Central Banks and Cyber Resilience
Why the institutions at the centre of money and settlement require security designed for national-scale financial continuity
Introduction
Central banks sit close to the operational core of the financial system. In addition to setting monetary policy, many provide settlement accounts, operate or oversee payment infrastructure and act as critical nodes in the distribution of liquidity. A cyber incident affecting those functions would therefore have implications far beyond the confidentiality of central-bank data.
Their resilience challenge is unusual because essential services may need to continue during market stress, geopolitical tension or a wider technology disruption. Security has to be designed around national-scale continuity: trusted identities, redundant infrastructure, controlled crisis procedures and the ability to communicate with banks even when normal channels are impaired.
The Monetary Core
Commercial banks ultimately rely on central-bank money for final settlement in many payment systems. That gives central-bank infrastructure a special status because balances held there sit at the base of the domestic monetary hierarchy. Security controls around settlement accounts and payment interfaces therefore protect more than one institution’s assets; they support confidence that obligations across the banking system can be discharged in central-bank money.
Central banks often operate or oversee systems that sit at the core of national payment and settlement infrastructure. Their technology can support reserve accounts, high-value payments, securities operations and emergency liquidity functions. A disruption therefore has a different significance from an outage at an ordinary commercial firm. It can affect the mechanisms through which banks settle with one another and through which monetary policy is transmitted into the financial system.
Payment Systems Cannot Simply Go Offline
A prolonged interruption to high-value settlement can create queues of unpaid obligations and force institutions to conserve liquidity. Even if underlying transactions remain valid, uncertainty about when they will settle can change behaviour across the market. Central banks and system operators therefore design continuity arrangements, participant procedures and fallback capabilities around the assumption that payment services are economically time-critical.
Critical payment systems operate against fixed obligations and market deadlines, so extended interruption can create queues, liquidity hoarding and uncertainty about settlement finality. Central banks therefore design for continuity through redundancy, alternate processing arrangements and carefully controlled recovery procedures. The objective is not merely technical uptime. It is to preserve the ability of the banking system to settle obligations with confidence even when part of the infrastructure is degraded.
Resilience Through Redundancy
Redundancy is valuable only when alternative systems do not share the same hidden dependencies. Separate facilities, communication paths and operational teams can reduce common-mode failure, but they have to be tested under realistic conditions. Cyber resilience adds another requirement: recovery environments must remain trustworthy if an attacker has compromised credentials or management systems in production. The objective is not simply a second copy of infrastructure but an independent path to trusted operation.
True redundancy requires more than duplicate hardware. Independent power, communications, identity services, operating environments and staff procedures may all be needed so that a single failure does not disable both primary and backup arrangements. Central banks also conduct sector exercises because the infrastructure only works if commercial participants can connect and operate under contingency conditions. Resilience is therefore a property of the network, not just of the central institution.
A Central Bank Security Event Is Different
An incident involving a central bank can affect expectations even before any financial loss occurs. Market participants may question payment continuity, liquidity access or the reliability of official communications. That confidence dimension explains why crisis communication and coordination with commercial banks are part of cyber resilience. A central bank has to restore both function and trust in the function.
The confidence dimension is unusually important. Market participants expect central-bank systems to represent the highest standard of operational reliability, and uncertainty about their integrity can influence behavior even before material losses occur. Communication, verification and transparency around recovery are therefore part of incident management. The institution must restore both the system and confidence in the authoritative financial state that the system represents.
Conclusion
Central-bank cyber resilience protects the monetary and settlement infrastructure on which private financial activity depends. Its importance comes from concentration: a small number of systems can support enormous volumes of economic activity. For markets, the relevant risk is therefore not merely whether a central bank experiences an intrusion, but whether the event weakens the availability or trustworthiness of settlement, liquidity and official financial communication.
Cyber resilience at a central bank is part of financial stability because the institution anchors critical settlement and liquidity functions. The relevant question is not whether every attack can be prevented, but whether essential monetary and payment operations can continue or recover without creating uncertainty about finality and balances. That is why central-bank security is ultimately a question of market continuity as much as technology.