NIBAF Pakistan Holds SBP Cyber Security Vigilance Session Under CROS 1

NIBAF Pakistan conducted a specialized technical session on “SBP’s Cyber Security Vigilance” at its Islamabad Campus on August 31, 2026. The session was organised under the Cyber Risk Officers Scheme (CROS-1) and focused on the supervisory and regulatory aspects of cybersecurity within Pakistan’s financial sector. The programme provided participants with an opportunity to develop a stronger understanding of cybersecurity vigilance and the measures required to strengthen the security posture of regulated financial institutions.

The technical session was designed around the State Bank of Pakistan’s supervisory framework for cybersecurity vigilance. As financial institutions increasingly rely on digital systems and technology based services, cybersecurity supervision has become an important component of maintaining the security and resilience of the financial sector. The session focused on how supervisory mechanisms can be used to assess cybersecurity preparedness, identify potential vulnerabilities and support financial institutions in strengthening their overall cyber risk management practices.

The programme was facilitated by Farjad Feroz, Joint Director, CySD, State Bank of Pakistan. His participation provided the trainees with insights into SBP’s approach to cybersecurity vigilance and the regulatory expectations applicable to financial institutions. The session covered key areas relevant to officers working with cyber risk, allowing participants to examine cybersecurity from a supervisory perspective and understand the role of regulatory oversight in addressing emerging digital threats.

A key area of the session was threat intelligence sharing, which plays an important role in helping financial institutions remain informed about emerging cyber risks. Sharing relevant threat intelligence can support institutions in identifying potential threats and taking timely measures to strengthen their security controls. The session highlighted the importance of structured information sharing within the financial sector as part of a broader cybersecurity vigilance framework.

Incident reporting standards were also addressed during the technical module. Effective reporting of cybersecurity incidents allows relevant stakeholders to understand the nature and potential impact of cyber events while supporting an appropriate response. The session provided participants with an understanding of the importance of reporting standards within SBP’s supervisory framework and the role such processes play in maintaining visibility over cybersecurity incidents affecting regulated financial institutions.

The training also focused on proactive threat mitigation strategies designed to reinforce cybersecurity postures across financial institutions. Proactive mitigation involves identifying potential threats and vulnerabilities before they result in significant operational or security impacts. For financial institutions, this approach is particularly important because digital systems support a wide range of banking and financial activities, making effective cybersecurity controls an important part of operational resilience.

The session formed part of the Cyber Risk Officers Scheme (CROS-1), which provides specialised technical exposure to professionals involved in cyber risk and related areas. By focusing specifically on SBP’s cybersecurity vigilance framework, the programme provided participants with knowledge relevant to the supervisory responsibilities associated with cybersecurity within the financial sector.

The discussion around cybersecurity vigilance also highlighted the relationship between regulatory supervision and institutional cyber resilience. Financial institutions operate complex technology environments and face an evolving range of cyber risks. Effective supervision requires institutions to maintain appropriate security measures, monitor potential threats, report incidents through established channels and take proactive steps to reduce exposure. These areas were brought together during the NIBAF Pakistan session to provide participants with a broader understanding of cybersecurity oversight.

Threat intelligence, incident reporting and proactive mitigation are closely connected within an effective cybersecurity framework. Information about emerging threats can help institutions identify areas requiring attention, while established reporting procedures can provide regulators and relevant stakeholders with timely visibility into incidents. Proactive mitigation measures can then help institutions address identified vulnerabilities and strengthen their defences against potential cyber events.

NIBAF Pakistan’s technical session provided CROS-1 participants with an opportunity to examine these issues from the perspective of financial sector regulation and supervision. The involvement of a State Bank of Pakistan official as facilitator further connected the training with the regulatory framework governing cybersecurity vigilance within regulated financial institutions.

The August 31 session reflects the importance of specialised cybersecurity training as Pakistan’s financial sector continues to expand its use of digital technologies. With financial institutions increasingly dependent on technology based systems, maintaining effective cyber risk management and regulatory oversight remains an important part of financial sector stability. The session at NIBAF Pakistan’s Islamabad Campus focused on strengthening participants’ understanding of SBP’s cybersecurity vigilance framework and the measures required to reinforce cybersecurity practices across regulated institutions.

Follow the PakBanker Whatsapp Channel for updates across Pakistan’s banking ecosystem.