## tarea2025066-print-pdf

## Source details

**Canonical URL:** [tarea2025066-print-pdf](https://www.imf.org/-/media/files/publications/tar/2025/english/tarea2025066-print-pdf.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/tar/2025/english/tarea2025066-print-pdf.pdf.md)
- [Structured JSON version](/-/media/files/publications/tar/2025/english/tarea2025066-print-pdf.pdf.json)

---

### Preface — Mission and scope
- A Technical Assistance (TA) mission from the Monetary and Capital Markets Department (MCM) of the International Monetary Fund (IMF) visited Lima, Peru during the period September 18 to October 1, 2024. Virtual meetings were also held during the period August 13 to 21, 2024.
- Purpose: advise the authorities in developing a comprehensive cybersecurity strategy for the financial sector in Peru.
- Activities:
  - Reviewed the cyber posture of Peru to assess current capabilities and challenges.
  - Met with financial sector authorities and external stakeholders to discuss developments and issues relating to the cyber resilience of the financial sector (Annex 1).
  - Recommended actions to support the development of a comprehensive cybersecurity strategy for the financial sector in Peru and for the SBS.
- Principal engagements included meetings with Mr. Sergio Espinosa Chiroque (Superintendent), senior management and staff from the SBS, and representatives from the public and private sectors.
- The mission produced this TA report summarizing findings and recommendations.

### Context and recent incidents
- Documented attack types include: denial of service attacks, data breaches, phishing scams, malware, ransomware, fake fingerprints, and technology disruptions.
- Major 2023 incident:
  - Data breach at the National Registry of Identification and Civil Status (RENIEC) involving exposure of sensitive personal information, including fingerprints.
  - An estimate of 14 million civil registration records (from a total of 60 million) maintained by municipal governments have been digitized.
  - RENIEC systems are linked with identity management and public health insurance systems where 11 million workers (beneficiaries) could collect their payments from the nationwide network of branches of a state bank.
- Incident counts from internal records:
  - 10 incidents occurred in 2023.
  - six incidents during 2024 (as of August).
- Consequences and trends:
  - Compromised personal information facilitated impersonation tactics, including fake fingerprints to open bank accounts.
  - Impersonation attacks and SIM swap scams in telecommunications during 2022 and 2023 produced significant user losses.
  - SBS prohibited the sending of one-time passwords via short message services in response.
  - Cyber-attacks associated with impersonations, AI, and supply chain are areas of growing concern.

### Key findings by element (summarized)
- Element 1: Cybersecurity Strategy and Framework
  - Financial authorities (SBS, BCRP, SMV, MEF) share collective interest in sector cyber resilience but no forum currently exists to coordinate cybersecurity strategies.
  - Recommendation: establish a high-level inter-agency committee and a public-private Cyber Resilience Forum.
- Element 2: Governance
  - The SBS faces resource constraints amid continued digitalization and rising cybersecurity risks.
  - An increase of    five additional staff are needed to support the onsite inspection of cybersecurity risks of supervised entities.
  - Stakeholders suggested more comprehensive, detailed, and precise cybersecurity regulation.
- Element 3: Risk and Control Assessment
  - Information on critical service providers has been collected, but cyber mapping of the financial system and cyber network remains to be carried out.
  - Cyber mapping would help identify interconnectedness, concentration risks, and potential systemic impacts.
- Element 4: Monitoring
  - Cyberattacks targeting FIs are documented, but a comprehensive Cyber Threat Landscape report is lacking.
  - Prioritization has shifted toward off-site supervision; an increase in onsite supervision of cybersecurity risks is needed, with priority for domestic systemically important banks.
  - The lack of a red-team testing framework leaves the sector vulnerable; a comprehensive testing framework such as threat-led penetration testing is recommended.
- Element 5: Response
  - A national CERT for public institutions exists, but no sectoral CERT for the financial sector is envisaged in the draft national strategy.
  - Systemically important FIs and FMIs are not obligated to report incidents to the national CERT.
  - Recommendation: establish a dedicated CERT for the financial sector (FinCERT) integrated with the national CERT.
- Element 6: Recovery
  - A large-scale cyberattack simulation exercise was conducted in 2022, but participation was incomplete (excluding the securities regulator, capital market entities, and microfinance companies) and communications/coordination were not sufficiently tested.
  - Recommendation: design more comprehensive, inclusive cross-sector and cross-border exercises.
- Element 7: Information Sharing
  - A basic cyber information-sharing platform introduced in 2022 focuses on phishing and lacks useful detail.
  - No formal cyber incident reporting framework with a standardized format currently exists.
  - Recommendation: implement a sector-wide threat intelligence information-sharing platform and a standardized incident reporting framework.
  - Public awareness campaigns are piecemeal; a comprehensive cyber education and public awareness program, including a Cyber Month, is needed.
- Element 8: Continuous Learning
  - Cybersecurity strategy should be regularly reviewed and updated given evolving threats.
  - With generative AI and quantum computing emerging, studies and advisories to FIs on use, opportunities, and risks are recommended.

### Recommendations (time frames preserved)
- Time Frame definitions: Short-Term (ST): 1 year; Medium Term (MT): around 2 to 3 years; Long Term (LT): around 4 to 5 years.
- Element 1: Cybersecurity Strategy and Framework
  - Prioritize the establishment of a high-level inter-agency committee to drive national cybersecurity initiatives for the financial sector. (SBS, BCRP, SMV, MEF) — ST
  - Establish a public-private Cyber Resilience Forum that fosters active participation, collaboration and sharing with trusted stakeholders. (SBS, BCRP, SMV) — ST
- Element 2: Governance
  - Increase resources for cybersecurity risk supervision and oversight. (SBS) — ST
  - Enhance cybersecurity regulation. (SBS) — MT
- Element 3: Risk and Control Assessment
  - Map the financial system and cyber network. (SBS) — ST
- Element 4: Monitoring
  - Develop a Cyber Threat Landscape Report (SBS, BCRP, SMV) — MT
  - Increase onsite supervision of cybersecurity risks with a commensurate increase in capacity and resources. (SBS) — MT
  - Develop a cyber testing framework for controlled cyberattacks that simulates real-world threats. (SBS) — MT
- Element 5: Response
  - Establish a dedicated CERT for the financial sector (FinCERT) and integrate it with the national CERT. (SBS, BCRP, SMV, MEF) — MT
- Element 6: Recovery
  - Conduct comprehensive cyberattack simulation exercises, expand participation and develop a cross-authorities response framework for sector cyber resilience. (SBS) — MT
- Element 7: Information Sharing
  - Implement a sector-wide threat intelligence info-sharing platform and a standardized incident reporting framework. (SBS, BCRP, SMV) — ST
  - Implement a Comprehensive Cyber Education and Public Awareness Program, including a Cyber Month (SBS, BCRP, SMV, MEF) — ST
- Element 8: Continuous Learning
  - Conduct a formal survey to quantify cybersecurity skills gaps and develop a cyber competency roadmap for the financial sector. (SBS) — MT
  - Establish regular review for cybersecurity strategy and framework to be responsive to emerging threats. (SBS) — ST
  - Study and issue advisories to financial institutions on the use, opportunities and risks of generative artificial intelligence and quantum computing in the financial sector. (SBS) — MT

### Implementation considerations
- Prioritization and sequencing of recommendations should be decided by authorities and stakeholders relative to legal mandates and resource availability.
- Annual reviews, ongoing stakeholder consultations, and monitoring of the evolving cyber threat landscape are advised.
- Implementation will require pooling resources and sector-wide coordination.

### Supervisory and oversight framework — Authorities and scope
- Main financial-sector cybersecurity authorities:
  - Superintendency of Banking Insurance and Private Pension Fund Administrators (SBS):
    - Oversees around 109 entities (of which 88 entities are onsite), including four domestic systemically important banks.
  - Central Reserve Bank of Perú (BCRP):
    - Designates, regulates, and supervises three systemically important payment systems: (i) Sistema LBTR, (ii) Cámara de Compensación Electrónica S.A (CCE), and (iii) Sistema de Liquidación Multibancaria de Valores (SLMV).
  - Superintendence of Securities Market (SMV):
    - Supervises around 81 entities associated with clearing and settlement, stock exchange, fund management, mutual funds, investment, collective funds, securitization, pricing, and risk classification.
- Other relevant governmental authorities with cybersecurity roles:
  - Ministry of Economy and Finance (MEF).
  - National Authority of Personal Data Protection (ANPD).
  - National Digital Security Center (CNSD).
  - Supervisory Agency for Private Investment in Telecommunications (OSIPTEL).
  - Competition and Consumer Protection Authority (INDECOPI).
- Peru is categorized as Tier 3 in ITU Global Cybersecurity Index 2024 (basic cybersecurity commitments).

### Element 1: High-Level Inter-Agency Committee and Cyber Resilience Forum
- High-Level Inter-Agency Committee — Recommendation:
  - Establish a committee with SBS, BCRP, SMV and MEF as core members; invite other agencies (e.g., CNDS) as appropriate.
  - Committee design and functions:
    - Senior officials (heads and deputies) with a secretariat resourced to support the committee.
    - Mandate to coordinate key national cybersecurity initiatives tailored to the financial sector, including FinCERT, information-sharing platforms, and sector-wide incident response.
    - Conduct an initial stock-take of existing capabilities and initiatives across agencies to avoid duplication.
    - Use structured discussions and workshops to build consensus on ownership and resource issues; designate lead or co-leading agencies or consider rotating leadership.
    - Coordinate with non-financial sector agencies engaged in national security and critical infrastructure.
- Industry Forum — Recommendation:
  - Establish a public-private Cyber Resilience Forum with senior executives from major FIs, relevant government officials, and cybersecurity experts.
  - Ensure senior membership with decision-making authority, clear terms of reference, steering committee, and dedicated secretariat.
  - Build trust via open communication, FI involvement in decision-making, confidentiality assurances, and feedback mechanisms.
  - Monitor and evaluate the forum's effectiveness by participation, initiative impact, and sector resilience improvements.

