Banking Law And Information Security Governance Kuwait .
Banking Law and Information Security Governance in Kuwait
1. Introduction
Information security governance in banking means the system through which a bank's board, senior management, risk functions, cybersecurity teams, internal auditors and employees collectively manage the confidentiality, integrity, availability and resilience of financial information and technology systems.
Modern banks are heavily dependent on digital infrastructure. Customer accounts, payment instructions, credit information, identity records, transaction histories and confidential commercial information are stored and processed electronically. Consequently, failure of information security can create not merely an IT problem but also a banking-law, governance, confidentiality, operational-risk and regulatory problem.
In Kuwait, the principal supervisory authority is the Central Bank of Kuwait (CBK). The legal and regulatory framework includes:
Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business, as amended;
CBK supervisory instructions;
the CBK Cybersecurity Framework introduced in 2020;
the Cyber and Operational Resilience Framework (CORF), introduced in December 2025;
information-security standards including ISO/IEC 27001;
confidentiality requirements;
internal-control requirements;
electronic-payment and related financial-sector regulations.
The most significant recent development is CORF, which replaced/evolved the earlier cybersecurity approach into what the CBK describes as a “resilience-first” and “maturity-oriented” regulatory model.
2. Meaning of Information Security Governance
Information security governance is broader than installing firewalls or antivirus software.
It concerns the organisational structure through which information-security decisions are made.
A bank needs to determine:
Who owns cybersecurity risk?
Who approves security policies?
Who monitors compliance?
Who reports major incidents?
Who determines acceptable risk?
Who supervises third-party technology providers?
Who reports serious weaknesses to senior management and the board?
Therefore, governance establishes accountability.
Technology then operates within that governance structure.
3. Central Bank of Kuwait's Supervisory Role
The CBK has extensive statutory supervisory powers over banks and regulated financial institutions.
Article 78 of Kuwait's banking legislation permits the CBK to inspect banks and financial institutions under its supervision.
CBK inspectors may examine accounts, books, records, instruments and other documents considered necessary for the inspection.
The CBK can subsequently prepare a report identifying weaknesses and recommend corrective measures. It can also establish a period within which the regulated institution must correct violations or unsound positions.
This provision is highly relevant to information-security governance.
A bank cannot simply state that cybersecurity is an internal technical matter outside supervisory scrutiny.
Where information-security weaknesses affect banking safety, internal controls, operational resilience or regulatory compliance, they can become part of banking supervision.
4. Development of Kuwait's Cybersecurity Framework
In 2020, the CBK introduced its strategic Cybersecurity Framework for the Kuwaiti banking sector.
The framework was designed to establish an integrated approach to cyber resilience across the banking sector.
Its core architecture included:
Governance, Risk Management and Compliance
Banks were expected to integrate governance, risk and compliance into their business processes.
Cybersecurity Baselines
Minimum security expectations created a common security foundation.
Assessment and Maturity
Institutions needed mechanisms for evaluating cybersecurity capabilities.
Cyber Crisis Management
Banks needed preparation for major incidents.
Cyber Threat Intelligence
Information concerning threats could support sector-wide resilience.
Awareness and Training
Human capabilities were recognised as an important part of cybersecurity.
The framework therefore treated cybersecurity as an enterprise-governance issue rather than simply an IT-department responsibility.
5. Cyber and Operational Resilience Framework – CORF
A major regulatory development occurred on 3 December 2025, when the CBK launched its Cyber and Operational Resilience Framework for local banks and financial institutions.
CORF represents an evolution from the 2020 framework.
The CBK describes this transition as moving from foundational cybersecurity compliance toward a:
resilience-first and maturity-oriented model.
The objective is not merely to prevent attacks.
Regulated institutions should develop capabilities to:
anticipate → withstand → respond → recover → adapt.
This distinction is important.
No sophisticated banking institution can realistically guarantee that every cyber incident will always be prevented.
Modern governance therefore also asks whether the institution can continue critical services and recover safely when disruption occurs.
