Skip to content
Critical Infrastructure

Uzbekistan's Central Bank is moving toward risk-based cyber supervision

4 min read
Share

On August 25, at the Silk Road Finance and Technology Forum in Tashkent, Mirzabek Bobojanov, Head of Unit at CERT-CBU, announced that the Central Bank of Uzbekistan will introduce a new cybersecurity maturity assessment framework for financial institutions in 2027.

The current regulatory model applies uniform compliance requirements across the sector. The new one will assess each institution individually based on its actual cyber risk exposure and maturity level.

This is the right direction, and it matters more than a single forum announcement might suggest.

Why the existing model is insufficient

Uzbekistan's financial sector has grown faster than most observers expected. Uzum reached a $1.5 billion valuation in 2025, backed by Tencent and VR Capital. TBC Uzbekistan is expanding. Uzcard and Humo are scaling digital payment infrastructure across the country. Open banking frameworks are being developed. The fintech ecosystem looks increasingly like what you would expect from a market with 36 million people and significant unbanked population.

A compliance checklist designed for a slower-moving sector does not adequately capture the security posture of a bank deploying machine learning-based fraud detection at scale versus a regional lender still running batch-file reconciliation. Both may pass the same checklist. Only one is operating at the risk surface implied by its technology choices.

The scale of the threat

In the first half of 2026, Uzbekistan authorities blocked 29 trillion soums (approximately $2.44 billion) in fraudulent withdrawals, deactivated 18,838 bank cards linked to criminal activity, and solved 9,282 cybercrimes. The Interior Ministry has declared 2026 the Year of Combating Cybercrime.

These are not numbers that suggest a threat landscape a compliance checkbox is going to contain.

The session at the Silk Road Forum covering this topic, titled Trust at the Speed of AI: Cyber Resilience and Fraud Defence for Payment Rails, included participants from Visa CEMEA, Ipak Yuli Bank, Asakabank, and KPMG Uzbekistan. The framing around AI is not incidental. The fraud methods targeting Uzbek financial infrastructure are increasingly AI-assisted, and the supervision framework needs to account for that.

What risk-based maturity assessment means in practice

The model Bobojanov described is familiar to anyone who has worked with the UK's CBEST framework or the EU's TIBER-EU program. Rather than auditing against a fixed control list, it assesses each institution's maturity across domains (governance, detection, response, recovery) and calibrates expectations to the institution's risk profile and operational complexity.

The practical effect: a systemically important bank with significant digital payment volumes faces a materially different assessment than a smaller regional institution. This allows the supervisor to focus examination resources on the highest-risk institutions and avoid creating a false sense of security from checkbox compliance at institutions operating at low risk and low complexity.

The 2027 target gives banks in Uzbekistan roughly a year to prepare. Based on how these programs have been implemented elsewhere, near-term actions include: conducting a self-assessment against NIST CSF or ISO 27001, identifying control gaps most likely to matter under a risk-based framework, and engaging with CERT-CBU's consultation process as the framework is developed.

The regional significance

Uzbekistan is the most populous country in Central Asia and increasingly functions as a regional hub for fintech and digital commerce. The regulatory approach it adopts in financial cybersecurity will have influence on how peer regulators in Kazakhstan, Kyrgyzstan, and Tajikistan approach the same questions. A shift toward risk-based maturity supervision, if well implemented, is the kind of model that could travel.

The Central Bank of Uzbekistan is making a bet that the sector it regulates is mature enough to be supervised in a more sophisticated way. The 2027 launch will test that assumption.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you work in financial sector security in the Caucasus or Central Asia and want to discuss what risk-based cybersecurity supervision looks like in practice.

Related articles