### Element 2: Governance — Staffing, regulation, and supervisory resourcing
- SBS cybersecurity staffing (current):
  - Department of Information Systems and Security Supervision: one department head, 15 supervisors, and two interns.
  - Around 4 staff work full time in developing cybersecurity tools for off-site supervision, and 4 staff on information security supervision.
- Recommendation (staffing):
  - Increase resources for cybersecurity risk supervision:
    - Based on discussions with the authorities, five additional staff are needed to complement work in the Department of Information Systems and Security Supervision.
    - Additional resources to support onsite inspection of cybersecurity risks, particularly for domestic systemically important banks.
  - Staffing model: combination of generalist supervisory skills complemented with technical specialists; upskilling in cybersecurity and data sciences; hiring, training, and retention strategies.
- Regulatory observations:
  - Existing cybersecurity regulations are principle-based; key instruments include:
    - 2021 Information Security and Cybersecurity Regulation (Regulation 504-2021-SBS) (Last Update: June 2024)
    - 2020 Business Continuity Management Regulation (Regulation 877-2020-SBS)
    - 2019 Operational Risk Management (Regulation 2116-2009-SBS)
    - and other circulars/regulations listed in the supervisory architecture.
  - Industry feedback: regulations have been difficult to interpret and implement; request for more detailed proportionality guidance and minimum standards; gaps include lack of specific cybersecurity requirements for payment processors.

### Element 3: Risk and Control Assessment — Cyber mapping
- Current actions:
  - SBS has collected information on critical service providers by entity and determined their concentration.
  - No comprehensive firm-level or sector-wide cyber mapping has been completed.
- Recommendation: Conduct cyber mapping in two steps:
  1. Firm-level: in-depth understanding of a firm’s ICT systems and ICT risk management.
  2. Sector-wide: consolidate financial and technical connections to form a systemwide financial sector network map.
- Mapping benefits:
  - Identify interconnectedness and concentration risks in third-party service providers.
  - Estimate impact of cyber-attacks on nodes and potential contagion channels (liquidity shortage, write-downs, defaults).
  - Identify key nodes (payment and settlement systems, clearing FIs, underpinning technology systems) and prepare contingency/protection mechanisms.

### Element 4: Monitoring — Cyber Threat Landscape and Supervisory Assessments
- Cyber Threat Landscape — Recommendation:
  - Develop a Cyber Threat Landscape for the Peruvian Financial Sector Report:
    - Tailored to jurisdictional threats, key participants (banks, broker-dealers, FMIs, third parties), threat actors, tactics, techniques, procedures, and vulnerabilities.
    - Use to support scenario development, playbook building, and exercising.
- Supervisory assessments — current practice:
  - On average, the SBS conducts 10 inspections where the scope of assessment is information security or cybersecurity.
  - Off-site supervision has increased; onsite inspections remain resource intensive and limited.
  - FIs are rated annually on information security management practices; scores feed into operational risk ratings.
  - Supervisory proportionality via three regimes: Simplified Regime, General Regime, Reinforced Regime.
- Recommendation:
  - Increase onsite supervision of cybersecurity risks with corresponding capacity and resource increases.
  - Prioritize domestic systemically important banks.

### Testing framework — current situation and recommendations
- Current situation:
  - FIs required to conduct vulnerability scans and penetration tests when introducing new products or making changes, but not regularly; no requirement for Red team tests.
  - SBS conducts limited security reviews on mobile applications via its laboratory; scope subset of OWASP top ten mobile security framework.
  - No structured sector-wide testing framework; absence of comprehensive red-team testing limits insight into real-world resilience.
- Recommendations:
  - Prioritize vulnerability assessments and standard penetration tests while developing a long-term Threat-Led Penetration Testing (TLPT) framework (also known as Red Team Testing).
  - Introduce TLPT gradually, focusing first on higher-risk FIs; draw on models like EU-TIBER and UK CBEST.
  - Design TLPT framework elements:
    - Red, purple, and gold team exercises informed by threat intelligence.
    - Certification system for service providers and oversight team.
    - Working group within the Cyber Resilience Forum to design the framework.
    - Secure platform to share anonymized insights from TLPT exercises.
  - Use testing results to enhance supervisory assessments and feedback loops.

### Element 5: Response — FinCERT and cross-authorities coordination
- Current situation:
  - CNDS has a national CERT primarily serving public institutions; no sectoral CERTs are envisaged in its draft strategy.
  - Financial sector requires faster, finance-tailored responses; SBS, BCRP and SMV do not currently agree who should lead a FinCERT.
  - FIs are not required to report cyber incidents to the national CERT.
- Recommendation — FinCERT:
  - Establish a dedicated FinCERT integrated with the national CERT.
  - Key actions:
    - Form a FinCERT Project Task Force to define roles, responsibilities and protocols.
    - Review legal/regulatory frameworks to enable mandated reporting and collaboration.
    - Secure funding, possibly via public-private partnerships.
    - Develop Standard Operating Procedures (SOPs) linking business continuity and risk management.
    - Pilot the CERT with selected institutions before full implementation.
  - Integration measures:
    - Formal communication channels between FinCERT and national CERT.
    - Integration protocols for incident collaboration, intelligence sharing, and joint exercises.

### Element 6: Recovery — Exercises and Cross-Authorities Response Framework
- Current situation:
  - SBS requires FIs to integrate cyberattack scenarios into their business continuity plans (mandate introduced in 2020).
  - Large-scale exercise in 2022 included commercial banks, select non-bank FIs, ASBANC, SBS, MEF and the BCRP.
  - Non-participants in 2022: SMV, the stock exchange, Cavali, capital market firms and microfinance companies.
  - Observations: exercise enhanced individual preparedness but did not sufficiently test sector response, communication, and coordination.
- Recommendation:
  - Conduct comprehensive cyberattack simulation exercises, expand participation, and develop a Cross-Authorities Response and Coordination Framework among SBS, BCRP, SMV and MEF.
  - Consider simulation scenarios that stress-test system-wide liquidity when critical FIs and FMIs are severely disrupted.
  - Plan and conduct cross-sector and cross-border exercises with foreign regulators and broaden cooperation with the telecommunications regulator beyond authentication issues.

### Element 7: Information Sharing, Incident Reporting, and Public Awareness
- Information sharing — current situation:
  - SBS gathers cybersecurity incident information primarily from FI reports when there are significant losses, fraud, reputational damage, or operational disruptions.
  - On average, SBS receives between 5 to 10 such incident reports annually.
  - Forensic reports are required when incidents are reported.
  - In June 2023, SBS introduced a basic information-sharing platform focused on phishing; platform lacks detail and is not real-time or alerting.
  - Platforms are fragmented: ASBANC’s platform is privately operated and excludes other FIs; some FIs are FS-ISAC members with minimal engagement.
  - No formal standardized cyber incident reporting framework has been implemented.
- Recommendations:
  - Implement a sector-wide threat intelligence information-sharing platform and a standardized incident reporting framework.
    - Assess SBS’ and ASBANC’s existing platforms to decide enhance/merge/build new.
    - Establish protocols for classifying and categorizing data; encourage FI participation via incentives and training.
    - Integrate the platform with the national CERT and international threat intelligence networks; adopt frameworks like the FSB’s FIRE standard.
- Public awareness — recommendations:
  - Implement a Comprehensive Cyber Education and Public Awareness Program, including declaring every September a cybersecurity month.
  - Lead initiative by the High-level Interagency Committee with banks, FIs, associations, government agencies, and financial authorities.
  - Provide ongoing, dynamic campaigns addressing emerging threats (e.g., AI-powered attacks); FIs to adopt communication guidelines (e.g., avoid use of links) to mitigate phishing.

### Element 8: Continuous Learning, Skills, and Innovation
- Current situation — skills:
  - No formal survey has quantified the cybersecurity skills shortage in the financial sector.
  - Indicative observations:
    - Heads of cybersecurity at three of the four systemically important banks are from foreign countries (Colombia, Brazil, and Spain).
    - Movement of cybersecurity professionals between FIs indicates a competitive market; smaller firms face shortages.
    - Authorities estimate the financial sector may still face a significant shortfall in cybersecurity professionals, potentially in the hundreds, though exact figures are undetermined without a formal survey.
  - SBS initiatives: promoted training events, supported some international certifications, allocated a shared annual training budget, and occasionally acquired online training platforms; budget constraints limit sustainability.
- Recommendations — skills and training:
  - Conduct a formal survey to quantify cybersecurity skills gaps and develop a cyber competency roadmap for the financial sector.
  - Implement a national cybersecurity training program tailored to the financial sector; collaborate with universities, private companies, and international partners.
  - Develop market for cyber qualifications, accreditation, and certification; establish centers of excellence and public awareness campaigns.
  - Provide financial incentives for obtaining industry-recognized certifications.
- Innovation and future-proofing:
  - Study and issue advisories on generative AI and quantum computing for FIs; collaborate with CNSD, ASBANC, private companies, and universities.
  - Encourage FIs to assess and mitigate generative AI and quantum computing risks and develop implementation best-practice guidelines.
  - Monitor technological advancements and issue best practice guidelines and advisories as appropriate.

