Protect the systems the financial system relies on.
A cyber incident at a central bank can spread to the institutions and markets that depend on it. We help central banks strengthen the resilience of the infrastructures they operate, prepare for threat-led testing, and introduce AI into supervision and analysis with the confidentiality and oversight their role requires.
Situations we help with
Across payment and settlement systems; banking supervision; monetary and market operations; and statistics and research.
- The payment or settlement systems you operate need to show they can resume critical operations within two hours of a severe disruption.
- A threat-led red-team test is planned, and the board wants confidence in how findings will be prioritised and closed.
- You expect supervised firms to meet cyber governance standards, and want your own institution to demonstrate the same.
- Confidential market and supervisory data is shared with service providers and other authorities under different controls.
- Teams want to use AI for supervisory analysis or research, and there is no agreed rule on which data it may see.
The challenges
Systemic consequences
A central bank operates or oversees payment, settlement, and market systems that other institutions depend on, so a disruption can spread far beyond the institution itself.
Highly sensitive information
Monetary policy, market operations, and supervisory data are valuable to attackers and to states, and premature disclosure can move markets.
Setting the standard
Supervised firms are held to cyber resilience expectations, and the central bank's own arrangements are visible to the firms it supervises.
Sophisticated adversaries
Central banks can attract well-resourced, state-aligned attackers, so defence relies on threat intelligence, testing, and rapid recovery.
The IMF's April 2024 Global Financial Stability Report found that the risk of extreme losses from cyber incidents in the financial sector has increased, and that a severe incident at a major institution could disrupt critical services and spill over to others.
AI in central banking
Supervisory analysis
- The value
- Faster review of supervisory returns and reports.
- What needs governing
- Confidential supervisory data sent to services that are not approved, and findings that rest on unchecked outputs.
Economic research and forecasting
- The value
- Faster analysis of large and new data sources.
- What needs governing
- Model outputs used in policy work without validation or a clear owner.
Internal operations
- The value
- More efficient document handling and correspondence.
- What needs governing
- Market-sensitive information exposed through tools with broad data access.
AI Factory Design sets which AI services may see confidential data, and how their outputs are checked, so AI can support supervision and analysis without compromising confidentiality. It is part of our AI Governance and Transformation practice.
Regulation that may apply
CPMI-IOSCO cyber resilience guidance
- Applies to
- Financial market infrastructures, including systemically important payment systems, central securities depositories, and central counterparties, some of them operated by central banks.
- What it asks
- Governance, identification, protection, detection, response and recovery, testing, situational awareness, and learning, designed to resume critical operations within two hours of a disruption and complete settlement by the end of the day.
- Timing
- Published in June 2016.
ECB cyber resilience oversight expectations
- Applies to
- Financial market infrastructures overseen by the Eurosystem.
- What it asks
- Puts the CPMI-IOSCO guidance into practice at three maturity levels: evolving, advancing, and innovating.
- Timing
- Published in December 2018.
TIBER-EU and CBEST
- Applies to
- Central banks, financial market infrastructures, and financial entities taking part in threat-led red-team testing in the EU and the UK.
- What it asks
- Controlled attacks on live production systems, based on threat intelligence, to test detection, response, and recovery.
- Timing
- TIBER-EU was updated in February 2025 to align with DORA's threat-led penetration testing rules.
Recommended engagements
Zero Trust Transformation
Separates payment, market, and supervisory systems, limiting how far an intrusion can spread.
View engagementAI Factory Design
Sets which AI services may handle confidential supervisory and market data, and how their outputs are checked.
View engagementBoard Cyber Governance Review
Tests the board's oversight of cyber resilience against the standards the institution expects of others.
View engagementCyber Resilience Executive Exercise
Rehearses the decisions a severe disruption to payment or settlement systems would force on executives.
View engagement