Banking Law And Financial Market Infrastructure Regulation Spain .
Banking Law and Financial Market Infrastructure Cyber Resilience in Kuwait
Introduction
Financial market infrastructure (FMI) cyber resilience concerns the ability of payment, clearing, settlement, banking and related financial systems to prevent, withstand, respond to and recover from cyber and operational disruptions.
In Kuwait, this subject has become increasingly important because banks, payment providers and public institutions depend heavily on interconnected electronic systems. The Central Bank of Kuwait (CBK) operates or oversees important national payment infrastructure, including the Kuwait Automated Settlement System for Inter-participant Payments (KASSIP) and other clearing and payment arrangements. KASSIP operates through CBK-Net and follows the Principles for Financial Market Infrastructures (PFMIs).
The regulatory approach has also evolved significantly. The CBK's 2020 Cybersecurity Framework established sector-wide cybersecurity requirements. On 3 December 2025, the CBK introduced the Cyber and Operational Resilience Framework (CORF), moving toward a resilience-focused and maturity-oriented supervisory model.
Legal and Regulatory Framework
1. Central Bank of Kuwait's Supervisory Authority
The principal institutional authority is the Central Bank of Kuwait, operating under Kuwait's banking legislation.
Its responsibilities extend beyond supervising individual banks. The CBK oversees payment systems to maintain their safety, efficiency and reliability and conducts reviews covering participant performance, operations and risk management.
Cyber resilience therefore forms part of the broader objective of protecting financial and monetary stability.
2. Cyber and Operational Resilience Framework
The 2025 Cyber and Operational Resilience Framework (CORF) updated the earlier 2020 cybersecurity framework.
Its approach is broader than conventional information security. The regulatory objective is for financial institutions not merely to prevent cyberattacks but also to anticipate disruptions, withstand them, restore critical services and adapt following incidents.
The framework became applicable to local banks and financial institutions from 3 December 2025.
This reflects an important regulatory distinction:
Cybersecurity concentrates primarily on protecting systems and information.
Cyber resilience additionally considers whether essential financial services can continue or be rapidly restored when protective measures fail.
3. Electronic Transactions Law
Law No. 20 of 2014 concerning Electronic Transactions provides an important statutory foundation for electronic payments.
The legislation gives the CBK authority over electronic payment transactions and permits it to issue binding regulatory instructions.
Using this authority, the CBK updated its Instructions for Regulating the Electronic Payment of Funds in May 2023. These rules impose requirements relating to governance, risk management, AML/CFT, cybersecurity, business continuity and customer protection.
4. KASSIP and Systemically Important Payments
KASSIP is Kuwait's real-time gross settlement infrastructure for inter-participant payments.
Transactions are processed individually and, following settlement, are final and non-retractable. Participating institutions connect through CBK-Net, the CBK's private network.
The CBK expressly requires participants to manage risks arising from their use of the system so that transactions continue regularly and operational continuity and safety are maintained.
Consequently, a cyberattack affecting a participating bank is not merely an internal IT problem. If sufficiently serious, it can become a financial-infrastructure risk.
5. Kuwait Automated Clearing House
Kuwait's infrastructure was further developed when the CBK launched the Kuwait Automated Clearing House (KACH) in January 2026.
KACH supports automated low-value and recurring transactions and can transmit transactions around the clock, including public holidays. Its architecture uses the secure closed CBK-Net environment based on VPN technology and encrypted payment messaging. Final net settlements are transmitted to KASSIP.
The interconnection illustrates why cyber resilience must address the financial ecosystem rather than individual institutions separately.
Core Principles of FMI Cyber Resilience
Governance
Senior management and boards should treat cyber risk as an enterprise and financial-stability issue rather than solely as an IT function.
Responsibility should therefore be clearly allocated for cyber-risk management, incident escalation, business continuity and recovery.
Identification of Critical Operations
Financial institutions should identify systems whose disruption could materially affect payments, settlements or customer services.
Critical systems can include payment gateways, settlement connections, customer databases, authentication infrastructure and communication networks.
Protection
Preventive controls include access management, authentication, encryption, network segmentation, security monitoring and protection of sensitive financial information.
The CBK previously required local banks to maintain ISO 27001 certification covering relevant information-security and technology areas.
Detection
Resilience requires rapid identification of abnormal activity.
Banks and payment institutions therefore need monitoring mechanisms capable of distinguishing legitimate activity from potential cybersecurity incidents.
Incident Response
A cyber incident should trigger predetermined escalation and crisis-management procedures.
The CBK's earlier cybersecurity strategy already incorporated cyber-crisis management and mechanisms for reporting and sharing cyber-threat information among banks.
Recovery and Business Continuity
An institution should be capable of restoring essential operations following disruption.
Recovery plans should address data integrity, backup systems, alternative processing arrangements, communications and dependencies on external technology providers.
The CBK confirmed in March 2026 that local banks had been strengthening business-continuity and emergency plans, upgrading digital infrastructure and conducting scenario-based exercises as part of operational preparedness.
Third-Party Risk
Modern banking institutions rely extensively on technology suppliers and infrastructure providers.
Consequently, outsourcing does not eliminate cyber risk. Banks need appropriate governance over external providers because disruption at a technology supplier can affect multiple financial institutions simultaneously.
Relevant Case Laws
A significant qualification is necessary: published Kuwaiti jurisprudence specifically concerning cyber resilience of financial market infrastructures is extremely limited. Kuwait's framework is primarily regulatory and supervisory rather than case-law driven.
Accordingly, it would be inaccurate to invent six Kuwaiti “FMI cyber-resilience cases.” The following established cases provide relevant comparative legal principles concerning cybersecurity, payment systems, unauthorized transactions, data protection and financial infrastructure.
