{
  "title": "Using Simulations for Cyber Stress Testing Exercises",
  "publication": "IMF Working Papers, May 2, 2025",
  "sourceUrl": "https://www.imf.org/en/publications/wp/issues/2025/05/02/using-simulations-for-cyber-stress-testing-exercises-566489",
  "canonical": "https://www.imf.org/en/publications/wp/issues/2025/05/02/using-simulations-for-cyber-stress-testing-exercises-566489",
  "overlayPath": "/en/publications/wp/issues/2025/05/02/using-simulations-for-cyber-stress-testing-exercises-566489/index.md",
  "summary": "We demonstrate how computer-based simulations could support cyber stress testing exercises through a three-step framework.",
  "sections": [
    {
      "heading": "Overview of framework",
      "content": "- Demonstrates how computer-based simulations could support cyber stress testing exercises through a three-step framework.\n  - Step 1: Cyber-attack scenarios are designed to target the systemic nodes of a payment network at different times, disrupting a major bank, critical service provider, large-value payment system, and a foreign exchange settlement system.\n  - Step 2: The stress resulting from the scenarios is simulated using transaction-level data, and its impact is measured through a range of risk metrics.\n  - Step 3: Cyber preparedness is discussed to identify effective practices that could strengthen the cyber resilience of the financial sector."
    },
    {
      "heading": "Scenario design and simulation approach",
      "content": "- Attack targets enumerated:\n  - A major bank\n  - A critical service provider (common dependency across banks)\n  - A large-value payment system (centralized payment system)\n  - A foreign exchange settlement system\n- Simulation inputs and methods:\n  - Uses transaction-level data to simulate stress.\n  - Measures impact through a range of risk metrics (as described in the exercise)."
    },
    {
      "heading": "Key findings and illustrative results",
      "content": "- Main insights:\n  - The exercise provides insights into the main vulnerabilities of the financial sector and key transmission channels under plausible scenarios that necessitate preemptive action and recovery and response measures.\n- Finnish-data example (simulation results for Finnish data):\n  - End-of-day liquidity risk is most severe when a cyber-attack hits a major bank or several banks simultaneously through dependence on a common critical service provider.\n  - An attack on a centralized payment system produces less severe end-of-day liquidity risk where effective queuing and liquidity-saving mechanisms can better support recovery.\n  - Outcomes could be aggravated under more severe and prolonged scenarios."
    },
    {
      "heading": "Policy implications and cyber preparedness",
      "content": "- Objectives of preparedness discussion:\n  - Identify effective practices that could strengthen the cyber resilience of the financial sector.\n  - Highlight need for preemptive action and recovery and response measures.\n- Recommended focus areas (as reflected by the exercise):\n  - Reducing single points of failure associated with critical service providers.\n  - Strengthening queuing and liquidity-saving mechanisms within centralized payment systems.\n  - Planning for scenarios that are more severe and prolonged to assess potential aggravation of outcomes.\n\n---\n\n Content in this bundle\n\n- Working Paper\n  - Working Paper (Markdown version){rel=\"alternate\" type=\"text/markdown\"}\n  - Working Paper (PDF){rel=\"external\" type=\"application/pdf\"}\n\n---\n\nSource: https://www.imf.org/en/publications/wp/issues/2025/05/02/using-simulations-for-cyber-stress-testing-exercises-566489"
    }
  ],
  "bullets": [
    "[Markdown version](/en/publications/wp/issues/2025/05/02/using-simulations-for-cyber-stress-testing-exercises-566489/index.md)",
    "[Structured JSON version](/en/publications/wp/issues/2025/05/02/using-simulations-for-cyber-stress-testing-exercises-566489/index.json)",
    "[Bundle manifest](/en/publications/wp/issues/2025/05/02/using-simulations-for-cyber-stress-testing-exercises-566489/bundle-manifest.json)",
    "Authors: Tanai Khiaonarong, Kasperi N Korpinen, Emran Islam",
    "Published: May 2, 2025",
    "Series: IMF Working Papers",
    "DOI: https://doi.org/10.5089/9798229008952.001",
    "Demonstrates how computer-based simulations could support cyber stress testing exercises through a three-step framework.",
    "Attack targets enumerated:",
    "Simulation inputs and methods:",
    "Main insights:",
    "Finnish-data example (simulation results for Finnish data):",
    "Objectives of preparedness discussion:",
    "Recommended focus areas (as reflected by the exercise):",
    "**Working Paper**"
  ],
  "related": [
    {
      "title": "Working Paper",
      "role": "paper",
      "sourceUrl": "https://www.imf.org/-/media/files/publications/wp/2025/english/wpiea2025085-print-pdf.pdf",
      "summary": {
        "path": "/-/media/files/publications/wp/2025/english/wpiea2025085-print-pdf.pdf.md",
        "mime": "text/markdown"
      },
      "binary": {
        "path": "/-/media/files/publications/wp/2025/english/wpiea2025085-print-pdf.pdf",
        "mime": "application/pdf"
      }
    }
  ],
  "alternates": {
    "markdown": "/en/publications/wp/issues/2025/05/02/using-simulations-for-cyber-stress-testing-exercises-566489/index.md",
    "json": "/en/publications/wp/issues/2025/05/02/using-simulations-for-cyber-stress-testing-exercises-566489/index.json",
    "bundleManifest": "/en/publications/wp/issues/2025/05/02/using-simulations-for-cyber-stress-testing-exercises-566489/bundle-manifest.json"
  },
  "generatedAtUtc": "2026-09-17T01:40:13.764Z"
}