6. Board Responsibility
Information security should receive appropriate attention at board and senior-management level.
The board's role is generally strategic rather than operational.
It should ensure that the institution has appropriate structures for identifying and controlling significant technology and cybersecurity risks.
Important governance matters include:
risk appetite;
cybersecurity strategy;
organisational responsibilities;
significant technology investments;
material third-party dependencies;
major incidents;
business continuity;
recovery capabilities.
Daily technical security operations can be delegated.
Ultimate governance responsibility cannot simply disappear because specialist employees or contractors perform the technical work.
7. Senior Management Responsibility
Senior management translates board-approved strategy into operational arrangements.
Management should ensure that security policies are actually implemented.
This can require:
appropriate staffing;
security budgets;
internal controls;
incident procedures;
risk reporting;
training;
technology maintenance.
An information-security policy that exists only on paper provides little protection.
Effective governance therefore requires evidence that policies are implemented, tested and reviewed.
8. Three Lines of Responsibility
Banks commonly organise governance around different layers of responsibility.
First Line – Business and Technology Operations
Operational teams manage risks arising from daily banking and technology activities.
Second Line – Risk and Compliance
Independent risk and compliance functions monitor whether activities remain within established requirements and risk limits.
Third Line – Internal Audit
Internal audit independently evaluates whether governance and control systems are appropriately designed and functioning.
This separation helps reduce the possibility that the same department creates, operates and independently evaluates its own security controls.
9. Information Security Function
A specialised information-security function plays a central role.
Typical responsibilities include:
security policy;
security architecture;
access management;
vulnerability management;
threat monitoring;
incident response;
security awareness;
reporting.
Independence is important.
If security personnel cannot escalate serious weaknesses because operational managers want to avoid delays or costs, the governance structure becomes ineffective.
10. Confidentiality, Integrity and Availability
Information-security governance traditionally protects three fundamental characteristics.
Confidentiality
Information should be available only to authorised persons.
Banking confidentiality makes this especially important.
Integrity
Financial information should remain accurate and protected from unauthorised modification.
A payment system that remains available but permits transaction manipulation is not secure.
Availability
Customers and authorised personnel should be able to access necessary systems when required.
Banking services therefore require both cybersecurity and operational resilience.
CORF's emphasis on resilience substantially reinforces the availability dimension.
11. Banking Confidentiality
Kuwaiti banking legislation imposes significant confidentiality obligations.
Information obtained through banking positions cannot simply be disclosed without legal authority.
Article 80 also specifically requires CBK inspection officials to maintain secrecy concerning information obtained through supervisory inspections.
From an information-security perspective, confidentiality should therefore be implemented technologically.
Examples include:
access restrictions;
authentication;
encryption;
logging;
privileged-access controls;
secure transmission.
Legal confidentiality without technical controls would provide incomplete protection.
12. Identity and Access Management
Identity and access management is a fundamental component of security governance.
Banks should ensure that users receive access appropriate to their legitimate responsibilities.
Important principles include:
Least Privilege
Employees receive only the access necessary for their jobs.
Role-Based Access
System permissions correspond to organisational responsibilities.
Privileged Access Management
Powerful administrator accounts receive stronger controls.
Periodic Review
Access rights should be reassessed periodically.
Prompt Revocation
Access should be removed when employment or contractual relationships end.
These mechanisms reduce both external and insider risk.
13. Segregation of Duties
Sensitive banking activities should not unnecessarily depend on one individual.
For example, a person who initiates a major financial transaction should not necessarily be the sole person authorised to approve it.
Likewise, an administrator capable of modifying security settings should not have unrestricted ability to erase independent audit evidence.
Segregation of duties helps prevent:
fraud;
unauthorised transactions;
manipulation of records;
concealment of misconduct.
It is therefore both an internal-control and information-security principle.
14. Risk Assessment
Information-security governance should be risk-based.
Not every information system creates identical risk.