1. CJEU – Bundesverband der Verbraucherzentralen v Deutsche Kreditbank, Case C-28/18
The Court examined payment-services requirements relating to communication between a bank and its customers.
Relevance: Secure electronic communication is an important component of digital payment infrastructure. Financial institutions must ensure that electronic banking arrangements comply with legal requirements governing accessibility and communication of payment information.
2. CJEU – DenizBank AG v Verein für Konsumenteninformation, Case C-287/19
This case concerned payment cards equipped with near-field communication functionality and the application of EU payment-services rules.
The Court considered questions involving payment instruments, authentication and unauthorized transactions.
Relevance to Kuwait: Contactless and automated payment systems require a legal allocation of responsibility when authentication or security mechanisms fail.
3. CJEU – Beobank SA v JL, Case C-351/21
The case concerned a disputed payment transaction and the information that a payment-service provider must provide to a customer.
Relevance: Cyber resilience includes maintaining reliable transaction records and mechanisms enabling suspicious or unauthorized transactions to be investigated.
4. CJEU – BAWAG PSK Bank für Arbeit und Wirtschaft und Österreichische Postsparkasse, Case C-375/15
The Court considered how information required under payment-services legislation could be supplied through electronic banking channels.
Relevance: Financial infrastructures must maintain secure and legally effective electronic communications, particularly where important financial information is transmitted digitally.
5. CJEU – WM and Sovim SA, Joined Cases C-37/20 and C-601/20
Although primarily concerning beneficial-ownership information and data protection rather than payment infrastructure, the judgment examined the balance between regulatory objectives and protection of personal information.
Relevance: Cyber-resilient financial infrastructure must protect confidentiality and data integrity while meeting legitimate regulatory requirements.
6. CJEU – Österreichische Post, Case C-300/21
The Court examined compensation under the GDPR following unlawful processing of personal data.
Relevance: A cyber or operational incident affecting financial infrastructure can generate not only operational consequences but also potential data-protection liability where personal information is compromised.
7. CJEU – VB v Natsionalna agentsia za prihodite, Case C-340/21
This judgment is especially relevant to cybersecurity. It concerned personal data disclosed following a cyberattack against a public authority.
The Court addressed security obligations, assessment of appropriate technical and organisational measures, and potential compensation.
Relevance to Kuwaiti financial institutions: A successful cyberattack does not by itself determine every question of legal responsibility. The adequacy of organizational and technical security arrangements remains central to determining whether required safeguards were implemented.
Application to Kuwait's Financial Infrastructure
These principles can be applied to Kuwait through the CBK's regulatory architecture.
A cyber incident involving a local bank could potentially disrupt its connection with national payment systems. An attack against an electronic-payment infrastructure provider could affect large numbers of retail transactions. Compromise of a third-party technology provider could simultaneously affect several institutions.
This interconnectedness explains why the CBK's approach has moved from basic cybersecurity compliance toward broader operational resilience.
Kuwait's payment-system modernization reinforces this requirement. KASSIP uses CBK-Net and ISO 20022 messaging, while KACH uses secure encrypted communications and feeds final net settlements into KASSIP.
A resilient architecture therefore requires protection at multiple levels: individual banks, payment providers, communication networks, settlement infrastructure and third-party technology providers.
Relationship with International Standards
Kuwait's framework also reflects international financial-infrastructure standards.
The CBK states that KASSIP operates within the Principles for Financial Market Infrastructures, developed by the Committee on Payments and Market Infrastructures and IOSCO.
These principles emphasize operational reliability, risk management, settlement finality and business continuity.
Cyber resilience complements these traditional FMI requirements. A settlement system may have legally sound rules, sufficient liquidity arrangements and clear settlement finality, but it cannot perform its financial-stability function if a cyber incident makes the infrastructure unavailable or corrupts essential information.
Regulatory Challenges
Several challenges remain particularly significant.
Systemic concentration risk arises when many institutions depend on the same network, technology supplier or payment infrastructure.
Third-party dependency means that banks must consider vulnerabilities outside their direct technological environment.
Rapid technological change can cause security controls to become outdated.
Cross-border interconnectedness means that cyber incidents outside Kuwait can potentially affect domestic banks through correspondent banking, payment networks or technology providers.
Recovery integrity is equally important. Rapidly restoring a system is insufficient if the institution cannot establish that transaction and account data remain accurate.
Finally, regulators must balance security and innovation. Excessively weak controls increase systemic vulnerability, while unnecessarily restrictive requirements can impede legitimate financial innovation.
Conclusion
Banking law and financial market infrastructure cyber resilience in Kuwait have evolved from conventional information-security requirements toward a comprehensive resilience-based regulatory framework.
The most important development is the CBK's 2025 Cyber and Operational Resilience Framework, which updated the 2020 cybersecurity framework and focuses on the ability of regulated institutions to anticipate, withstand, recover from and adapt to disruption.
This framework operates alongside Law No. 20 of 2014, the 2023 electronic-payment regulations, CBK payment-system oversight, KASSIP, CBK-Net and the newer KACH infrastructure. Together, these arrangements seek to protect the confidentiality, integrity, availability and continuity of Kuwait's financial system.
The comparative cases discussed above—Deutsche Kreditbank, DenizBank, Beobank, BAWAG, Sovim, Österreichische Post, and VB—provide useful judicial principles concerning secure payments, authentication, electronic communication, data protection and cybersecurity responsibility.
However, they should not be described as Kuwaiti case law. Published Kuwait-specific judicial decisions directly addressing FMI cyber resilience remain limited, so the strongest legal analysis of this subject presently comes from Kuwait's statutes, CBK regulations and supervisory frameworks rather than from six directly equivalent Kuwaiti court precedents.

comments