### International references and testing frameworks
- Guidance and standards informing recommendations include:
  - CPMI-IOSCO Guidance on Cyber Resilience for FMIs (June 2016).
  - FSB Recommendations to Achieve Greater Convergence in Cyber Incident Reporting: Final Report (April 2023).
  - IMF Cybersecurity Risk Supervision (2019).
  - FSB stocktake of cybersecurity regulation and G7 Fundamental Elements of Cybersecurity for the Financial Sector.
- International testing frameworks cited as models:
  - EU-TIBER / ECB TIBER-EU (Threat Intelligence-Based Ethical Red Teaming).
  - UK CBEST framework.
  - CPMI-IOSCO recommended methodologies for FMIs (vulnerability assessments, scenario-based testing, penetration tests, red team exercises).

*IMF Technical Assistance Report — tarea2025066-print-pdf*

### Preface ................................................................................................................

### Preface

### Mission and scope
- A Technical Assistance (TA) mission from the Monetary and Capital Markets Department (MCM) of the International Monetary Fund (IMF) visited Lima, Peru during the period September 18 to October 1, 2024. Virtual meetings were also held during the period August 13 to 21, 2024.
- Purpose: advise the authorities in developing a comprehensive cybersecurity strategy for the financial sector in Peru.
- Activities:
  - Reviewed the cyber posture of Peru to assess current capabilities and challenges.
  - Met with financial sector authorities and external stakeholders to discuss developments and issues relating to the cyber resilience of the financial sector (Annex 1).
  - Recommended actions to support the development of a comprehensive cybersecurity strategy for the financial sector in Peru and for the SBS.
- Principal engagements included meetings with Mr. Sergio Espinosa Chiroque (Superintendent), senior management and staff from the SBS, and representatives from the public and private sectors.
- The mission produced this TA report summarizing findings and recommendations.

### Context and recent incidents
- Cyberattacks targeting financial institutions (FIs) have included denial of service attacks, data breaches, phishing scams, malware, and ransomware.
- In 2023, a major cybersecurity incident involved a data breach at the national identity registry that affected an estimate of 14 million civil registration records, interconnected with identity management, public health insurance, and banking systems.
- Compromised personal information led to a rise in cybercrime, according to authorities and industry sources.
- With further digitalization expected, authorities plan to develop a comprehensive cybersecurity strategy for the financial sector.

### Key findings by element (summarized)
- Element 1: Cybersecurity Strategy and Framework
  - Financial authorities (SBS, BCRP, SMV, MEF) share collective interest in sector cyber resilience but no forum currently exists to coordinate cybersecurity strategies.
  - Recommendation: establish a high-level inter-agency committee and a public-private Cyber Resilience Forum.

- Element 2: Governance
  - The SBS faces resource constraints amid continued digitalization and rising cybersecurity risks.
  - An increase of    five additional staff are needed to support the onsite inspection of cybersecurity risks of supervised entities.
  - Stakeholders suggested more comprehensive, detailed, and precise cybersecurity regulation.

- Element 3: Risk and Control Assessment
  - Information on critical service providers has been collected, but cyber mapping of the financial system and cyber network remains to be carried out.
  - Cyber mapping would help identify interconnectedness, concentration risks, and potential systemic impacts.

- Element 4: Monitoring
  - Cyberattacks targeting FIs are documented, but a comprehensive Cyber Threat Landscape report is lacking.
  - Prioritization has shifted toward off-site supervision; an increase in onsite supervision of cybersecurity risks is needed, with priority for domestic systemically important banks.
  - The lack of a red-team testing framework leaves the sector vulnerable; a comprehensive testing framework such as threat-led penetration testing is recommended.

- Element 5: Response
  - A national CERT for public institutions exists, but no sectoral CERT for the financial sector is envisaged in the draft national strategy.
  - Systemically important FIs and FMIs are not obligated to report incidents to the national CERT.
  - Recommendation: establish a dedicated CERT for the financial sector (FinCERT) integrated with the national CERT.

- Element 6: Recovery
  - A large-scale cyberattack simulation exercise was conducted in 2022, but participation was incomplete (excluding the securities regulator, capital market entities, and microfinance companies) and communications/coordination were not sufficiently tested.
  - Recommendation: design more comprehensive, inclusive cross-sector and cross-border exercises.

- Element 7: Information Sharing
  - A basic cyber information-sharing platform introduced in 2022 focuses on phishing and lacks useful detail.
  - No formal cyber incident reporting framework with a standardized format currently exists.
  - Recommendation: implement a sector-wide threat intelligence information-sharing platform and a standardized incident reporting framework.
  - Public awareness campaigns are piecemeal; a comprehensive cyber education and public awareness program, including a Cyber Month, is needed.

- Element 8: Continuous Learning
  - Cybersecurity strategy should be regularly reviewed and updated given evolving threats.
  - With generative AI and quantum computing emerging, studies and advisories to FIs on use, opportunities, and risks are recommended.

### Recommendations (time frames preserved)
- Time Frame definitions: Short-Term (ST): 1 year; Medium Term (MT): around 2 to 3 years; Long Term (LT): around 4 to 5 years.
- Element 1: Cybersecurity Strategy and Framework
  - Prioritize the establishment of a high-level inter-agency committee to drive national cybersecurity initiatives for the financial sector. (SBS, BCRP, SMV, MEF) — ST
  - Establish a public-private Cyber Resilience Forum that fosters active participation, collaboration and sharing with trusted stakeholders. (SBS, BCRP, SMV) — ST
- Element 2: Governance
  - Increase resources for cybersecurity risk supervision and oversight. (SBS) — ST
  - Enhance cybersecurity regulation. (SBS) — MT
- Element 3: Risk and Control Assessment
  - Map the financial system and cyber network. (SBS) — ST
- Element 4: Monitoring
  - Develop a Cyber Threat Landscape Report (SBS, BCRP, SMV) — MT
  - Increase onsite supervision of cybersecurity risks with a commensurate increase in capacity and resources. (SBS) — MT
  - Develop a cyber testing framework for controlled cyberattacks that simulates real-world threats. (SBS) — MT
- Element 5: Response
  - Establish a dedicated CERT for the financial sector (FinCERT) and integrate it with the national CERT. (SBS, BCRP, SMV, MEF) — MT
- Element 6: Recovery
  - Conduct comprehensive cyberattack simulation exercises, expand participation and develop a cross-authorities response framework for sector cyber resilience. (SBS) — MT
- Element 7: Information Sharing
  - Implement a sector-wide threat intelligence info-sharing platform and a standardized incident reporting framework. (SBS, BCRP, SMV) — ST
  - Implement a Comprehensive Cyber Education and Public Awareness Program, including a Cyber Month (SBS, BCRP, SMV, MEF) — ST
- Element 8: Continuous Learning
  - Conduct a formal survey to quantify cybersecurity skills gaps and develop a cyber competency roadmap for the financial sector. (SBS) — MT
  - Establish regular review for cybersecurity strategy and framework to be responsive to emerging threats. (SBS) — ST
  - Study and issue advisories to financial institutions on the use, opportunities and risks of generative artificial intelligence and quantum computing in the financial sector. (SBS) — MT

### Implementation considerations
- Prioritization and sequencing of recommendations should be decided by authorities and stakeholders relative to legal mandates and resource availability.
- Annual reviews, ongoing stakeholder consultations, and monitoring of the evolving cyber threat landscape are advised.
- Implementation will require pooling resources and sector-wide coordination.

*IMF Technical Assistance Report | 8*

### 2.      As part of its strategy to promote cooperation, the SBS requested technical assistance

### As part of its strategy to promote cooperation, the SBS requested technical assistance (TA) from the IMF to develop a comprehensive cybersecurity strategy for the financial sector in Peru

### Overview and objectives
- SBS requested IMF TA to develop a comprehensive cybersecurity strategy for the financial sector in Peru to:
  - Diagnose current challenges, supervisory capabilities, and capacity building needs.
  - Inform a holistic strategy to strengthen cyber resilience of the financial sector, safeguard the financial system, and foster sustained economic growth.
- At the international level, Peru is categorized as having basic cybersecurity commitments (Tier 3 in ITU Global Cybersecurity Index 2024).
- The cybersecurity strategy includes eight elements: (i) cybersecurity strategy and framework, (ii) governance, (iii) risk and control assessment, (iv) monitoring, (v) response, (vi) recovery, (vii) information sharing, and (viii) continuous learning.

### Cyber threat landscape — key findings
- Authorities recognize cyber risk as a significant threat to the financial sector and overall financial stability.
- Documented attack types include: denial of service attacks, data breaches, phishing scams, malware, ransomware, fake fingerprints, and technology disruptions.
- Incident counts from internal records:
  - 10 incidents occurred in 2023.
  - six incidents during 2024 (as of August).
- Phishing is identified as the most common and impactful threat to users in the financial sector.
- Major 2023 incident:
  - Data breach at the National Registry of Identification and Civil Status (RENIEC) involving exposure of sensitive personal information, including fingerprints.
  - An estimate of 14 million civil registration records (from a total of 60 million) maintained by municipal governments have been digitized.
  - RENIEC systems are linked with identity management and public health insurance systems where 11 million workers (beneficiaries) could collect their payments from the nationwide network of branches of a state bank.
- Consequences and trends:
  - Compromised personal information facilitated impersonation tactics, including fake fingerprints to open bank accounts.
  - Impersonation attacks and SIM swap scams in telecommunications during 2022 and 2023 produced significant user losses.
  - SBS prohibited the sending of one-time passwords via short message services in response.
  - Consumer protection body observed rise in incidents and fraudulent transactions involving phishing, biometric data, spoofing, and vishing; largely targeted vulnerable segments post-COVID19.
  - Cyber-attacks associated with impersonations, AI, and supply chain are areas of growing concern.

