Central Bank Training · Track D · OperationsPaid Event

Beyond Prevention: Cyber Security & Resilience

Financial-Sector Cyber Resilience

15–16 February 2027 · 2 daysNairobi, Kenya (or in-country delivery)
← Back to Events

Location

Nairobi, Kenya (or in-country delivery)

Get Directions

About This Event

“Assume the breach, then prove your sector can keep paying, settling and trading.”

A two-day programme for central bank staff who must move from preventing cyber attacks to withstanding them. You will examine the evolving threat landscape facing the financial sector, how to test incident response through exercises and threat-led testing, and how public-private information sharing strengthens resilience across the system.

What You'll Explore

A threat profile for your financial sector, mapped to MITRE ATT&CK

An incident-response checklist tested in a live tabletop exercise

A view of how threat-led penetration testing could work in your market

A draft design for a public-private information-sharing arrangement

A board briefing outline on cyber resilience and recovery objectives

Who Should Attend

Open to all qualifying staff, particularly: CISOs, Heads of IT Security, Operational Risk Managers, Financial Stability and Supervision Staff, Payment System Overseers, Incident Response Leads.

Why This Course Matters

Resilience Over Prevention

No perimeter stops every attack, so the real test is how quickly you detect, respond and recover. Planning for the breach means critical services keep running while the investigation happens.

Tested Incident Response

Tabletop exercises and threat-led penetration testing show whether your playbooks work under pressure. Testing now means the first time your team runs the plan is not during a live incident.

Sector Information Sharing

Attackers reuse tools and tactics across institutions, so one bank's warning is another's defence. A trusted sharing arrangement gives the whole sector earlier notice and a coordinated response.

Programme

Day 1 am

The evolving cyber threat landscape for finance

You will profile the threats facing African financial sectors, from ransomware and payment fraud to supply-chain and state-linked attacks, using MITRE ATT&CK to map how real intrusions unfold.

Day 1 pm

From prevention to resilience: frameworks & governance

You will work through the NIST Cybersecurity Framework 2.0 and CPMI-IOSCO cyber guidance, defining board oversight, recovery objectives and the governance that turns security into resilience.

Day 2 am

Incident-response testing & threat-led exercises

You will run a tabletop exercise on a simulated attack against a payment system, then review how threat-led penetration testing schemes such as TIBER-EU validate defences against realistic adversaries.

Day 2 pm

Public-private information sharing & sector coordination

You will design an information-sharing arrangement between the central bank, supervised firms and national CERTs, setting out trust rules, reporting timelines and the crisis communication plan.

Standards & Faculty Benchmark

NIST Cybersecurity Framework 2.0

The govern, identify, protect, detect, respond and recover structure used across the programme.

CPMI-IOSCO Cyber Resilience Guidance for FMIs

The 2016 guidance on cyber resilience that overseers apply to payment and settlement systems.

G7 Fundamental Elements of Cybersecurity

G7 elements for the financial sector, including those on threat-led testing and third-party risk.

These frameworks are the reference points supervisors, overseers and international peers use to judge cyber resilience in the financial sector. Aligning to them means your testing, reporting and sharing arrangements speak the same language as the institutions you coordinate with.

Is This Right for You?

  • ☑You oversee cyber risk in the central bank or supervised firms
  • ☑Your institution is building a sector cyber-resilience strategy
  • ☑You lead or support incident response and crisis communication

Good to Know

No deep technical background is needed; the programme is pitched at governance, oversight and response rather than hands-on security engineering. You leave with a tested incident-response checklist and a draft design for a sector information-sharing arrangement.

The Bottom Line

Return with a response plan that has already survived a simulated attack, and a sharing model the sector can sign up to.

Recommended For

Open to all qualifying staff, particularly: CISOs, Heads of IT Security, Operational Risk Managers, Financial Stability and Supervision Staff, Payment System Overseers, Incident Response Leads.

Event Date

15–16 February 2027

2 days

Select Tickets

Ticket Type

Individual

USD 1,500 per participant + 16% VAT

USD 1,740

Incl. 16% VAT