Learning Objectives:
-
Understand the importance of capacity building for cyber resilience.
-
Apply training and exercise programs to build central bank capabilities.
-
Recognise the role of knowledge sharing in capacity building.
-
Develop a capacity building framework for central bank cybersecurity.
6.1 The Importance of Capacity Building
Capacity building is essential for developing the skills, knowledge, and capabilities needed to address cyber threats. The BIS Cyber Resilience Coordination Centre (CRCC) organises an annual cyber security seminar, in addition to a variety of webinars and training sessions focused on specialised cyber topics . The CRCC also supports the development of operational capabilities in cyber resilience topics .
The SEACEN course on ICT Risk Management and Cybersecurity identifies that innovations such as mobile banking, artificial intelligence, and machine learning have significantly improved access to financial services, but they also introduce complex cyber and ICT-related risks alongside old ones that threaten financial stability. Capacity building helps central banks address these risks effectively.
6.2 Training and Education
Training programs for central bank staff are essential for building cyber resilience. The CRCC’s training and webinars provide central bank staff with opportunities to learn about emerging threats, best practices, and new technologies . The BIS also conducts cyber range exercises where security professionals can practise and develop key skills required to defend networks, including payment systems and operational processes .
Bilateral agreements, such as the MAS-BOT MoU, include provisions for joint training, study visits and research exchanges . These activities strengthen technical capabilities and deepen regulatory collaboration.
6.3 Cyber Exercises
Cyber exercises are essential for testing cyber resilience capabilities. The CRCC conducts regular cyber range exercises – immersive activities where security professionals can practise and develop key skills required to defend networks . The G7 Cyber Expert Group conducts cross-border coordination exercises to strengthen the collective ability of authorities to respond to cyber incidents .
The ECB’s TITUS exercise involved more than 300 staff members and technical experts from all participating institutions, testing the cohesiveness of the response of an important part of the financial market . Exercises help identify areas for further improvement and build confidence in incident response capabilities.
6.4 Knowledge Sharing
Knowledge sharing is a critical component of capacity building. The CRCC hosts a secure online platform, BEACON, for collaboration and information sharing among the central bank cyber security community . BEACON enables central bank staff to share threat intelligence, best practices, and lessons learned in a secure and trusted environment.
The CPMI-IOSCO Cyber Guidance emphasises the importance of “situational awareness” and information sharing for enhancing the collective cyber resilience of financial market infrastructures . Periodic joint round tables to share information among all participants, both public and private, involved in the fight against cybercrime, are an effective means of knowledge sharing .