Learning Objectives:
-
Analyse the geopolitical drivers of cyber threats targeting the financial sector.
-
Understand the role of state-sponsored actors in cyber conflicts and hybrid warfare.
-
Recognise the link between geopolitical tensions and the escalation of cyber attacks.
-
Examine the implications of geopolitical cyber threats for central bank resilience.
5.1 The Geopolitical Context of Cyber Threats
Geopolitical tensions are increasingly playing out in cyberspace, with state-sponsored cyberattacks becoming a significant tool of statecraft. The ECB has observed that both the prevalence of geopolitical risks and their actual manifestation have been rising in recent years, and that cyberattacks are playing an increasingly important role in the perpetration of hybrid conflicts . Geopolitical threats have waxed and waned since the turn of the millennium, at times escalating into hostile action, accompanied by a longer-standing trend of increasing geopolitical tension and global fragmentation .
The concept of hybrid warfare—the use of non-military tools alongside military force to achieve strategic objectives—has gained prominence, with cyberattacks serving as a key component. The ECB notes that hybrid techniques, including espionage, infrastructure sabotage, and influence campaigns, are increasingly being used to pursue conflicts by other means . While such techniques are not new, the rise of the internet and digitalisation since the 1980s has turned cyber space into a key battleground where such activities may be carried out and has opened up new avenues of attack .
The degree to which countries have used cyberattacks to further their national interests varies greatly, with a relatively small cluster of countries, often classified as authoritarian regimes, being responsible for the majority of state-sponsored attacks . Such cyberattacks are clearly linked to geopolitical tensions .
5.2 State-Sponsored Cyberattacks and the Financial Sector
State-sponsored cyberattacks primarily target state institutions and critical infrastructures and are mainly aimed at data theft . The principal targets of state-sponsored cyberattacks are state institutions such as governments and ministries, the armed forces, and public administration . Primary targets in critical infrastructures include the telecommunications, energy, and financial sectors as well as defence and transport companies . Attacks on specific sectors, including the financial industry, tend to be clustered over time .
There are many reasons why sovereign states engage in malicious cyber activities, although attacks are predominantly aimed at data theft, potentially linked to espionage . However, especially in times of open conflict, the goal of sabotage and data destruction is to cause maximum disruption by interfering with an opponent’s military operations or by destabilising civilian life . Disruptive attacks can also be used to exert pressure in the hope of forcing a change in behaviour or political position. As such, some cyberattacks can be a part of influence campaigns around important elections. In addition, some cyber activities are aimed at expropriation, in particular via ransomware attacks or the theft of crypto-assets .
The financial sector is a primary target for state-sponsored actors due to its critical role in national and international economic stability. A successful state-sponsored cyberattack on a central bank or major financial institution could have cascading effects on the broader financial system.
5.3 Hybrid Threats and Financial Stability
The ECB has identified that the risks of a cyber incident that could threaten the stability of a central bank are linked to geopolitical tensions . A number of countries conduct cyber activity not just via dedicated military or intelligence units but also via groups of cyber criminals acting on their behalf . This blurring of lines between state and non-state actors complicates the threat landscape and makes attribution more difficult.
The potential for cyber incidents to threaten financial stability has been recognised by regulators globally. The European Central Bank has emphasised that the prevalence of geopolitical risks and their actual manifestation have been rising, and that cyberattacks are playing an increasingly important role in the perpetration of hybrid conflicts . This recognition has led to increased focus on cyber resilience as a critical component of financial stability frameworks.
5.4 Implications for Central Bank Resilience
The geopolitical dimensions of cyber threats have significant implications for central bank resilience. Central banks must prepare for the possibility of state-sponsored cyberattacks that are more sophisticated and persistent than typical criminal attacks. The ECB’s analysis suggests that state-sponsored attacks are likely to continue to increase in frequency and sophistication, particularly in times of geopolitical tension .
Key implications include:
-
Enhanced Threat Intelligence:Â Central banks need to invest in threat intelligence capabilities to understand the geopolitical threat landscape and anticipate potential attacks.
-
Improved Attribution Capabilities:Â Understanding who is behind an attack is essential for developing appropriate defensive strategies and coordinating with international partners.
-
Strengthened International Cooperation: Cross-border coordination and information sharing are essential for countering state-sponsored cyber threats. The Malaysian central bank’s response to the foiled cyber heist involved collaboration with SWIFT, other central banks, and law enforcement agencies .
-
Resilience to Prolonged Attacks: State-sponsored actors may conduct sustained campaigns over extended periods, requiring central banks to maintain high levels of vigilance and resilience.