Learning Objectives:

  • Understand the international standards and best practices for cyber resilience.

  • Identify the key recommendations of the CPMI-IOSCO Cyber Guidance.

  • Recognise the role of the IMF and FATF in cybersecurity governance.

  • Apply international standards to central bank cyber risk management.

8.1 The CPMI-IOSCO Cyber Guidance

The Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) released the first internationally agreed guidance on cyber resilience for financial market infrastructures (FMIs) . The Cyber Guidance aims to add momentum to and instil international consistency in the industry’s ongoing efforts to enhance FMIs’ ability to pre-empt cyber attacks, respond rapidly and effectively to them, and achieve faster and safer target recovery objectives .

Key Concepts:

  • Board and Senior Management Attention: Sound cyber governance is key. Board and senior management attention is critical to a successful cyber resilience strategy .

  • Recovery Capability: The ability to resume operations quickly and safely after a successful cyber attack is paramount .

  • Threat Intelligence and Testing: FMIs should make use of good-quality threat intelligence and rigorous testing .

  • Continuous Improvement: Cyber resilience requires a process of continuous improvements .

  • Collective Endeavour: Cyber resilience cannot be achieved by an FMI alone; it is a collective endeavour of the whole “ecosystem” .

  • Culture of Cyber Risk Awareness: FMIs should aim to instil a culture of cyber risk awareness and demonstrate ongoing re-evaluation and improvement of their cyber resilience at every level within the organisation .

8.2 The Cyber Guidance and the PFMI

The Cyber Guidance is supplemental to the Principles for Financial Market Infrastructures (PFMI) . It primarily addresses governance (Principle 2), the framework for the comprehensive management of risks (Principle 3), settlement finality (Principle 8), operational risk (Principle 17), and FMI links (Principle 20) .

The Cyber Guidance provides authorities with a set of internationally agreed guidelines to support consistent and effective oversight and supervision of FMIs in the area of cyber risk .

8.3 The Role of the IMF

The IMF plays a key role in promoting cybersecurity in the financial sector through its surveillance, technical assistance, and standard-setting activities. The IMF’s Financial Sector Assessment Program (FSAP) assesses cybersecurity frameworks in member countries.

8.4 The Role of the FATF

The Financial Action Task Force (FATF) has issued guidance on the intersection of cybersecurity and anti-money laundering/counter-terrorist financing (AML/CFT). The FATF’s recommendations address the risks posed by cyber-enabled fraud and the use of virtual assets for illicit purposes.

8.5 Best Practice Benchmarking

The adoption of internationally recognised standards is common practice in financial institutions. ISO 27001, the NIST Cybersecurity Framework, and CIS Controls are the most common frameworks for implementing cybersecurity governance . While global standards provide a foundational structure, regional regulatory bodies have developed complementary frameworks tailored to local contexts and requirements