### Supervisory and oversight framework — authorities and scope
- Main financial-sector cybersecurity authorities:
  - Superintendency of Banking Insurance and Private Pension Fund Administrators (SBS):
    - Oversees around 109 entities (of which 88 entities are onsite), including four domestic systemically important banks.
  - Central Reserve Bank of Perú (BCRP):
    - Designates, regulates, and supervises three systemically important payment systems: (i) Sistema LBTR, (ii) Cámara de Compensación Electrónica S.A (CCE), and (iii) Sistema de Liquidación Multibancaria de Valores (SLMV).
  - Superintendence of Securities Market (SMV):
    - Supervises around 81 entities associated with clearing and settlement, stock exchange, fund management, mutual funds, investment, collective funds, securitization, pricing, and risk classification.
- Other relevant governmental authorities with cybersecurity roles:
  - Ministry of Economy and Finance (MEF).
  - National Authority of Personal Data Protection (ANPD).
  - National Digital Security Center (CNSD).
  - Supervisory Agency for Private Investment in Telecommunications (OSIPTEL).
  - Competition and Consumer Protection Authority (INDECOPI).

### Methodology and scope of the mission
- Guidance and standards informing the strategy included:
  - CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures (FMI) (June 2016).
  - FSB Recommendations to Achieve Greater Convergence in Cyber Incident Reporting: Final Report (April 2023).
  - IMF Cybersecurity Risk Supervision (2019).
  - FSB Stocktake of Publicly Released Cybersecurity Regulations, Guidance and Supervisory Practices (October 2017).
  - G7 Fundamental Elements of Cybersecurity for the Financial Sector.
- Mission approach:
  - Stock-take using responses to a pre-mission questionnaire and meetings with key stakeholders to collect information on threat landscape, supervision and oversight, testing frameworks, incident reporting, information sharing, crisis simulations, and related areas.
  - Findings informed development of the cybersecurity strategy.
- Scope exclusions (not covered by the mission):
  - (i) Internal strategy for improving the cybersecurity risk management of the SBS.
  - (ii) Strengthening cyber resilience of systemically important FMIs.
  - (iii) Developmental and operational aspects of establishing a financial sector CERT.
  - (iv) Oversight and supervision of FMIs by the BCRP.

### Next steps and implementation approach
- SBS committed to implementing IMF recommendations to enhance cybersecurity resilience and to collaborate with relevant authorities and stakeholders.
- Prioritization, duration, and sequencing of each recommendation to be decided by authorities relative to legal and institutional mandates and resource availability.
- Recommendations would benefit from annual reviews, stakeholder consultations, and monitoring of the evolving threat landscape.

### Element 1: Cybersecurity Strategy and Framework — High-Level Cyber Committee
Current situation
- SBS, SMV, BCRP and MEF take interest in financial-sector cyber resilience but lack a unified forum to coordinate national cybersecurity initiatives.
- Absence of consensus on leadership/ownership of essential initiatives (e.g., financial sector CERT) due to concerns over expanding core mandates, resource requirements, and sustaining initiatives.
- Resulting fragmentation has impeded development and implementation of sector-wide initiatives such as CERT implementation, information-sharing platforms, and formal incident coordination.
- Financial institutions and FMIs are highly interconnected, underscoring the need for coordinated oversight and collaboration among authorities.

Recommendation
- Prioritize establishment of a High-Level Inter-Agency Committee for Coordinating National Cybersecurity Initiatives in the financial sector, with the SBS, BCRP, SMV and MEF as core members and other agencies (e.g., CNDS) invited as appropriate.
- Committee design and functions:
  - Comprise senior officials, especially heads and deputies, and allocate resources for a secretariat to support the committee.
  - Mandate to coordinate and agree on key national cybersecurity initiatives tailored to the financial sector, including overseeing establishment of a sector-specific CERT, developing information-sharing platforms, and coordinating sector-wide incident response efforts.
  - Conduct an initial stock-take of existing cybersecurity capabilities and initiatives across agencies to identify platforms and avoid duplication.
  - Use structured discussions and workshops to build consensus on ownership and importance of initiatives, address resource/cost concerns, and negotiate compromises.
  - Designate lead or co-leading agencies for major initiatives or consider a single lead for cohesive management; consider a rotating leadership model to share ownership and prevent overburdening one agency.
  - Coordinate with non-financial sector agencies involved in national security and critical infrastructure to integrate financial sector initiatives into broader national efforts.

*IMF Technical Assistance Report*

### 25.        To address concerns regarding resources, costs, and effort, the committee should

### 25.        To address concerns regarding resources, costs, and effort, the committee should 

### Industry Forum — Current situation
- SBS, SMV and BCRP have stepped up on regulating and supervising cyber risks, but collaboration among FIs and regulators is still lacking.
- FIs are hesitant to share cyber incidents or vulnerabilities with their regulators due to fears of being perceived as having weak cyber risk management and attracting supervisory scrutiny; this lack of trust hinders effective information sharing.
- Absence of a framework that encourages open communication limits the effectiveness of sector-wide exercises and collaborative initiatives.
- No forum currently exists dedicated to facilitating collaboration between FIs and public authorities to drive collective action on cyber resilience.
- The SBS has set up an Information Security Sectoral Working Group consisting of a few key banks and the Association of Banks of Peru (ASBANC) to dialogue on common cybersecurity and authentication challenges and to find solutions; lack of formal structures (terms of reference, objectives, meeting schedule) has raised legitimacy concerns, including legal questions about the group's right to publish non-binding recommendations.
- There is a Market-wide Business Continuity Working Group conducting business continuity exercises, including cyber-attack scenarios, but its scope does not address cyber-specific needs or initiatives.
- International precedents cited: Cross Market Operational Resilience Group (CMORG), Financial Services Sector Coordinating Council (FSSCC), Euro Cyber Resilience Board (ECRB).

### Industry Forum — Recommendation (paragraphs 30–33)
- Establish a public-private Cyber Resilience Forum to foster active participation, collaboration and sharing experiences with trusted stakeholders; serve as a pivotal platform to enhance sector-wide cyber resilience through strategic dialogue, collective problem-solving, and coordinated action.
- Forum composition and leadership:
  - Bring together senior representatives from key stakeholders, including high-level executives from major FIs, relevant government officials, and cybersecurity experts to ensure authority and expertise.
  - Define membership and leadership structure: include senior representatives from major FIs and relevant government agencies as core members, gradual inclusion of private sector cybersecurity experts.
  - Appoint a chairperson or co-chairpersons from the SBS, BCRP or SMV, supported by a steering committee comprising representatives from both public and private sectors.
  - Ensure members are senior executives or officials with decision-making authority.
- Trust-building and operations:
  - Build trust through open and transparent communication between the financial regulator and FIs, including regular updates on regulatory changes, cyber threats, and collaborative efforts.
  - Involve FI representatives in decision-making processes; organize regular meetings, workshops, and training sessions.
  - Establish feedback mechanisms to address FIs’ concerns and suggestions; recognize and reward active participants; assure confidentiality of sensitive information shared within the forum.
  - Establish clear terms of reference, agendas, and priorities; define operational procedures including meeting frequency and decision-making processes.
  - Set key agenda items such as threat landscape reviews and joint strategy development.
  - Support the forum with a dedicated secretariat, sufficient resources, and staffing; encourage participation through recognition programs, training, and awareness initiatives.
  - Regularly monitor and evaluate the forum's effectiveness based on participation, initiative impact, and sector resilience improvements.

### III. Element 2: Governance — Cybersecurity Risk Supervisory Resources (Current situation)
- SBS cybersecurity and operational risk supervision responsibilities are grouped under the Deputy Superintendent of Risks, including: (i) the Department of Information Systems and Security Supervision and (ii) the Department of Operational Risk Supervision.
- Department of Information Systems and Security Supervision staffing: one department head, 15 supervisors, and two interns.
- Around 4 staff work full time in developing cybersecurity tools for off-site supervision, and 4 staff on information security supervision.
- Most staff are system engineers with expertise in information security and technology supervision.
- SBS faces resource constraints as digitalization increases cybersecurity risks of supervised entities; financial autonomy exists but available resources have constrained speed and scope of regulatory activities, including cybersecurity supervision.
- SBS staff working on IT and security supervision have multiple responsibilities beyond cybersecurity (including data reliability supervision) and contribute to resolution of troubled FIs.
- Off-site supervision of cybersecurity risks has improved, but onsite supervision has been lacking relative to the number of entities supervised, including systemically important banks.
- Resource constraints impact the SBS’s ability to expand supervisory and oversight capabilities or respond swiftly to emerging threats.

