Learning Objectives:

  • Understand the BIS Cyber Resiliency Framework and its components.

  • Apply the framework to assess cyber resilience in central banks.

  • Recognise the role of benchmarking in continuous improvement.

  • Understand the CRCC’s role in promoting central bank cyber resilience.

2.1 The BIS Cyber Resilience Coordination Centre (CRCC)

The Cyber Resilience Coordination Centre (CRCC) was established by the Bank for International Settlements (BIS) to promote central bank networking and skills acquisition to combat cyber threats . The CRCC facilitates the exchange of knowledge, promotes collaboration, and supports the development of operational capabilities in cyber resilience topics. Since its inception in 2020, the CRCC’s activities have grown steadily and its outreach has extended beyond BIS member central banks .

The CRCC has developed the Cyber Resiliency Framework and Benchmark for central banks . To date, 10 central banks have completed the assessment. The framework provides a structured approach for central banks to assess and improve their cyber resilience posture.

2.2 The Cyber Resiliency Framework

The Cyber Resiliency Framework is designed to help central banks assess and strengthen their cyber resilience. The framework is built on internationally recognised standards and best practices. While the specific details of the framework are not publicly available in the search results, the Framework is a key tool for central banks seeking to benchmark their cyber resilience against peers.

2.3 The Cyber Resiliency Benchmark

The Benchmark component of the CRCC’s work allows central banks to compare their cyber resilience posture against their peers. The Skills for Africa course includes “cybersecurity frameworks and standards (e.g., ISO 27001, NIST)” as a core module . The SEACEN course includes “international standards and best practices” as part of its curriculum .

2.4 Applying the Framework

The Framework is designed to be applied through a structured assessment process. The Skills for Africa course covers “cyber risk assessment methodologies” and “developing and implementing risk mitigation strategies” . This includes identifying “areas that need to improve and new capabilities that need to be implemented” .

The Framework helps central banks:

  • Recognise the complexity and new threat landscape brought by emerging technologies.

  • Adopt modern enabling technologies supporting security and resilience where appropriate.

  • Take stock of existing capabilities that could be leveraged.

  • Identify the capabilities that need to mature.

  • Identify new capabilities that would need to be implemented.