Euro zone banks losing millions due to poor IT outsourcing, ECB finds

The European Central Bank (ECB) has warned that banks in the Euro zone are losing millions of euros due to poor tech outsourcing.

The commentary came as a result of a survey among banks supervised by the ECB on how prepared they are to deal with risks such as hacks, legacy tech and poor contractors.

The ECB found that banks lost €148 million due to "unavailability or poor quality of outsourced services". This figure, the cenbank said, represented a 360 per cent increase from 2021.

In a newsletter, the ECB said: “These losses were related to a small number of high-volume events and further highlight the need to properly manage risks arising from reliance on service providers.”

The ECB noted that this was "concentrated within a few significant institutions and therefore not indicating a sectoral trend", but warned that "outsourcing arrangements often failed to sufficiently address IT security requirements".

These failings, along with others, caused the ECB to conclude that Euro zone banks’ lack of preparedness in regard to cybersecurity were "more severe and widespread than expected," highlighting that many surveyed banks failed to identify all potential risks or did not have adequate systems in place to appropriately respond to hacks and other incidents.

Adding that banks targeted by inspections have already received recommendations, the ECB said that it "expects all banks under its direct supervision to take immediate and concrete steps to make sure that their IT and cybersecurity risk management is aligned with supervisory expectations."

The report also identifies a significant increase in spend on outsourced cloud services. Of the banks surveyed, cloud services accounted for 3.1 per cent of all IT spend and increased by 56 per cent in 2022.



Share Story:

Recent Stories


Safeguarding economies: DNFBPs' role in AML and CTF compliance explained
Join FStech editor Jonathan Easton, NICE Actimize's Adam McLaughlin and Graham Mackenzie of the Law Society of Scotland as they look at the role Designated Non-Financial Businesses and Professions (DNFBPs) play in the financial sector, and the challenges they face in complying with anti-money laundering and counter-terrorist financing regulations.

Ransomware and beyond: Enhancing cyber threat awareness in the financial sector
Join FStech editor Jonathan Easton and Proofpoint cybersecurity strategist Matt Cooke as they discuss the findings of the State of the Phish 2023 report, diving into key topics such as awareness of cyber threats, the sophisticated techniques being used by criminals to target the financial sector, and how financial institutions can take a proactive approach to educating both their employees and their customers.

Click here to read the 2023 State of the Phish report from Proofpoint.

Cracking down on fraud
In this webinar a panel of expert speakers explored the ways in which high-volume PSPs and FinTechs are preventing fraud while providing a seamless customer experience.

Future of Planning, Budgeting, Forecasting, and Reporting
Sage Intacct is excited to present FSN The Modern Finance Forum’s “Future of Planning, Budgeting, Forecasting, and Reporting Global Survey 2022” results. With participation from 450 companies around the globe, the survey results highlight how organisations are developing their core financial processes by 2030.