BIS lays out steps for ‘secure and resilient’ CBDC systems

BIS says a cyber attack on “critical infrastructure” could threaten potential CBDC framework

article-image

Proxima Studio/Shutterstock modified by Blockworks

share

Research into safe and sustainable CBDC systems has continued apace, with the Bank of International Settlements on Friday outlining the agency’s latest steps to provide a “security and resilience framework” for them.

The idea behind the Bank of International Settlements’ paper, published on Friday, was to help banks safeguard against risks when it comes to CBDC implementation. 

The paper, dubbed Project Polaris, is designed to get ahead of CBDC launches and protect “critical infrastructure.”

While some central banks — such as Kenya — have said the once-promising allure of CBDCs has faded, other financial institutions, like the IMF, are receptive to possible adaptation.

While central banks largely have cyber security measures in place, the introduction and rollout of CBDCs could lead to new risks. While over 100 countries — including the UK and US — are currently exploring a potential CBDC, few have moved beyond small-stage, pilot projects and into actual implementation. 

“CBDC systems will need to remain highly resilient in a broad range of scenarios, including short-term (such as temporary system outages), ongoing situations (such as in areas without reliable internet, telecommunications connectivity or power), or civil contingency conditions (such as natural disasters or war), 9 besides being highly responsive in normal operations,” the BIS wrote.

Successful and safe implementation requires modernized technology to not only support a CBDC, but also to protect it, the agency found — echoed by other central banks.

Among the suggestions, Project Polaris pushed for central banks to hire a chief security officer (CSO). 

The CSO would then be able to have “regular” communication with counterparts across the globe, since CBDCs will require an international framework. There would also be an “incident response team” who could respond to a variety of potential scenarios.

It also urges central banks to consider other operators needed in a CBDC ecosystem, from commercial banks to merchant partners. This would lead up to the fulfillment of a resilience requirement — similar to a stress test — depending on the CBDCs “weakest link.”

Overall, frequent check-ups and assurances of secure technology are said to be key for any CBDC if central banks decide to deploy them.

“The framework could also help central banks assess their cyber security and resilience maturity level as it stands today as compared with what could be required when operating a CBDC system, by assessing and ranking how the organization adheres to the practices outlined in this framework,” the BIS wrote.

Project Polaris is not the first foray into CBDC research that the BIS has conducted. It put out another report in late June focused on how commercial banks could tokenize customer deposits.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 24 - 26, 2026

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Flying_Tulip.png

Research

Flying Tulip's perpetual put option provides real principal protection, but investors must pay a valuation premium today for products that have to be built over the next 24 months. This structure works best as a stablecoin substitute where the put allows continuous monitoring—accept opportunity cost in exchange for asymmetric upside if the team executes on its ambitious cross-collateral architecture.

article-image

As flows consolidate and volatility fades, finding edge now means knowing which games are still worth playing

article-image

Value distribution came to $1.9 billion distributed in Q3, though total revenues have yet to beat 2021 heights

article-image

MegaETH public sale auction ends tomorrow, and the free money machine has attracted people who like free money

article-image

With tBTC under the hood, Acre abstracts bridging and converts non-BTC rewards to bitcoin

article-image

Accountable is also eyeing mid-November for mainnet launch

article-image

“Adjusted for size, I think it may be the most successful ETP launch of all time,” Bitwise CIO Matt Hougan says