Learning Objectives:

  • Understand the mandate and functions of the G7 Cyber Expert Group.

  • Apply the G7 Fundamental Elements to strengthen cyber resilience.

  • Recognise the role of the G7 CEG in ransomware resilience.

  • Understand the G7 CEG’s cross-border coordination exercises.

3.1 The Mandate of the G7 Cyber Expert Group

The G7 Cyber Expert Group (CEG) was founded in 2015 to serve as a multi-year working group that coordinates cybersecurity policy and strategy across the eight G7 jurisdictions . The U.S. Department of the Treasury’s Office of Cybersecurity and Critical Infrastructure co-chairs the CEG alongside the Bank of England .

The CEG’s mission is to enhance the cyber resilience of the financial sector by fostering preparedness, establishing a shared understanding of the threat landscape, and promoting unified approaches to risk mitigation. The Group has published various sets of Fundamental Elements on cybersecurity topics, including cybersecurity in the financial sector, penetration testing, cyber exercises, ransomware resilience, and third-party risk management .

3.2 The G7 Fundamental Elements

The G7 Fundamental Elements are non-prescriptive and non-binding documents that provide financial entities with high-level building blocks for addressing cybersecurity threats . They provide an overview of the current policy approaches, industry guidance, and best practices in place throughout the G7 .

The Fundamental Elements of Ransomware Resilience for the Financial Sector (2022) provides guidance on eight key areas :

  1. Cybersecurity Strategy and Framework: Integrating ransomware resilience measures into the overall cybersecurity strategy and framework.

  2. Governance: Assessing legal and regulatory requirements related to ransom payments, including sanctions risks.

  3. Risk and Control Assessment: Establishing control assessment mechanisms for ransomware risks, including insurance.

  4. Monitoring: Monitoring ransomware activity to identify hidden risks and providing information to law enforcement and cybersecurity authorities.

  5. Response: Implementing response measures according to pre-established plans.

  6. Recovery: Having clear procedures for restoring affected functions.

  7. Information Sharing: Sharing ransomware incident information and knowledge with internal and external stakeholders.

  8. Continuous Learning: Improving ransomware response capabilities through lessons learned.

The G7 CEG also published the Fundamental Elements for Third Party Cyber Risk Management in the Financial Sector, reflecting the growing recognition of supply chain security as a critical concern .

3.3 Cross-Border Coordination Exercises

The G7 Cyber Expert Group conducts cross-border coordination exercises (CBCE) to strengthen the collective ability of authorities to respond to cyber incidents . The G7 adopted a long-term exercise strategy to increase the frequency and consistency of these simulations, thereby enhancing preparedness across all jurisdictions.

The 2026 exercise simulated a large-scale cyber-attack across all G7 jurisdictions, bringing together ministries of finance, central banks, bank supervisors, and market authorities, fostering a unified response . The initiative enables financial authorities to further align and integrate the various operational and strategic components required for an effective response to cyber incidents.

3.4 The G7 CEG and Global Cybersecurity

The G7 CEG plays a crucial role in promoting global cybersecurity in the financial sector. By coordinating policy and strategy across the G7 jurisdictions, the CEG promotes regulatory convergence and international cooperation. The Fundamental Elements provide a common reference point for financial institutions and regulators, facilitating a consistent approach to cybersecurity across borders.