Central banking

Protect the systems the financial system relies on.

A cyber incident at a central bank can spread to the institutions and markets that depend on it. We help central banks strengthen the resilience of the infrastructures they operate, prepare for threat-led testing, and introduce AI into supervision and analysis with the confidentiality and oversight their role requires.

Situations we help with

Across payment and settlement systems; banking supervision; monetary and market operations; and statistics and research.

  • The payment or settlement systems you operate need to show they can resume critical operations within two hours of a severe disruption.
  • A threat-led red-team test is planned, and the board wants confidence in how findings will be prioritised and closed.
  • You expect supervised firms to meet cyber governance standards, and want your own institution to demonstrate the same.
  • Confidential market and supervisory data is shared with service providers and other authorities under different controls.
  • Teams want to use AI for supervisory analysis or research, and there is no agreed rule on which data it may see.

The challenges

Systemic consequences

A central bank operates or oversees payment, settlement, and market systems that other institutions depend on, so a disruption can spread far beyond the institution itself.

Highly sensitive information

Monetary policy, market operations, and supervisory data are valuable to attackers and to states, and premature disclosure can move markets.

Setting the standard

Supervised firms are held to cyber resilience expectations, and the central bank's own arrangements are visible to the firms it supervises.

Sophisticated adversaries

Central banks can attract well-resourced, state-aligned attackers, so defence relies on threat intelligence, testing, and rapid recovery.

The IMF's April 2024 Global Financial Stability Report found that the risk of extreme losses from cyber incidents in the financial sector has increased, and that a severe incident at a major institution could disrupt critical services and spill over to others.

Source: International Monetary Fund, Global Financial Stability Report, April 2024

AI in central banking

Supervisory analysis

The value
Faster review of supervisory returns and reports.
What needs governing
Confidential supervisory data sent to services that are not approved, and findings that rest on unchecked outputs.

Economic research and forecasting

The value
Faster analysis of large and new data sources.
What needs governing
Model outputs used in policy work without validation or a clear owner.

Internal operations

The value
More efficient document handling and correspondence.
What needs governing
Market-sensitive information exposed through tools with broad data access.

AI Factory Design sets which AI services may see confidential data, and how their outputs are checked, so AI can support supervision and analysis without compromising confidentiality. It is part of our AI Governance and Transformation practice.

Regulation that may apply

CPMI-IOSCO cyber resilience guidance

Applies to
Financial market infrastructures, including systemically important payment systems, central securities depositories, and central counterparties, some of them operated by central banks.
What it asks
Governance, identification, protection, detection, response and recovery, testing, situational awareness, and learning, designed to resume critical operations within two hours of a disruption and complete settlement by the end of the day.
Timing
Published in June 2016.

ECB cyber resilience oversight expectations

Applies to
Financial market infrastructures overseen by the Eurosystem.
What it asks
Puts the CPMI-IOSCO guidance into practice at three maturity levels: evolving, advancing, and innovating.
Timing
Published in December 2018.

TIBER-EU and CBEST

Applies to
Central banks, financial market infrastructures, and financial entities taking part in threat-led red-team testing in the EU and the UK.
What it asks
Controlled attacks on live production systems, based on threat intelligence, to test detection, response, and recovery.
Timing
TIBER-EU was updated in February 2025 to align with DORA's threat-led penetration testing rules.

We use analytics cookies to understand how this site is used. See our Privacy Notice for details. You can change your choice at any time.