### III. Element 2: Governance — Cybersecurity Risk Supervisory Resources (Recommendation, paragraphs 36–37)
- Increase resources for cybersecurity risk supervision as part of ongoing reorganization.
  - Based on discussions with the authorities, five additional staff are needed to complement work in the Department of Information Systems and Security Supervision.
  - Resource assessments should consider emerging risks, technological advancements, and regulatory developments.
  - Additional resources should support onsite inspection of cybersecurity risks of supervised entities, particularly for domestic systemically important banks.
- Ensure supervisors have necessary experience and expertise:
  - Adequate technical skills and appropriate number of resources are needed to assess a firm’s cyber risk profile and cybersecurity risk control maturity level.
  - Address skills gaps as a key concern given cyber threats’ impact on financial stability.
  - Recommended staffing model: combination of generalist supervisory skills (operational risk management focus) complemented with technical specialists.
  - Consider upskilling staff with competencies in cybersecurity and data sciences and recruit new employees with relevant skill sets.
  - Hiring, training, and retention of specialists should be a key element of the strategy.

### III. Element 2: Governance — Cybersecurity Regulation (Current situation, paragraphs 38–43)
- Regulatory architecture comprises several key regulations and frameworks; Table 2 lists major regulations and circulars related to operational and cybersecurity risks issued by the SBS (selected items):
  - 2021 Information Security and Cybersecurity Regulation (Regulation 504-2021-SBS) (Last Update: June 2024)
  - 2020 Business Continuity Management Regulation (Regulation 877-2020-SBS)
  - 2019 Operational Risk Management (Regulation 2116-2009-SBS)
  - 2017 Criteria for Recording Operational Loss Events (Circular G-191-2017)
  - 2017 Corporate Governance and Integral Risk Management (Regulation 272-2017-SBS)
  - 2015 Key Risk Indicators for Business Continuity Management (Circular G-180-2015)
  - 2013 Credit and Debit Card Regulation (Regulation 6523-2013-SBS) (Last update: June 2024)
  - 2012 New Products or Significant Changes (Circular G-165-2012)
  - 2009 Operational Risk Management (Regulation 2116-2009-SBS)
  - 2009 Requirement of Effective Capital for Operational Risk (Regulation 2115-2009-SBS)
- Cybersecurity regulation is principle-based, providing flexibility on methods to achieve compliance; Information Security and Cybersecurity Regulation of 2021 is being enhanced and contains guidelines based on NIST and ISO/IEC standards; includes provisions on third-party service providers, cloud services, and significant data processing services; authorities expect to issue new circulars covering information sharing on cyber threats, reporting of cybersecurity incidents, and setting minimum evaluations for information security and cybersecurity management systems.
- Business Continuity Management Regulation of 2020 contains minimum standards and obligations to report events causing significant interruption to operations; includes a list of controls for business continuity management.
- Operational Risk Management Regulation of 2009 requires comprehensive risk management policies appropriate for firm size and complexity.
- No current plans to issue regulations specifically on artificial intelligence; Regulations on model risk (053-2023-SBS) are issued and authorities plan to issue a new regulation on principles for risk data aggregation.
- Industry feedback: existing cybersecurity regulations have been difficult to interpret and implement; suggestions include setting minimum standards for all FIs with higher standards for higher-risk institutions; proportionality principle exists (Information Security and Cybersecurity Regulation of 2021, Article 4) but industry suggests it lacked details.
- Other suggested improvements: standardize incident reporting, clarify information requirements in notification of cybersecurity incidents, guidance on quantification of risks for cybersecurity risk insurance, further distinguish cybersecurity risks from operational risks to ensure fit-for-purpose regulation and greater senior management and Board attention.
- Emerging concern: rise of identity theft related to affiliation of merchants with payment processors; existing cybersecurity regulations do not cover payment processors and authorities state there are no specific cybersecurity requirements for payment processors within SBS scope.

### III. Element 2: Governance — Cybersecurity Regulation (Recommendations, paragraphs 44–46)
- Enhance cybersecurity regulations with guidelines; SBS should continuously improve existing cybersecurity regulations.
  - Tailor focus: smaller and lower-capacity firms should strengthen cyber hygiene; the largest and most globally connected firms and key system nodes should be subject to heightened standards.
  - Ensure regulation makes cybersecurity requirements enforceable and allows use of supervisory actions where needed.
- Apply cybersecurity regulation requirements proportionate to supervised firms’ risk:
  - While proportionality principles are established (Information Security and Cybersecurity Regulation of 2021, Article 4), provide more detail on proportional application.
  - Requirements should set a range of cybersecurity risk management controls applicable to all supervised firms, with increased complexity and systemic importance reflected in maturity of controls; emphasize continuous improvement.
- Baseline topics for effective regulation (based on IMF Cyber Risk Supervisory Toolbox):
  - Governance and oversight
  - Technology and cyber risk management
  - IT services management
  - Cybersecurity operations
  - Response and recovery
  - Scanning, testing, exercising, and remediation
  - Independent assurance
  - Outsourcing and technology service provider management

### IV. Element 3: Risk and Control Assessment — Cyber Mapping (Current situation and recommendations, paragraphs 47–49)
- Current actions:
  - SBS has collected information on critical service providers by entity and determined their concentration, providing a preliminary analysis of critical services.
  - Authorities have been involved in a project to test the cyber resilience of certain critical services relevant to the payment system with international assistance.
  - Efforts to map the financial system and cyber network have not been done; industry sources suggest cyber mapping would be useful to identify interdependencies (for example between banks and insurance firms) and prepare contingency plans, and aid coordination with other governmental agencies.
- Recommendation: Conduct cyber mapping.
  - Two-step process:
    1. Firm-level: develop an in-depth understanding of a firm’s ICT systems, building on supervisors’ knowledge of supervised firms’ business models, management of ICT risks, and importance for the financial sector.
    2. Sector-wide: consolidate firm-specific financial and technical connections to form a systemwide view—a financial sector network map combining financial connections between systemic firms and their respective ICT connections.
  - Identify key technology systems in use by each supervised firm (in-house or third-party), as similar ICT systems can make supervised firms vulnerable to the same cyber-attack techniques.
  - Use knowledge of both financial and technical connections to conduct firm-level supervisory risk assessments (for example, operational risk assessments, including ICT risk).
  - Mapping benefits:
    - Identify potential systemic risks from interconnectedness and concentrations in third-party service providers.
    - Assess how a shock to one supervised firm/utility/service provider can spread to others, potentially leading to a cascade of liquidity shortage, write-downs, and defaults.
    - Identify key nodes in the financial system (e.g., payment and settlement system, FIs that carry out key services such as clearing, and underpinning technology systems) to understand systemwide cyber risk.
    - Use the cyber map to estimate the impact of a cyber-attack on any node and assist in identifying concentration risks in third-party service providers and protection mechanisms for assets.

*IMF Technical Assistance Report | 20-27*

### 50.        SBS collects and documents cases involving cyberattacks targeting FIs. However, a

### Supervisory Assessments, Testing Framework, and Response (paras 50–79)

### Cyber Threat Landscape
- Current situation:
  - SBS collects and documents cases involving cyberattacks targeting FIs, but "a comprehensive cyber threat landscape report is currently lacking in Peru."
  - Authorities could improve overall analysis by combining different sources of information and developing a cyber threat landscape report updated annually.
  - Possible report types based on international experience: a Generic Threat Landscape Report or a report tailored for the financial sector.
- Recommendation (para 51):
  - Develop a Cyber Threat Landscape for the Peruvian Financial Sector Report that:
    - Elaborates on the specific threat landscape of the Peruvian financial system, taking into consideration threats unique to the jurisdiction.
    - Considers key financial market participants and their critical functions, including (wholesale and retail) banks, broker, dealers, FMIs, and other critical third parties.
    - Considers the different threat actors (including their tactics, techniques, and procedures) and common vulnerabilities.
    - Supports scenario development, playbook building, and exercising to better foresee attack patterns and prepare FIs.

### B. Supervisory Assessments
- Current situation:
  - Information security and cybersecurity are integral parts of the supervisory review process for FIs, encompassing both on-site and off-site reviews.
  - Cybersecurity assessments can be conducted as part of general inspections or as a separate review.
  - On-site inspections are prioritized for well-known cases due to resource intensity; off-site supervision provides wider sector assessment.
  - On average, the SBS conducts 10 inspections where the scope of assessment is information security or cybersecurity (para 53).
  - Off-site reviews have included: protection of credit and debit card information, security practices in mobile and web application development, black box assessment of vulnerabilities in mobile applications.
  - Authorities plan assessments of incident response, security operation center capabilities, and cybersecurity programs; a survey tool is being designed for data collection (para 54).
  - FIs are rated annually on information security management practices; this score is integrated into the operational risk management rating and may impact the global internal score (para 55).
  - Onsite inspections related to information security or cybersecurity risks are conducted with a moderate level of intrusiveness (documentary evidence only); independent third-party reviews may be required for technical validation (para 56).
  - Supervisory manuals reference various standards; SBS uses a tool called Teammate for recording guidelines. Visits authorizing capital requirements via the alternative standard method use an Excel spreadsheet with detailed security-topic information; such visits typically take between three to five weeks (para 57).
  - In 2021, additional supervisory guidelines incorporated ISO 27000 series and NIST CSF but were not used due to a shift toward more off-site activities (para 57).
  - Supervisory proportionality is applied through three regimes (para 58):
    - Simplified Regime: applied to small entities; basic and general security requirements.
    - General Regime: comprehensive measures related to information security, authentication, security in third party providers, and cybersecurity.
    - Reinforced Regime: applied to entities with significant market concentration requiring additional measures.
  - FIs are required to have a comprehensive cybersecurity risk management process as part of operational risk; authorization to use the Alternative Standard Method requires demonstrating good practices (para 59).
  - FIs are not required to set aside specific provisions for future cyber losses (para 59).
  - FIs are required to include cyber-attack scenarios as part of business continuity plans; a sector-wide cyberattack simulation exercise was conducted in 2022 involving the financial sector, insurance companies, AFPs, and key financial authorities (para 60).
  - SBS supervisory measures in recent years have focused on mobile application vulnerabilities, independent assessments for web/mobile platforms, verifying PCI compliance, assessing phishing detection/response capabilities, and directives for corrective actions in cases of information leaks or fraud-related activities (para 61).
- Recommendation (para 62):
  - Increase onsite supervision of cybersecurity risks with a commensurate increase in capacity and resources.
  - Prioritize domestic systemically important banks given higher risk profile and concentration risk.
  - Assess cybersecurity risk as part of the supervisory review process; treat cyber risk as an important subcategory of operational risk relevant to governance, strategy, business model, and capital risk.

