Technical Notes and Manuals

Strengthening Cybersecurity: Lessons from the Cybersecurity Survey

By Rangachary Ravikumar

March 21, 2025

Download PDF More Formats on IMF eLibrary Order a Print Copy

Preview Citation

Format: Chicago

Rangachary Ravikumar. "Strengthening Cybersecurity: Lessons from the Cybersecurity Survey", Technical Notes and Manuals 2025, 006 (2025), accessed March 23, 2025, https://doi.org/10.5089/9798400296864.005

Export Citation

  • ProCite
  • RefWorks
  • Reference Manager
  • BibTex
  • Zotero
  • EndNote

Disclaimer: This Technical Guidance Note should not be reported as representing the views of the IMF. The views expressed in this Note are those of the author(s) and do not necessarily represent the views of the IMF, its Executive Board, or IMF management.

Summary

This technical note and manual (TNM) draws lessons from cybersecurity surveys conducted by the Monetary and Capital Markets Department (MCM) to provide advice to central banks, supervisory authorities and policy makers seeking to strengthen cybersecurity of their financial sectors. The TNM covers various measures adopted by central banks and supervisory authorities, lessons learned from the survey results, and further efforts to be made in strengthening cybersecurity, besides providing references to work by international standard setting bodies. Concerted efforts are needed to (i) develop national and financial sector focused cybersecurity strategies; (ii) build cyber risk regulatory and supervisory capacity; and (iii) address resource constraints. Legal and regulatory clarity regarding supervisory powers; adequate attention by top management; and resource augmentation will help supervisory authorities address existing gaps in these areas. Central banks and supervisory authorities also need to develop processes to better understand the threat landscape on a continuous basis. Capacity needs to be augmented in: (i) conducting cyber exercises and tests; (ii) helping build sector-wide incident response capabilities; and (iii) building cyber maps. In addition, special attention is needed towards establishing and nurturing robust institutional arrangements, in terms of enabling legal provisions to criminalize cyberattacks and establishing Computer Emergency Response Teams and Financial Sector CERTs.

Subject: Cyber risk, Economic sectors, Financial Sector, Technology

Keywords: Cyber incidents, Cyber resilience, Cyber risk, Cyber risk regulation, Cybersecurity, Financial sector, Financial sector cyber strategy, National cyber strategy, Operational resilience

Publication Details