A bank should identify:
critical systems;
important information;
threats;
vulnerabilities;
potential consequences;
existing controls;
remaining risk.
Management can then prioritise security investment.
Core banking and payment systems, for example, generally require stronger controls than low-risk internal applications.
15. ISO/IEC 27001
International information-security standards are also important within Kuwait's banking framework.
The CBK previously required local banks to obtain and maintain relevant ISO/IEC 27001 certification within the cybersecurity framework.
The CBK explained that ISO 27001 supports the development and monitoring of information-security systems through risk assessment and appropriate technical and operational controls.
Certification does not mean that a bank can never suffer a cyber incident.
Rather, it demonstrates implementation of a structured information-security management system within the relevant certification scope.
16. Third-Party Risk
Banks increasingly depend upon external technology providers.
Examples include:
cloud providers;
software developers;
payment processors;
cybersecurity companies;
data centres;
consultants.
Outsourcing technology does not automatically transfer the bank's regulatory responsibilities.
Governance should therefore address:
due diligence;
contractual security requirements;
access controls;
incident reporting;
audit rights;
subcontracting;
business continuity;
exit arrangements.
Concentration risk is also important where many financial institutions depend upon the same technology provider.
17. Cloud Security Governance
Cloud computing creates significant efficiency but also governance questions.
A bank should understand:
where information is processed;
how access is controlled;
how encryption is managed;
how incidents are reported;
whether subcontractors are involved;
how data can be recovered;
how the relationship can be terminated safely.
Moving information to cloud infrastructure therefore changes the technical environment but does not eliminate governance responsibilities.
18. Incident Response
A bank should assume that some security incidents may eventually occur.
Information-security governance must therefore include an incident-response framework.
A typical structure involves:
Detection → Assessment → Containment → Investigation → Recovery → Review.
Roles should be defined before an incident occurs.
During a major cyberattack there may be insufficient time to decide from the beginning who has authority to shut down systems, contact regulators or activate recovery infrastructure.
19. Cyber Crisis Management
A serious cyber incident can become an organisational crisis.
Examples include:
widespread payment-system outage;
ransomware;
major customer-data compromise;
destruction of critical records;
compromise of privileged accounts.
Cyber crisis management therefore involves more than technical response.
Senior management, communications, legal, compliance, business continuity and operational teams may all need to participate.
The earlier CBK cybersecurity framework specifically incorporated cyber crisis management into its architecture.
20. Business Continuity
Operational resilience asks whether critical banking services can continue or recover after disruption.
Banks therefore need:
backup arrangements;
disaster-recovery infrastructure;
recovery priorities;
alternative communications;
testing;
crisis procedures.
CORF substantially strengthens this perspective by placing cyber risk and operational resilience within an integrated supervisory framework.
21. Cybersecurity Awareness and Training
Employees remain an important component of information security.
The CBK has repeatedly invested in cybersecurity capacity building. In May 2025, for example, it announced the fifth edition of its Cybersecurity Leaders Program, aimed at strengthening specialised information and network-security expertise in Kuwait's banking sector.
Training can cover:
security responsibilities;
credential protection;
incident reporting;
confidential information;
social-engineering awareness;
acceptable system use.
Governance therefore combines people, processes and technology.
22. Artificial Intelligence Governance
Banks increasingly use AI for:
fraud detection;
credit assessment;
cybersecurity monitoring;
customer service;
AML monitoring;
document processing.
AI introduces additional information-security questions.
Training data may contain confidential information.
AI systems may depend on external providers.
Automated outputs can also be inaccurate or manipulated.
Banks therefore need governance addressing:
data → model → access → monitoring → human oversight → accountability.
AI should be incorporated into the existing risk-management structure rather than treated as a completely separate technological experiment.
23. Open Banking
Open banking further increases the importance of information-security governance.
In June 2025, the CBK issued a draft regulatory framework for open banking designed around supervisory, security, technical and operational standards for local banks and fintech companies.
Open banking can require controlled interaction between bank systems and authorised external providers.
