8.1 The Expanding Scope of International Cooperation

International cybersecurity cooperation is expanding rapidly to address emerging threats and technologies. The G7 Cyber Expert Group (CEG), founded in 2015, has evolved from a policy coordination forum to a central driver of concrete action plans, including a roadmap for post-quantum cryptography (PQC) migration and principles for collective cyber incident response .

In December 2025, the G7 CEG released the “G7 Fundamental Elements of Collective Cyber Incident Response and Recovery in the Financial Sector (CCIRR)”, promoting coordinated response and recovery actions in the event of large-scale cyber incidents . Structured around three main areas—creation, implementation, and long-term maintenance of the CCIRR mechanism—the document establishes non-binding guiding principles to strengthen response and recovery operations, foster convergence across jurisdictions, and improve international cooperation .

The CCIRR document addresses key topics including:

  • Governance: Establishing clear roles and responsibilities for collective response.

  • Coordination Protocols: Standardising communication and decision-making during cross-border incidents.

  • Interoperability: Ensuring compatibility with existing frameworks.

  • Crisis Response and Communication Tools: Enhancing situational awareness and information exchange.

  • Regular Tests: Conducting joint exercises to test collective response capabilities.

  • Information and Intelligence Sharing: Building a trusted community for threat intelligence exchange.

  • Building a Trusted Community: Fostering relationships between authorities, financial institutions, and third-party providers.

A long-term exercise strategy has been adopted to increase the frequency and consistency of cross-border coordination simulations, enhancing preparedness across all jurisdictions .


8.2 Bilateral and Regional Cooperation Frameworks

Bilateral agreements between central banks provide structured frameworks for cooperation across information sharing, competency building, and operational preparedness .

8.2.1 The MAS-Bank of Thailand Cybersecurity MoU

The Monetary Authority of Singapore (MAS) and the Bank of Thailand (BOT) signed a Memorandum of Understanding in July 2026 to strengthen cybersecurity cooperation and combat digital fraud . The agreement establishes cooperation across three areas:

1. Information Sharing on Cybersecurity and Digital Fraud: Exchange of regulatory updates, incident reports, and threat intelligence relevant to the financial sector .

2. Competency Building: Joint staff training, study visits, and exchange of research and policy insights to strengthen technical capabilities .

3. Operational Preparedness: Joint cross-border cybersecurity and crisis management exercises to strengthen institutional readiness .

MAS Managing Director Chia Der Jiun stated: “Cyber risks and digital fraud are key transnational threats confronting our region and calls for closer collaboration to combat these risks. This MoU will facilitate such enhanced partnership and collaboration between MAS and BOT, reflecting our shared commitment to safeguarding trust and resilience in our financial systems” .

BOT Governor Vitai Ratanakorn added: “As cyber threats and digital fraud continue to evolve rapidly amidst growing financial connectivity and technological advancement, closer collaboration between MAS and BOT will help deepen mutual capabilities and achieve seamless cross-border intelligence exchange to counter emerging threats” .

8.2.2 Regional Cooperation Frameworks

The Executives’ Meeting of East Asia-Pacific Central Banks (EMEAP) Governors’ Meeting, held in Singapore in July 2026, resolved to deepen the exchange of views on digital fraud and scams affecting the financial sector . The meeting identified priority themes including geopolitical tensions, rapid digitalisation and AI adoption, and escalating climate and environmental threats .

The Bank of Thailand and Bank Negara Malaysia have also signed an MoU to deepen their collaboration on cybersecurity efforts, enabling more effective information sharing mechanisms and improving the collective ability to prevent and respond to digital fraud .


8.3 The G7 Post-Quantum Cryptography Roadmap

The G7 Cyber Expert Group published a roadmap in January 2026 to support the orderly transition of the financial sector towards post-quantum cryptographic solutions . The roadmap addresses the significant risk that sufficiently advanced quantum computers could break widely used cryptographic protocols that protect financial systems and data .

8.3.1 Key Timelines

The roadmap recommends:

  • Migration of critical systems and assets: Within the 2030–2032 timeframe .

  • Transition of non-critical systems: By around 2035 .

G7 CEG Co-Chair Duncan Mackinnon stated: “The introduction of quantum computers that can break our encryption tools presents a significant risk to the safety and soundness of our financial ecosystem. This is something we must address together, and the roadmap guidance will be an important reference for organizations to consider as they prepare their systems and data to be quantum resilient” .

8.3.2 Key Elements of the Roadmap

The roadmap sets out a structured approach including:

1. International Coordination: Promoting a consistent approach across jurisdictions and avoiding fragmentation .

2. Alignment with Evolving Standards: Ensuring compatibility with NIST and other PQC standards .

3. Cooperation Between Public and Private Sectors: Engaging financial institutions, critical service providers, and technology vendors .

4. Prioritisation of Critical Systems: Focusing on systems with long-lived or high-value financial data .

5. Cryptographic Agility: Building the ability to update cryptography quickly as standards evolve .

8.3.3 Implications for Financial Institutions

The roadmap makes no distinction between “big bank” and “small bank”—its perspective applies across the financial ecosystem . Financial institutions must:

1. Elevate Quantum Risk to the Boardroom: Boards need clarity on the realities that widely deployed cryptographic algorithms will eventually fail, encrypted data can be harvested today and decrypted later, and replacing cryptography across interconnected systems takes years .

2. Recognise Cryptography as a Supply Chain Risk: Financial institutions don’t operate in isolation—cryptography underpins core banking platforms, payment systems, cloud services, fintech integrations, and third-party providers .

