all.
Recovering 27.3 per cent from the third party, this incident books Rs 3.2 crore and the year reads Rs 43.8 crore at 73.0 per cent of limit L11, while the outage stays at 9 hours and 48,000 failed transactions.
| Recovery share v | Incident I9 net | The year, net | Limit L11 used |
|---|---|---|---|
| 0 per cent | Rs 4.4 crore | Rs 45.0 crore | 75.0% |
| 27.3 per cent, what this bank got | Rs 3.2 crore | Rs 43.8 crore | 73.0% |
| 50 per cent | Rs 2.2 crore | Rs 42.8 crore | 71.3% |
| 75 per cent | Rs 1.1 crore | Rs 41.7 crore | 69.5% |
| 100 per cent | nil | Rs 40.6 crore | 67.7% |
| Constant at every row | 9 hours | 48,000 failed | no crossing |
The five solved points, so a reader who never touches the control still gets both findings. The other twelve incidents carry Rs 40.6 crore and no setting of this dial touches them. Nothing on this range reaches limit L11 of Rs 60.0 crore.
Educational illustration. Assumptions on screen. The recovery is modelled as a share of the loss. A contract that caps recovery at a fixed rupee amount behaves completely differently as the loss grows, and this invented case does not say which of the two this contract was, so the panel names the question rather than settling it. At the default setting incident I9 books Rs 3.2 crore, and incident I3's net loss is the same figure, so both readings name the incident rather than the bare number.
The contract returned Rs 1.2 crore of the Rs 4.4 crore. What does the record not say about that contract, and why would it matter on a bigger loss?
The failure: one line on a committee paper reading cyber and third party risk
Merging the two headings is the mistake, and it does not look like a mistake when it is made. Somebody building a pack has limited rows. Two headings that both feel technical and both feel modern get pushed onto one line, and the line gets a number beside it. Nobody objects. The number looks like information.
Work out what that line can be asked. The merged line cannot answer how much of the year came from somebody acting deliberately against the bank. The relationship events are folded into it. The same line cannot answer how much of the operation sits in other people's hands. The threat events are folded in too. Merging the two is not a simplification of the reporting, it is the deletion of both answers. The deletion is silent. The merged line still prints a figure, and a figure reads as though somebody measured something.
The governance at this invented bank makes it worse rather than better. Committee G8, information security, has six members, meets quarterly and reports into committee G6 rather than into the board. For outsourcing and third party arrangements the case names policy PL8 and no committee at all. So one lens already has a table that meets four times a year and speaks at second hand, and the other has a document with no stated recipient. Fold them into one row and the row belongs to whichever of those two arrangements is stronger. Here that is committee G8, the one that at least meets. The weaker question is the one that quietly stops being asked, and it is the question about who is holding the operation.
A committee paper carries one line reading cyber and third party risk with a single figure beside it. What two questions can that paper no longer answer?
How this gets used by somebody who has to act on it
Take an analyst reading a bank from the outside, with the annual report and nothing else. The disclosure says operational risk losses for the year were Rs 43.8 crore against an internal cap of Rs 60.0 crore, and somewhere there is a paragraph about technology and outsourcing. The analyst cannot audit any of it. The analyst can ask which questions the bank has arranged itself to answer, and the answer is visible from the outside more often than people expect. A bank that reports a threat number and a dependence number separately has two functions doing two different jobs. A bank that reports one merged line has disclosed that somebody folded two questions into one row, and it is fair to ask what else got folded.
Then there is the person inside who has to act. If the number in front of that person is a threat number, the actions available are all on the institution's own side of the door: access, detection, architecture, the review that found near miss N5 after 46 days. If the number is a dependence number, none of those actions touch it, and the ones that do are selection, contract terms, monitoring and a tested exit. The two lenses are not two ways of describing an exposure, they are two different action lists, and a reader who cannot tell which number is in front of them cannot pick a list.
And take the everyday version. The shape is the same. A household that has its salary from one employer and its cooking gas from one supplier has two completely different worries. Somebody breaking in is one kind of problem and the gas not arriving is another, and no amount of insurance against burglary makes the gas arrive. Insurance moves money after the fact, and a recovery clause does exactly that for incident I9. Neither ever moved the 9 hours.
Naming the bodies, and where to find them
A threat lens, a relationship lens and six criteria are the same in any country, so everything above is written without a jurisdiction in it. The obligations differ by country, and outsourcing is one of the most closely governed subjects in operational risk, so only the bodies that set the obligations are named below.
The operational risk framework and the seven event categories the sort above leans on originate with the Basel Committee on Banking Supervision, whose work is published by the Bank for International Settlements at bis.org. The Basel framework is the origin, and it obliges no Indian bank by itself. The binding requirements for an Indian bank on outsourcing, third party arrangements, information security and cyber security come from the Reserve Bank of India at rbi.org.in, where the current position is found. Where the institution is a market intermediary rather than a bank, the relevant body is the Securities and Exchange Board of India at sebi.gov.in.
Requirements, materiality tests, register standards, reporting timelines, thresholds, notice periods and effective dates can all move. The current text at the source is what governs, and confirming it there comes before relying on any of it.
Where the two lenses stop. Information security as a subject, meaning the properties it protects, access management, privileged access and the review cadence, is covered separately earlier in this sequence: near miss N5 appears above only as something to sort, and the 46 days are quoted rather than analysed. The step by step method for assessing a third party, from inventory and criticality through the contract to a tested exit, is the framework piece at the end of this sequence. Business continuity, disaster recovery, crisis declaration and the impact tolerance belong to the resilience sequence. The resilience sequence also holds the tolerance question about incident I9, and this invented case does not say which service that outage touched, so no tolerance breach can be computed for it. Control testing, the audit finding, the deficiency rating and remediation belong to the controls and assurance sequence. The policy set PL1 to PL9 and the committee structure G1 to G8 belong to the governance sequence and are used here and handed straight back.
Sources
| Source | Document | Site |
|---|---|---|
| Bank for International Settlements | The Basel Committee on Banking Supervision publications setting out the operational risk framework and the seven event categories named in the sort above | bis.org |
| Reserve Bank of India | What an Indian bank must actually do about outsourcing, third party arrangements, information security and cyber security | rbi.org.in |
| Securities and Exchange Board of India | The equivalent position where the institution is a market intermediary rather than a bank | sebi.gov.in |
Vindhya Commercial Bank Limited and every incident, near miss, policy, committee and limit attached to it are invented.
Educational material. Not advice on any investment, tax, budget or market position.
