BIS lays out steps for ‘secure and resilient’ CBDC systems

BIS says a cyber attack on “critical infrastructure” could threaten potential CBDC framework


Proxima Studio/Shutterstock modified by Blockworks


Research into safe and sustainable CBDC systems has continued apace, with the Bank of International Settlements on Friday outlining the agency’s latest steps to provide a “security and resilience framework” for them.

The idea behind the Bank of International Settlements’ paper, published on Friday, was to help banks safeguard against risks when it comes to CBDC implementation. 

The paper, dubbed Project Polaris, is designed to get ahead of CBDC launches and protect “critical infrastructure.”

While some central banks — such as Kenya — have said the once-promising allure of CBDCs has faded, other financial institutions, like the IMF, are receptive to possible adaptation.

While central banks largely have cyber security measures in place, the introduction and rollout of CBDCs could lead to new risks. While over 100 countries — including the UK and US — are currently exploring a potential CBDC, few have moved beyond small-stage, pilot projects and into actual implementation. 

“CBDC systems will need to remain highly resilient in a broad range of scenarios, including short-term (such as temporary system outages), ongoing situations (such as in areas without reliable internet, telecommunications connectivity or power), or civil contingency conditions (such as natural disasters or war), 9 besides being highly responsive in normal operations,” the BIS wrote.

Successful and safe implementation requires modernized technology to not only support a CBDC, but also to protect it, the agency found — echoed by other central banks.

Among the suggestions, Project Polaris pushed for central banks to hire a chief security officer (CSO). 

The CSO would then be able to have “regular” communication with counterparts across the globe, since CBDCs will require an international framework. There would also be an “incident response team” who could respond to a variety of potential scenarios.

It also urges central banks to consider other operators needed in a CBDC ecosystem, from commercial banks to merchant partners. This would lead up to the fulfillment of a resilience requirement — similar to a stress test — depending on the CBDCs “weakest link.”

Overall, frequent check-ups and assurances of secure technology are said to be key for any CBDC if central banks decide to deploy them.

“The framework could also help central banks assess their cyber security and resilience maturity level as it stands today as compared with what could be required when operating a CBDC system, by assessing and ranking how the organization adheres to the practices outlined in this framework,” the BIS wrote.

Project Polaris is not the first foray into CBDC research that the BIS has conducted. It put out another report in late June focused on how commercial banks could tokenize customer deposits.

Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

The Lightspeed newsletter is all things Solana, in your inbox, every day. Subscribe to daily Solana news from Jack Kubinec and Jeff Albus.


Upcoming Events

Salt Lake City, UT

MON - TUES, OCT. 7 - 8, 2023

Blockworks and Bankless in collaboration with buidlbox are excited to announce the second installment of the Permissionless Hackathon – taking place October 7-8 in Salt Lake City, Utah. We’ve partnered with buidlbox to bring together the brightest minds in crypto for […]

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Pack your bags, anon — we’re heading west! Join us in the beautiful Salt Lake City for the third installment of Permissionless. Come for the alpha, stay for the fresh air. Permissionless III promises unforgettable panels, killer networking opportunities, and mountains […]

recent research

Research Report Cover Vertex.jpg


The proliferation of new perp DEXs has led to fragmented liquidity across various DEXs and chains. Vertex, known for its vertically-integrated DEX that includes spot, perpetual, and integrated money markets, is now tackling cross-chain liquidity fragmentation through horizontal integration with the launch of new Edge instances. Vertex's integrated offerings and cross-margined account structure amplify the benefits of new instances: native cross-chain spot trading, optimized cross-chain basis trading, consistent interest rates, reduced bridging friction, and more.


Partnering with EtherFi and Angle, the fully on-chain perp DEX features bespoke collateral



Gavin Wood introduced the next evolutionary step for the Polkadot network: the Join-Accumulate Machine, or JAM


The side events were the places to be at Consensus 2024, according to attendees


Also, who’s come out swinging in the spot ether ETF fee war — and who could undercut them


I know it is not in their nature, but US regulators could learn a lot by researching the digital asset frameworks that overseas regulators have already gotten right


Also, the ETF hype train can count out at least one member