### C. Testing Framework
- Current situation:
  - FIs are required to conduct vulnerability scans and penetration tests when introducing new products or making changes to systems, but not on a regular basis; SBS plans to make regular testing a requirement in the next update of the Regulations (para 63).
  - There are no plans for FIs to perform Red team tests (para 63).
  - SBS conducts security reviews on financial services mobile applications via its own laboratory; tests are limited in scope and purpose, personnel trained by the ITU, and test scope is a subset of the OWASP top ten mobile security framework (para 64).
  - These laboratory reviews are supervisory tools, not industry testing services or certifications; results are fully shared with FIs (para 64).
  - Authorities could consider involving specialized third-party experts for future application security assessments for sustainability (para 64).
  - The financial sector lacks a structured cyber testing framework to assess and enhance FIs' ability to detect, respond to, and recover from cyber incidents; current methods rely heavily on self-assessments, audits, and onsite inspections, offering limited insights into real-world resilience (paras 65–66).
  - The absence of comprehensive red-team testing constrains SBS’s view of effectiveness of cybersecurity policies and controls; having a testing framework would enable red, purple, and gold teaming exercises (paras 66–67).
  - A well-designed testing framework such as Threat-Led Penetration Testing (TLPT, also known as Red Team Testing) should evolve with threat intelligence; CPMI-IOSCO emphasizes leveraging cyber threat intelligence to design tests simulating advanced threats and extreme scenarios (para 67).
- Recommendations (paras 68–73):
  - Consider involving specialized third-party experts for application security assessments if the security laboratory program continues (para 68).
  - Prioritize vulnerability assessments and standard penetration tests while developing a long-term cyber testing framework to simulate real-world threats through controlled cyberattacks (para 69).
    - Initially focus on frequent and extensive vulnerability assessments and non-adversarial penetration tests across FIs.
    - Introduce TLPT gradually, focusing first on higher-risk FIs due to cost and complexity.
  - TLPT framework design elements (paras 70–72):
    - Incorporate red, purple, and gold team exercises informed by real-time threat intelligence.
    - Draw on established models like EU-TIBER and UK CBEST.
    - Include a certification system for service providers to ensure quality.
    - Form a working group within the Cyber Resilience Forum with FIs, authorities, and experts to design the framework and address sector-specific challenges.
    - Partner with threat intelligence providers to integrate current threat landscapes into testing scenarios.
    - Roll out in stages starting with systemically important FIs and expand to smaller entities; BCRP should apply guidelines to FMIs.
    - Design TLPT objectives, scope, and methodologies; create certification for external TLPT providers; establish a dedicated oversight team; develop a secure platform to share anonymized insights from TLPT exercises.
  - Use TLPT and testing results to enhance supervisory assessments and establish feedback mechanisms; regularly review and update the framework to keep pace with evolving threats (para 73).

### VI. Element 5: Response — A. Financial Sector CERT
- Current situation (paras 74–76):
  - CNDS has established a national CERT primarily serving public institutions; no sectoral CERTs are envisaged in its draft cybersecurity strategy.
  - Lack of guidance from CNDS for a financial sector CERT is a growing concern for SBS, SMV, and BCRP.
  - A national CERT lacks specialized expertise needed for finance; the financial sector requires faster responses and different regulatory considerations.
  - A sectoral CERT for finance (FinCERT) can develop tailored threat intelligence, sector-specific incident response, vulnerability management, and situational awareness.
  - Major challenge: SBS, BCRP and SMV do not see themselves as responsible for leading a FinCERT initiative due to concerns about costs, resources, expertise, and mandate, resulting in no consensus or clear assignment of responsibility (para 75).
  - Authorities have not conducted studies to determine scope of services and associated costs of operating a FinCERT, hindering feasibility assessment (para 75).
  - FIs are not required to report cyber incidents to the national CERT, creating a lack of integration and hindering information sharing and coordinated responses (para 76).
- Recommendation (paras 77–79):
  - Establish FinCERT and integrate it with the national CERT; make this a key priority on the high-level committee’s agenda (para 77).
    - FinCERT objectives: provide specialized support in threat intelligence, incident response, vulnerability management, and situational awareness tailored to the financial industry.
    - Integrate FinCERT with the national CERT for collaboration on broader threats and resource sharing.
  - Key actions (para 78):
    - Form a FinCERT Project Task Force with representatives from relevant authorities to define roles, responsibilities, and protocols aligned with financial sector needs.
    - Review legal and regulatory framework to ensure FinCERT can mandate reporting, enforce standards, and collaborate effectively.
    - Secure funding, possibly through public-private partnerships.
    - Develop Standard Operating Procedures (SOPs) to integrate business continuity and risk management.
    - Pilot the CERT with select institutions before full implementation.
  - Integration measures (para 79):
    - Establish formal communication channels between FinCERT and the national CERT for seamless information sharing and coordinated incident responses.
    - Develop integration protocols for collaboration during incidents, threat intelligence sharing, and joint exercises.
    - Conduct regular coordination meetings to review initiatives and emerging threats.

*IMF Technical Assistance Report | excerpt paras 50–79*

### 80.        The SBS requires FIs to integrate cyberattack scenarios into their business continuity

### tarea2025066-print-pdf - 80.        The SBS requires FIs to integrate cyberattack scenarios into their business continuity

### Cyberattack simulation exercises and business continuity
- The SBS requires FIs to integrate cyberattack scenarios into their business continuity plans; this mandate was introduced in 2020.
- Continuity plans outline response strategies, resilience measures, and recovery procedures.
- A large-scale cyberattack simulation exercise was conducted by the SBS in 2022, involving commercial banks, select non-bank FIs, ASBANC, SBS, MEF and the BCRP.
- Non-participants in the 2022 exercise included the SMV, the stock exchange, and Cavali (central securities depository and securities settlement systems). Capital market firms and microfinance companies were also not involved.
- Stakeholder observations:
  - The exercise was beneficial for enhancing individual preparedness.
  - The exercise did not sufficiently test cyber response, communication and coordination within the sector.
  - There is no formal framework for authorities to coordinate response to a cyber crisis.

### Gaps identified and rationale for a Cross-Authorities Response & Coordination Framework
- Identified gap: absence of a comprehensive response framework to coordinate among financial authorities and international partners for cross-border cyber incidents.
- Proposed function: facilitate structured collaboration between the central bank, financial supervisory authorities, technical experts, and other government bodies to manage business and technical consequences of a cyber incident.
- No cross-sector and cross-border exercises are being planned.
- Current cross-border engagement: SBS has held cyber information-sharing talks with foreign regulators from Colombia, Chile and Mexico, focused on exercise planning but not actual exercises.
- Cooperation with the telecommunications regulator exists but is focused only on authentication issues for financial service providers.
- Importance of cross-sector and cross-border exercises: prepare for cyber incidents with widespread financial impact, enhance communication and coordination, ensure effective response strategies, and promote shared practices and lessons learned.

### Recommendations on exercises and crisis coordination
- Conduct comprehensive cyberattack simulation exercises, expand participation and develop a Cross-Authorities Response Framework to enhance financial sector cyber resilience.
  - The comprehensive approach should involve testing cyber response, communication, and coordination within key stakeholders in the sector.
  - SBS should develop a formal Cross-Authorities Response and Coordination Framework to ensure better coordination between the SBS, BCRP, SMV and MEF.
  - The framework should enable coordination with FIs, FMIs, technical experts, and international partners, and facilitate swift and informed decision-making to mitigate impacts on business operations and financial stability.
- Consider future simulation exercises that stress tests system-wide liquidity in scenarios where critical FIs and FMIs are severely disrupted; tests should account for potential liquidity contagion across financial institutions.
- Expand participation in simulation exercises to include SMV, Cavali, capital market firms, and microfinance companies to exercise communication and coordination arising from interconnections among FIs, FMIs and authorities.
- Plan and conduct cross-sector and cross-border exercises:
  - Expand cyber information-sharing meetings with foreign regulators to include actual exercises, not just planning.
  - Broaden cooperation with the telecommunications regulator to address a wider range of issues beyond authentication.

