Using Simulations for Cyber Stress Testing Exercises
IMF Working Papers, May 2, 2025
Source details
- Canonical URL
- Using Simulations for Cyber Stress Testing Exercises
Other formats
Bibliographic details
- Authors: Tanai Khiaonarong, Kasperi N Korpinen, Emran Islam
- Published: May 2, 2025
- Series: IMF Working Papers
- DOI: https://doi.org/10.5089/9798229008952.001
Overview of framework
- Demonstrates how computer-based simulations could support cyber stress testing exercises through a three-step framework.
- Step 1: Cyber-attack scenarios are designed to target the systemic nodes of a payment network at different times, disrupting a major bank, critical service provider, large-value payment system, and a foreign exchange settlement system.
- Step 2: The stress resulting from the scenarios is simulated using transaction-level data, and its impact is measured through a range of risk metrics.
- Step 3: Cyber preparedness is discussed to identify effective practices that could strengthen the cyber resilience of the financial sector.
Scenario design and simulation approach
- Attack targets enumerated:
- A major bank
- A critical service provider (common dependency across banks)
- A large-value payment system (centralized payment system)
- A foreign exchange settlement system
- Simulation inputs and methods:
- Uses transaction-level data to simulate stress.
- Measures impact through a range of risk metrics (as described in the exercise).
Key findings and illustrative results
- Main insights:
- The exercise provides insights into the main vulnerabilities of the financial sector and key transmission channels under plausible scenarios that necessitate preemptive action and recovery and response measures.
- Finnish-data example (simulation results for Finnish data):
- End-of-day liquidity risk is most severe when a cyber-attack hits a major bank or several banks simultaneously through dependence on a common critical service provider.
- An attack on a centralized payment system produces less severe end-of-day liquidity risk where effective queuing and liquidity-saving mechanisms can better support recovery.
- Outcomes could be aggravated under more severe and prolonged scenarios.
Policy implications and cyber preparedness
- Objectives of preparedness discussion:
- Identify effective practices that could strengthen the cyber resilience of the financial sector.
- Highlight need for preemptive action and recovery and response measures.
- Recommended focus areas (as reflected by the exercise):
- Reducing single points of failure associated with critical service providers.
- Strengthening queuing and liquidity-saving mechanisms within centralized payment systems.
- Planning for scenarios that are more severe and prolonged to assess potential aggravation of outcomes.
Content in this bundle
- Working Paper