Cybersecurity Governance and Risk Oversight for Central Banks

Wishlist Share

About Course

The program aligns to the main themes found across NIST Cybersecurity Framework 2.0 (governance emphasis),
ISO/IEC 27001/27005, CPMI-IOSCO cyber resilience guidance for FMIs, ECB cyber resilience oversight
expectations, DORA’s ICT-risk and third-party oversight requirements, and IMF/BIS central-bank cyber risk
guidance.
Course Overview
This advanced professional programme equips central bank leaders and technical control functions with the governance, oversight, and practical implementation tools needed to manage cybersecurity and digital operational resilience in a central banking environment. The course covers cyber governance for monetary operations, reserves management, payment and settlement systems, supervision technology, market infrastructure oversight, financial stability operations, currency operations, cloud/third-party dependencies, and emerging digital public infrastructure/CBDC environments.
The programme blends governance frameworks, risk management, oversight methodology, case-based learning, scenario simulation, cyber crisis decision-making, and a capstone governance-improvement project. It is designed not only for cybersecurity specialists, but also for board members, executive committees, internal audit, operational risk, legal/compliance, payment systems, reserve management, and banking supervision functions that must exercise effective cyber risk oversight.
Course Goal
To strengthen the ability of central bank leaders and control functions to govern, assess, oversee, and improve cybersecurity resilience across critical central bank functions and across the wider financial ecosystem where the central bank has oversight, supervisory, or crisis-coordination responsibilities.
Training Outcomes
By the end of the programme, participants should be able to:
1. Explain the cyber risk landscape for central banks and distinguish between risks affecting the central bank as an institution and risks affecting the broader financial system it oversees.
2. Design or strengthen a central bank cyber governance model with clear board, executive, risk, security, audit, and business-line accountability.
3. Develop cyber risk appetite, tolerance statements, and escalation thresholds suitable for central banking and financial-market infrastructure environments.
4. Map critical business services and crown-jewel assets across payment systems, reserves/treasury, currency operations, supervisory systems, data platforms, and digital channels.
5. Apply risk assessment methods for cyber threats, vulnerabilities, business impact, systemic contagion, and concentration risk.
6. Oversee third-party and cloud cyber risk in line with leading supervisory expectations and resilience standards.
7. Evaluate cyber controls, monitoring, incident reporting, and crisis management arrangements at governance level.
8. Use resilience metrics, KRIs/KPIs, dashboarding, and board reporting to support informed oversight and
challenge.
9. Assess cyber resilience testing programmes, including tabletop exercises, red-team/threat-led testing,
backup/recovery exercises, and sector coordination drills.
10. Lead or support cyber crisis governance and post-incident lessons learned, including communications with government, regulators, law enforcement, financial sector participants, and the public.
11. Integrate cybersecurity into enterprise risk management, internal audit, compliance, operational resilience, and business continuity frameworks.
12. Produce a practical cyber governance improvement roadmap for a central bank or equivalent public financial institution.
Target Participants
This programme is suitable for:
Executive / Governance level
• Governors, deputy governors, board members
• Executive directors / directors general
• Board risk committee / audit committee members
• CIO, CISO, CRO, COO, CFO, General Counsel
• Heads of payment systems, reserves management, financial stability, supervision
Control and assurance functions
• Enterprise risk management teams
• Operational risk and resilience managers
• Information security / cybersecurity teams
• Internal audit and inspection teams
• Compliance, legal, data governance and privacy officers
• Business continuity / crisis management teams
Technical and business functions with oversight responsibilities
• Payment and settlement system operators
• Currency operations and cash management teams
• Treasury and reserve management staff
• Supervisory technology / regtech / suptech teams
• Financial market infrastructure oversight units
• Digital transformation, cloud, and IT architecture leads
• CBDC / digital payments programme teams

Show More

Course Content