### Information sharing and incident reporting (Element 7)
- Current situation:
  - The SBS gathers cybersecurity incident information primarily from reports submitted by FIs when there are significant losses or theft of data, internal or external fraud, reputational damage, or operational disruptions.
  - On average, it receives between 5 to 10 such incident reports annually.
  - A forensic report must be provided to the SBS when incidents are reported.
  - SBS maintains membership in FS-ISAC and collaborates with peer supervisors via memoranda of understanding focused on banks with a presence in Peru and home-host frameworks.
  - In June 2023, the SBS introduced a basic information-sharing platform primarily focused on collecting phishing event data reported by FIs; the platform is currently restricted to sharing event information without important details and is not real-time or alerting.
  - Existing platforms are fragmented: SBS’ platform limited to phishing; ASBANC’s privately operated platform includes some but not all banks, excludes other FIs, and members do not actively share information; some FIs are FS-ISAC members but with minimal active engagement.
  - The SBS requires incident reporting under broader business continuity regulations but has not implemented a formal cyber incident reporting framework with a standardized format.
- Recommendation summary:
  - Implement a sector-wide threat intelligence info-sharing platform and a standardized incident reporting framework.
    - Start with a thorough assessment of strengths and weaknesses of both the SBS’ and ASBANC’s existing platforms to decide whether to enhance one, merge, or develop a new solution.
    - Establish clear protocols for classifying and categorizing data to meet sector-specific needs.
    - Encourage active participation from FIs through incentives, recognition programs, and training.
  - Integrate the platform with the national CERT and international threat intelligence networks through formal data-sharing agreements to expand national and global threat intelligence access.
  - Standardize incident reporting by adopting globally recognized frameworks, like the FSB’s FIRE standard, and develop a sector-wide incident reporting tool integrated with the enhanced info-sharing platform for real-time reporting.

### Public awareness (Element 7 — Public Awareness)
- Current situation:
  - Consumers in Peru face increasing vulnerability to cyber-attacks, including DDOS, data breaches, phishing and scams; phishing is identified as the most common and impactful threat.
  - Emerging tactics include AI-powered attacks and supply chain vulnerabilities.
  - The recent breach at the national ID registry exposed sensitive personal information like fingerprints, increasing consumer vulnerability to impersonation and fraud.
  - Public education efforts are piecemeal: individual FIs run targeted campaigns for their customers; MEF conducts quarterly public awareness campaigns focused on financial inclusion for the unbanked; INDECOPI and the SBS run initiatives but stakeholders find efforts insufficient.
  - Unlike many countries, Peru lacks large regular collaborative cybersecurity awareness campaigns (e.g., national Cyber Month).
- Recommendations:
  - Implement a Comprehensive Cyber Education and Public Awareness Program, including a Cyber Month.
    - The initiative should involve banks, other FIs and associations, government agencies, and financial authorities, led by the High-level Interagency Committee.
    - Aim to enhance consumer knowledge on cyber risks, including AI-powered attacks, and improve protection against cyber-enabled fraud.
    - FIs should establish clear communication guidelines (e.g., avoid use of links) to mitigate phishing risks.
    - Campaigns should be ongoing, dynamic, and updated regularly to address emerging threats.
    - Recommend declaring every September a cybersecurity month as a sustained awareness effort with activities nationwide.

### Continuous learning and cybersecurity skills (Element 8)
- Current situation:
  - No formal or comprehensive survey has been undertaken to quantify the shortage of cybersecurity skills in Peru’s financial sector.
  - Development of cybersecurity capabilities was included in the current cybersecurity roadmap for the financial sector, but a coordinated survey or cyber competency roadmap has not been initiated by authorities or industry.
  - Indicative observations of skills shortage:
    - Heads of cybersecurity at three of the four systemically important banks are from foreign countries (Colombia, Brazil, and Spain), suggesting a lack of local talent for high-level positions.
    - Movement of cybersecurity professionals between FIs indicates a competitive job market, leaving smaller companies with shortages of specialized personnel.
    - Authorities estimate the financial sector may still face a significant shortfall in cybersecurity professionals, potentially in the hundreds, though exact figures are undetermined without a formal survey.
  - SBS initiatives:
    - SBS promoted various training events, some via the Information Security Sectoral Working Group with international collaboration.
    - Cybersecurity undergraduate and postgraduate programs have emerged in local universities in recent years.
    - SBS provides internal support for cybersecurity training, including funding for some international certifications, allocating a shared annual training budget, and occasionally acquiring online training platforms.
    - Limitations: budget constraints and long-term sustainability concerns; annual certification maintenance fees reduce attractiveness unless supervisors have other income sources.

*IMF Technical Assistance Report | Extracted content unit*

### 109.      Several private sector initiatives have been aimed to promote training, competition for

### Several private sector initiatives have been aimed to promote training, competition for cybersecurity skills upgrading in the financial sector

### Private sector initiatives and current situation
- Several private sector initiatives have been aimed to promote training, competition for cybersecurity skills upgrading in the financial sector.
- Initiatives include workshops on various topics related to information security and cybersecurity (such as a course on assembly) organized by ASBANC.
- Some banks have provided scholarships to cover university studies for eligible students in fields such as systems engineering but not on cybersecurity.
- Some banks offer cybersecurity programs online.
- Authorities are not aware of specific government-led programs, collaborations with universities for research, cybersecurity camps and competitions, or innovation labs in partnership with technology companies focused on cybersecurity in the financial sector.

### Recommendation: Cyber skills assessment and roadmap
- Conduct a formal survey to quantify cybersecurity skills gaps and develop a cyber competency roadmap for the financial sector.
- Enhance collaboration between FI s, universities, and regulators to align educational programs with industry needs.
- Develop the market for cyber qualifications, accreditation, and certification to build overall capacity and address skills shortage.
- Establish different levels of essential skills for progress in cyber roles.

### Recommendation: National training program and incentives
- Implement a national cybersecurity training program tailored to the financial sector.
- Collaborate with educational institutions, private companies, and international partners to develop specialized courses and certifications.
- Establish centers of excellence for cybersecurity research and innovation to foster collaboration and drive advancements in cybersecurity.
- Launch public awareness campaigns to educate the public and financial sector employees about cybersecurity best practices.
- Provide financial incentives for obtaining industry-recognized certifications to build a robust cybersecurity workforce.

### Regular review — current situation
- Developing a comprehensive cybersecurity strategy for the financial sector is a key priority for the SBS, and this technical assistance report provides crucial input in that effort.
- In 2021, the SBS, in partnership with the Alliance for Financial Inclusion, published a case study that outlined a cybersecurity roadmap for the financial sector and recommended the development of a tailored cybersecurity strategy.
- The insights and recommendations from this TA report will play a vital role in shaping the cybersecurity approach, informing key decisions, and ensuring the effective protection of the financial sector.
- The G7's Fundamental Elements of Cybersecurity for the Financial Sector emphasizes the importance of continuous learning and evolution in cybersecurity frameworks.
- Periodic reviews will help maintain the effectiveness of cybersecurity measures, optimize resource allocation, address gaps, and incorporate lessons learned from past incidents.

### Recommendation: Establish regular review process
- Establish a regular review process to assess and update the cybersecurity strategy and framework.
- Objective: ensure the cybersecurity strategy for the financial sector remains effective and responsive to emerging threats and the broader sectoral strategy involves multiple authorities.
- Include annual reviews of the cybersecurity strategy and framework.
- Engage with FI s, industry experts, and other relevant stakeholders to gather diverse insights and feedback.
- Consider external developments in related sectors, such as energy and telecommunications, that could impact the financial sector's cyber resilience.
- Prioritize continuous learning and improvement: conduct post-incident reviews, analyze lessons learned, and refine strategy accordingly.
- Engage in collaboration and information sharing with industry peers, regulators, and specialized cybersecurity firms.
- Key activities: cybersecurity exercises, simulations, training programs; subscribing to threat intelligence feeds and industry publications; attending conferences, workshops, and webinars.
- Invest in employees through regular security awareness training, mentorship programs, and knowledge sharing.
- Engage with academic institutions and research centers to leverage cutting-edge expertise.

### Innovation and future-proofing — current situation
- Peru faces cybersecurity threats that have increased in sophistication.
- Cybersecurity incidents have included impersonations which was exasperated with the major data breach of the RENIEC in 2023.
- The SBS has benefitted from having a computer laboratory staffed with qualified system engineers that have helped addressed mobile payment security and other challenges so far.
- Evolving risks stem from new and emerging technologies, for example, the use of generative artificial intelligence (AI) and quantum computing in future cyber-attacks.
- Feedback from stakeholders suggests the need to prepare for risks associated with the use of generative AI in the financial sector.
- Leading financial authorities in countries have proactively issued advisories on the safe use of generative AI.
- Funding support for regulated entities to defray manpower and technology costs in building capabilities in these areas has also been observed.

### Recommendation: Study and issue advisories on generative AI and quantum computing
- Study and issue advisories to FI s on the use, opportunities and risks of generative AI and quantum computing in the financial sector.
- Collaborate with other agencies such as the CNSD, government bodies, ASBANC, private companies, and universities.
- Encourage financial institutions to:
  - develop a better understanding of generative AI and quantum computing, the risks involved, and strategies for mitigating risks;
  - assess generative AI and quantum computing risks in their areas of responsibility; and
  - develop a plan for mitigating generative AI and quantum technology risks.
- Provide guidelines on best practices for implementing AI and quantum technologies.
- Maintain continuous monitoring of technological advancements and cyber threat trends, update advisories and regulations as necessary, and foster collaborative environments for sharing insights and best practices.
- Issue best practice guidelines when appropriate, ensuring alignment with technological advancements and sectoral readiness.

