## Using Simulations for Cyber Stress Testing Exercises

_IMF Working Papers, May 2, 2025_

## Source details

**Canonical URL:** [Using Simulations for Cyber Stress Testing Exercises](https://www.imf.org/en/publications/wp/issues/2025/05/02/using-simulations-for-cyber-stress-testing-exercises-566489)

## Other formats

- [Markdown version](/en/publications/wp/issues/2025/05/02/using-simulations-for-cyber-stress-testing-exercises-566489/index.md)
- [Structured JSON version](/en/publications/wp/issues/2025/05/02/using-simulations-for-cyber-stress-testing-exercises-566489/index.json)
- [Bundle manifest](/en/publications/wp/issues/2025/05/02/using-simulations-for-cyber-stress-testing-exercises-566489/bundle-manifest.json)

## Bibliographic details
- Authors: Tanai Khiaonarong, Kasperi N Korpinen, Emran Islam
- Published: May 2, 2025
- Series: IMF Working Papers
- DOI: https://doi.org/10.5089/9798229008952.001

---

### Overview of framework
- Demonstrates how computer-based simulations could support cyber stress testing exercises through a three-step framework.
  - Step 1: Cyber-attack scenarios are designed to target the systemic nodes of a payment network at different times, disrupting a major bank, critical service provider, large-value payment system, and a foreign exchange settlement system.
  - Step 2: The stress resulting from the scenarios is simulated using transaction-level data, and its impact is measured through a range of risk metrics.
  - Step 3: Cyber preparedness is discussed to identify effective practices that could strengthen the cyber resilience of the financial sector.

### Scenario design and simulation approach
- Attack targets enumerated:
  - A major bank
  - A critical service provider (common dependency across banks)
  - A large-value payment system (centralized payment system)
  - A foreign exchange settlement system
- Simulation inputs and methods:
  - Uses transaction-level data to simulate stress.
  - Measures impact through a range of risk metrics (as described in the exercise).

### Key findings and illustrative results
- Main insights:
  - The exercise provides insights into the main vulnerabilities of the financial sector and key transmission channels under plausible scenarios that necessitate preemptive action and recovery and response measures.
- Finnish-data example (simulation results for Finnish data):
  - End-of-day liquidity risk is most severe when a cyber-attack hits a major bank or several banks simultaneously through dependence on a common critical service provider.
  - An attack on a centralized payment system produces less severe end-of-day liquidity risk where effective queuing and liquidity-saving mechanisms can better support recovery.
  - Outcomes could be aggravated under more severe and prolonged scenarios.

### Policy implications and cyber preparedness
- Objectives of preparedness discussion:
  - Identify effective practices that could strengthen the cyber resilience of the financial sector.
  - Highlight need for preemptive action and recovery and response measures.
- Recommended focus areas (as reflected by the exercise):
  - Reducing single points of failure associated with critical service providers.
  - Strengthening queuing and liquidity-saving mechanisms within centralized payment systems.
  - Planning for scenarios that are more severe and prolonged to assess potential aggravation of outcomes.

---

## Content in this bundle

- **Working Paper**
  - [Working Paper (Markdown version)](/-/media/files/publications/wp/2025/english/wpiea2025085-print-pdf.pdf.md){rel="alternate" type="text/markdown"}
  - [Working Paper (PDF)](/-/media/files/publications/wp/2025/english/wpiea2025085-print-pdf.pdf){rel="external" type="application/pdf"}

---

_Source: https://www.imf.org/en/publications/wp/issues/2025/05/02/using-simulations-for-cyber-stress-testing-exercises-566489_
