Learning Objectives:
-
Define cyber resilience and distinguish it from traditional cybersecurity.
-
Understand the core principles of cyber resilience frameworks.
-
Identify the key components of a cyber resilience strategy.
-
Recognise the relationship between cyber resilience and operational resilience.
1.1 What is Cyber Resilience?
Cyber resilience is the ability to prepare for, withstand, respond to, and recover from cyber incidents while continuing to deliver critical services. The Skills for Africa training programme defines cyber resilience as a critical priority for central banks, given their role in safeguarding payment systems, financial market infrastructures, and Central Bank Digital Currencies (CBDCs) . Unlike traditional cybersecurity, which focuses on prevention, cyber resilience acknowledges that attacks will occur and emphasises the ability to maintain operations during and after an incident.
The distinction between cyber security and cyber resilience is fundamental. Cybersecurity focuses on preventing attacks. Cyber resilience accepts that attacks will happen and ensures the organisation can continue to operate and recover quickly. The Central Bank of Eswatini’s Guidelines emphasise that strategies and measures in a financial institution’s cyber resilience framework should not be restricted to securing the viability of its information technology operations alone, but should also cover people and processes .
The SEACEN course notes that innovations such as mobile banking, artificial intelligence, and machine learning have significantly improved access to financial services. However, these advancements also introduce complex cyber and ICT-related risks that threaten financial stability . Cyber threats have become more sophisticated and borderless, fuelled by increased digitisation, third-party dependencies, and geopolitical tensions .
1.2 Core Principles of Cyber Resilience
The BIS Cyber Resilience Coordination Centre has developed the Cyber Resiliency Framework and Benchmark for central banks . The framework helps central banks assess and strengthen their cyber resilience. The Skills for Africa programme identifies key principles including:
Board and Senior Management Attention: Sound cyber governance is key. Board and senior management attention is critical to a successful cyber resilience strategy .
Recovery Capability: The ability to resume operations quickly and safely after a successful cyber attack is paramount .
Threat Intelligence and Testing: Organisations should make use of good-quality threat intelligence and rigorous testing .
Continuous Improvement: Cyber resilience requires a process of continuous improvements .
Collective Endeavour: Cyber resilience cannot be achieved by an organisation alone; it is a collective endeavour of the whole “ecosystem” .
Culture of Cyber Risk Awareness: Organisations should aim to instil a culture of cyber risk awareness and demonstrate ongoing re-evaluation and improvement of their cyber resilience at every level within the organisation .
1.3 Key Components of a Cyber Resilience Strategy
A comprehensive cyber resilience strategy encompasses several interrelated components. The Skills for Africa course covers the “basics of cyber resilience” including “risk management, incident response, and business continuity” . The SEACEN course identifies “best practices for building cyber resilience, including governance frameworks, risk management processes, and international standards” .
Risk Management: Identifying, assessing, and managing cyber risks as part of the enterprise risk management framework. The Central Bank of Eswatini’s Guidelines note that a financial institution should identify cyber threats that could materially affect its ability to perform or to provide services as expected .
Incident Response: Establishing and testing incident response capabilities, including the design and execution of cyber exercises at institutional and industry levels . The SEACEN course includes “incident response and recovery planning” as a core topic .
Business Continuity: Ensuring that critical business functions can continue during and after a cyber incident. The Skills for Africa course covers “business continuity planning and disaster recovery in a cyber context” .
Recovery: Restoring systems and data after an incident. The course covers “recovery strategies and restoration of critical services” .
Testing and Exercises: Regular testing of cyber resilience through exercises and simulations. The SEACEN course includes “the design and execution of cyber exercises at institutional and industry levels” .
Information Sharing: Collaborative approaches to cybersecurity, including cross-sector information sharing and global coordination to address borderless threats .
1.4 Cyber Resilience and Operational Resilience
Cyber resilience is a critical component of operational resilience. The WWT article notes that an isolated approach to cyber or BCM no longer suffices; each institution must demonstrate a robust, end-to-end strategy addressing prevention, detection, response and recovery for all operational risk dimensions . Cyber threats are treated not as isolated IT challenges but as enterprise-wide risks demanding cohesive, consistent and rapid responses .
The Skills for Africa programme covers “design and test crisis management and disaster recovery plans” and “strengthen resilience against Distributed Denial of Service (DDoS) attacks and other disruptions” . This reflects the recognition that cyber resilience must be integrated into broader operational resilience frameworks.