### Contextual examples and international references noted
- References in the report include:
  - United States Department of the Treasury (2024). Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector, March.
  - Monetary Authority of Singapore (2024). Advisory on Addressing the Cybersecurity Risks Associated with Quantum, Circular No. MAS/TCRS/2024/01.
  - G7 Cyber Expert Group (2024) Statement on Panning for the Opportunities and Risks of Quantum Computing, September.
- Monetary Authority of Singapore (MAS) measures noted: urging adoption of post-quantum cryptography (PQC) and quantum key distribution (QKD); MAS committed S$100 million to support financial institutions in building capabilities in quantum and AI technologies, including supporting manpower costs and technology solutions.
- U.S. agencies such as the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and National Institute of Standards and Technology (NIST) have warned that cyber actors could leverage future quantum computing technology to break traditional non-quantum-resistant cryptographic algorithms.

### Annex I. Agenda for the Meetings (selected items)
- September 18: Meetings with Banking, Insurance and Pension Funds Authority; courtesy visit to SBS senior management; opening meeting; topics include SBS role and responsibilities in relation to cybersecurity; overview of banking, insurance, and pension in Peru; cybersecurity risk supervision and oversight framework for banks, insurance, and pensions in Peru.
- September 19: Meetings with Automated Clearing House and National Cyber Security Agency; topics include Peru’s Automated Clearing House (CCE) role and responsibilities; current threat landscape for retail payments; threat intelligence and information sharing; testing framework; cyber incident response and recovery; cyber incident reporting; cyber crisis simulation and exercises; CNSD role and responsibilities; National Cyber Strategy and Cybersecurity Legislation.
- September 20: Meeting with Securities Regulator (SMV); topics include SMV role and responsibilities; overview of securities markets and market infrastructures in Peru; current threat landscape and Cyber strategy of the SMV; cybersecurity oversight and supervisory framework for securities entities and market infrastructures.
- September 23 to October 1: Series of meetings with BCRP, OSIPTEL, INDECOPI, ASBANC, ASOMIF, FIs (BCP, CMAC Arequipa, Positiva Seguros y Reaseguros, Banco de la Nación), FEPCMAC, MEF; topics consistently focus on roles and responsibilities in relation to cybersecurity, current threat landscapes, threat intelligence and information sharing, testing frameworks, cyber incident response and recovery, cyber incident reporting, cyber crisis simulation and exercises; September 30 and October 1 dedicated to discussion of preliminary findings and recommendations and closing meeting with SBS senior management.

*IMF Technical Assistance Report | pages 42–46*

### Annex II .  G7 Fundamental Elements of

### Annex II .  G7 Fundamental Elements of Cybersecurity for the Financial Sector

### Purpose and scope
- Cyber risks are "increasing in sophistication, frequency, and persistence" and "threatening to disrupt our interconnected global financial systems."
- The elements are "non-binding, high-level fundamental elements" intended for financial sector private and public entities to tailor to their operational and threat landscape, role in the sector, and legal and regulatory requirements.
- The elements serve as building blocks to design and implement a cybersecurity strategy and operating framework, and as a dynamic process for systematic re-evaluation as the operational and threat environment evolves.
- Public authorities can use the elements to guide public policy, regulatory, and supervisory efforts.

### Element 1: Cybersecurity Strategy and Framework
- Establish and maintain a cybersecurity strategy and framework tailored to specific cyber risks and appropriately informed by international, national, and industry standards and guidelines.
- Purpose: specify how to identify, manage, and reduce cyber risks in an integrated and comprehensive manner.
- Entities should tailor strategies to their "nature, size, complexity, risk profile, and culture."
- Jurisdictions can establish sector-wide cybersecurity strategies that outline cooperation between entities, public authorities, dependent sectors, and other jurisdictions.

### Element 2: Governance
- Define and facilitate roles and responsibilities for personnel implementing, managing, and overseeing the cybersecurity strategy and framework to ensure accountability.
- Provide adequate resources, appropriate authority, and access to the governing authority (e.g., board of directors or senior officials at public authorities).
- Boards of directors (or similar oversight bodies) should establish cyber risk tolerance and oversee design, implementation, and effectiveness of cybersecurity programs.
- Effective governance: clear responsibilities, lines of reporting and escalation, mediation of competing objectives, and fostering communication among operating units, IT, risk, and control activities.

### Element 3: Risk and Control Assessment
- Identify functions, activities, products, and services—including interconnections, dependencies, and third parties—prioritize their relative importance, and assess their respective cyber risks.
- Evaluate inherent cyber risk (risk absent compensating controls) presented by people, processes, technology, and data supporting each identified function, activity, product, and service.
- Identify and assess existence and effectiveness of controls to determine residual cyber risk.
- Protection mechanisms: avoid/eliminate, mitigate through controls, or share/transfer risk.
- Assess risks entities present to others and to the financial sector as a whole.
- Public authorities should map critical economic functions to identify single points of failure and concentration risk; examples of critical economic functions include "deposit taking, lending, and payments to trading, clearing, settlement, and custody."

### Element 4: Monitoring
- Establish systematic monitoring processes to rapidly detect cyber incidents and periodically evaluate effectiveness of identified controls, including network monitoring, testing, audits, and exercises.
- Monitoring helps adhere to risk tolerances and timely remediate weaknesses.
- Testing and auditing protocols provide assurance and should be appropriately independent based on entity nature, cyber risk profile, and control environment.
- Public authorities can use examinations, on-site and other supervisory mechanisms, comparative analysis of testing results, and joint public-private exercises to understand sector-wide threats and vulnerabilities and individual entities’ risk profiles.

### Element 5: Response
- Timely actions to:
  - (a) assess the nature, scope, and impact of a cyber incident;
  - (b) contain the incident and mitigate its impact;
  - (c) notify internal and external stakeholders (such as law enforcement, regulators, and other public authorities, as well as shareholders, third-party service providers, and customers as appropriate);
  - (d) coordinate joint response activities as needed.
- Entities should implement incident response policies and controls that address decision-making responsibilities, escalation procedures, and stakeholder communication.
- Exercising protocols within and among entities and public authorities improves effectiveness and identifies interdependencies affecting maintenance of critical functions.

### Element 6: Recovery
- Resume operations responsibly while allowing for continued remediation, including by:
  - (a) eliminating harmful remnants of the incident;
  - (b) restoring systems and data to normal and confirming normal state;
  - (c) identifying and mitigating all vulnerabilities that were exploited;
  - (d) remediating vulnerabilities to prevent similar incidents;
  - (e) communicating appropriately internally and externally.
- Recovery should prioritize critical economic and other functions in accordance with objectives set by relevant public authorities.
- Pre-established and tested contingency plans for essential activities and key processes, such as funding, contribute to faster and more effective recovery.
- Mutual assistance among entities and public authorities in resumption and recovery of critical functions improves trust and confidence.

### Element 7: Information Sharing
- Engage in timely sharing of reliable, actionable cybersecurity information with internal and external stakeholders (including entities and public authorities within and outside the financial sector) on threats, vulnerabilities, incidents, and responses.
- Sharing technical information (e.g., threat indicators, exploitation details) helps entities update defenses and learn attacker methods.
- Sharing broader insights deepens collective understanding of sector-wide vulnerabilities that could disrupt critical economic functions and endanger financial stability.
- Entities and public authorities should identify and address impediments to information sharing.

### Element 8: Continuous Learning
- Regularly review the cybersecurity strategy and framework and when events warrant, including governance, risk and control assessment, monitoring, response, recovery, and information sharing components.
- Objectives: address changes in cyber risks, allocate resources, identify and remediate gaps, and incorporate lessons learned.
- Reviews should consider rapid evolution of cyber threats and vulnerabilities, best practices, technical standards, changes in sector composition, emergence of new entities/products/services, and reliance on third-party service providers.
- Consider developments in external dependency sectors (e.g., energy and telecommunications) as part of review processes.

### Annex III: International Practices of Comprehensive Testing Framework
- CPMI-IOSCO’s Cyber Resilience Guidance for FMIs: emphasizes a comprehensive testing program leveraging cyber threat intelligence to design tests simulating advanced threats and extreme scenarios; methodologies include vulnerability assessments, scenario-based testing, penetration tests, and red team exercises; tests should involve internal and external stakeholders, including business continuity and crisis response teams; results should be used to continuously improve cyber resilience with senior management and board awareness.
- European Central Bank — TIBER-EU:
  - Framework name: "Threat Intelligence-Based Ethical Red Teaming (TIBER-EU) framework."
  - Purpose: structured approach for FIs to conduct controlled cyberattack simulations based on credible threat intelligence.
  - Benefits: helps institutions identify and address weaknesses in people, processes, and technologies by emulating tactics used by real adversaries.
  - Adoption: "successfully adopted across various EU jurisdictions."
  - Source mention: "ECB TIBER-EU Framework, 2018"
- Bank of England — CBEST:
  - Framework name: "CBEST framework."
  - Purpose: delivers intelligence-led penetration testing for the UK's most significant FIs by combining threat intelligence from government and accredited providers to simulate sophisticated attacks.
  - Benefits: provides realistic assessment of an institution's cyber defenses and response capabilities and has "significantly improved the understanding and management of cyber risks within the UK financial sector."
  - Source mention: "CBEST Framework (Bank of England)."

*IMF Technical Assistance Report — Annex II: G7 Fundamental Elements of Cybersecurity for the Financial Sector; Annex III: International Practices of Comprehensive Testing Framework*

---


_Source: https://www.imf.org/-/media/files/publications/tar/2025/english/tarea2025066-print-pdf.pdf_
