The International Monetary Fund published a technical note drawing lessons from its 2021 and 2023 surveys of central banks and supervisory authorities, focused mainly on low- and lower-middle-income countries. The Cybersecurity Preparedness Index improved only marginally from 2.8 to 3.0, with substantial regional variation. While governance, regulation and supervisory arrangements advanced, more than half of surveyed jurisdictions still lacked national or financial sector cybersecurity strategies, and major gaps remained in incident response, information sharing, cyber risk supervision and financial stability analysis. Close to one-third of respondents had no protocols for major financial sector cyber incidents, while cyber information sharing was not prevalent among about three-quarters of authorities. Most jurisdictions did not include cyber risk in stress testing, only 8% had developed cyber maps, and fewer than half had specialized cyber risk supervisory units. The note calls for clearer supervisory powers, stronger on-site and off-site oversight including of critical third parties, mandatory incident reporting and testing frameworks, better threat intelligence and sectorwide response capabilities, and additional resources and training. It also recommends stronger legal and institutional arrangements, including Computer Emergency Response Teams and Financial Sector Computer Emergency Response Teams.
2025-03-21International Monetary Fund
International Monetary Fund survey finds marginal gains in financial sector cybersecurity preparedness, major supervisory gaps persist
An International Monetary Fund technical note found that financial sector cybersecurity preparedness improved only marginally between its 2021 and 2023 surveys. Major gaps persist in cybersecurity strategies, supervision, incident reporting and response, information sharing, testing and financial stability analysis. The note calls for clearer supervisory powers, stronger oversight and institutional arrangements, and more resources and training.