3. Focus on Cryptographic Agility: The post-quantum transition is not a one-time technology upgrade; it is an infrastructure and risk management challenge that touches systems, data, processes, and third-party dependencies .

The G7 CEG commits to monitoring and supporting migration progress, promoting international cooperation, facilitating dialogue and knowledge sharing, and tracking the evolution of threats and technologies .


8.4 The BIS Cyber Resilience Coordination Centre and Capacity Building

The Bank for International Settlements (BIS) Cyber Resilience Coordination Centre (CRCC) is a central hub for central bank cybersecurity collaboration . The CRCC supports central banks through knowledge sharing, collaboration, and operational readiness services.

8.4.1 The 7th Annual BIS Cybersecurity Seminar

In April 2026, the BIS hosted the 7th Annual Cybersecurity Seminar, focusing on three critical themes :

1. AI and Cybersecurity: The dual role of AI as both a threat and a defensive tool. Sessions addressed how AI amplifies existing threats, introduces fragile dependencies, and offers defensive capabilities such as AI-driven identity management .

2. Post-Quantum Cryptography (PQC): Quantum risk reframed as a current resilience priority, emphasising the “Harvest-Now-Decrypt-Later” threat. The seminar provided concrete actions including crypto-asset discovery, data-secrecy horizon mapping, and crypto agility .

3. Cyber Risk Quantification (CRQ): Translating technical exposure into financial and operational terms to inform decisions, budgets, and resilience planning .

8.4.2 Cyber Risk Quantification (CRQ)

CRQ is a practical decision-making tool that structures uncertainty and translates technical exposure into financial and operational terms that leaders can act upon . Key applications include:

  • Prioritisation and Budgeting: Comparing options based on expected loss reduction and return on security investment .

  • Supervision and Stress Testing: Employing institutional models to design sector-wide scenarios while balancing comparability with flexibility .

  • Practical Implementation: Focusing on thin-slice pilots for critical services, leveraging existing operational risk, incident, and business continuity management data .

8.4.3 Central Bank Digital Currencies (CBDCs) and Cybersecurity

The BIS has emphasised that CBDCs are inevitable and that their security is paramount to the future financial system . Key considerations include:

Cyber Risks: CBDCs introduce new levels of security challenges, with the vulnerabilities in the crypto universe serving as a cautionary tale .

Quantum-Resistant Cryptography: The BIS Innovation Hub is exploring integrating quantum-resistant cryptography into CBDC design .

Offline Cyber Resilience: Ensuring CBDCs remain functional and secure even when offline .

Privacy: Essential for public acceptance, especially for retail CBDCs .

The BIS emphasised that cybersecurity and resilience must be shared public goods among connected institutions .


8.5 Future Directions for International Cybersecurity Cooperation

8.5.1 AI-Enabled Threats

As AI increases the severity, scale, and sophistication of cyber threats, international cooperation will become more essential . Key areas include:

  • Shared Threat Intelligence: Rapidly exchanging information about AI-enabled attack patterns.

  • Defensive AI Capabilities: Collaborating on AI tools for threat detection and response.

  • AI Governance: Developing common principles for AI governance in the financial sector, as discussed at the Central Banking Autumn Meetings .

8.5.2 Post-Quantum Cryptography Migration

The G7 roadmap signals a shift in how quantum risk is treated—from a niche technical debate to a governance issue requiring long-term planning . International coordination is essential to ensure consistency across jurisdictions, prevent fragmentation, and build cryptographic agility across interconnected systems . The roadmap is not a regulatory mandate but a framework that will shape how institutions think, plan, and govern this transition .

8.5.3 Collective Incident Response and Recovery

The G7 CCIRR principles promote coordinated collective response to large-scale cyber incidents . Future directions include:

  • Regular Cross-Border Exercises: The G7 has adopted a long-term exercise strategy to increase the frequency and consistency of simulations .

  • Trusted Community: Building relationships between authorities, financial institutions, and third-party providers .

  • Interoperability: Ensuring compatibility with existing frameworks and national protocols .

8.5.4 Sustained International Collaboration

The Central Banking Autumn Meetings reinforced the importance of sustained international collaboration to mitigate systemic cyber risks . Key themes included:

  • Third-Party and Concentration Risks: Addressing vulnerabilities in interconnected financial ecosystems .

  • Geopolitical Volatility: Understanding how geopolitical tensions affect cyber preparedness .

  • AI as a Dual-Use Technology: Managing AI as both a defensive capability and a potential threat vector .

  • Enhanced Intelligence-Sharing Frameworks: Building systems for rapid, trusted information exchange .

The SecurEyes panel highlighted the varied realities and priorities within global financial environments, advancing themes such as climate-linked systemic risks, cybersecurity readiness, open finance models, and the urgency for globally aligned policy approaches .


8.6 Summary

The evolution of international cybersecurity cooperation is defined by several key trends:

1. Expanded Scope: From policy coordination to concrete action plans, including PQC roadmaps and collective incident response principles.

2. Structured Bilateral Frameworks: MoUs formalising cooperation across information sharing, competency building, and operational preparedness.

3. Quantum Readiness: The G7 roadmap establishes clear timelines and priorities for migrating to post-quantum cryptography.

4. AI and Cyber Risk Quantification: Emerging tools and approaches for measuring and managing cyber risk in financial terms.

5. Collective Resilience: A recognition that cyber resilience requires a shared, coordinated effort across the financial ecosystem.

The BIS CRCC, G7 CEG, and bilateral agreements form the foundation of a global effort to safeguard the stability and integrity of the financial system against evolving cyber threats