This increases the importance of:
API security;
authentication;
customer consent;
third-party governance;
transaction monitoring.
Information security therefore becomes an important condition for financial innovation.
24. Enforcement
Information-security governance is not merely voluntary good practice.
Article 85 of Kuwait's banking legislation gives the CBK enforcement powers where regulated banks violate applicable legislation or CBK decisions and instructions.
Available measures include warnings, financial penalties and restrictions on banking activities, depending upon the circumstances.
A major cyber incident does not automatically establish regulatory wrongdoing.
The regulatory question is different:
Did the institution maintain and operate the governance, controls and resilience measures required of it?
25. Relevant Case Law
There is an important limitation regarding case law.
Kuwait does not have six readily identifiable published Court of Cassation judgments specifically interpreting the modern CBK CORF framework. CORF itself only became applicable in December 2025.
It would therefore be inaccurate to invent six Kuwaiti “CORF cases.”
The following established comparative authorities demonstrate principles directly relevant to banking information-security governance.
Case 1 – Various Claimants v WM Morrison Supermarkets plc [2020] UKSC 12
This case concerned an employee who deliberately disclosed a large quantity of personal information.
The UK Supreme Court considered whether the employer was vicariously liable for the employee's deliberate misconduct.
On the particular facts, the Court concluded that the employee was pursuing a personal vendetta rather than acting in the ordinary course of his employment.
Relevance to Kuwait
The case illustrates an important governance principle:
authorised access can itself create security risk.
Banks therefore require controls addressing insiders as well as external attackers.
26. Case 2 – Lloyd v Google LLC [2021] UKSC 50
This UK Supreme Court case concerned large-scale processing of personal information and the availability of damages through representative proceedings.
Although it was not a banking case, it demonstrates the potentially significant legal consequences of systematic information processing.
Relevance to Kuwaiti banks
Banks process enormous quantities of structured personal and financial information.
Information governance should therefore address not only cybersecurity attacks but also:
lawful access;
appropriate processing;
accountability;
data management.
27. Case 3 – Vidal-Hall v Google Inc [2015] EWCA Civ 311
This English Court of Appeal decision addressed misuse of private information and data-protection issues arising from digital tracking.
Its importance lies in recognising that information-related harm cannot always be analysed solely through conventional physical or property loss.
Banking relevance
Unauthorised disclosure of financial information can create significant harm even where money has not immediately disappeared from an account.
Banks therefore protect both:
financial assets and financial information.
28. Case 4 – Halliburton Energy Services Inc v Chubb Bermuda Insurance Ltd [2020] UKSC 48
This case did not concern cybersecurity itself but dealt with disclosure, conflicts and governance within a complex commercial context.
Its broader relevance lies in the importance of transparent governance mechanisms where responsibilities and conflicts can affect decision-making.
Information-security relevance
Cybersecurity governance similarly requires:
clearly allocated responsibilities;
independent oversight;
escalation mechanisms;
disclosure of material issues.
A governance structure becomes ineffective where significant security concerns cannot reach independent decision-makers.
29. Case 5 – Philipp v Barclays Bank UK PLC [2023] UKSC 25
This major banking case concerned payment instructions given by a customer who had been deceived by fraudsters.
The UK Supreme Court considered the bank's duties when executing a customer's valid instructions.
Information-security relevance
The case demonstrates the importance of distinguishing:
unauthorised access
from
authorised transactions induced by fraud.
Cybersecurity systems, fraud-monitoring systems and legal controls therefore need to distinguish different types of payment risk.
30. Case 6 – Singularis Holdings Ltd v Daiwa Capital Markets Europe Ltd [2019] UKSC 50
This case involved fraudulent payment instructions issued by an individual controlling a company.
The Supreme Court upheld liability against the financial institution on the particular facts.
The case illustrates the broader importance of financial institutions responding appropriately to sufficiently serious warning indicators.
Information-security relevance
Governance systems should ensure that unusual activity can be:
detected → escalated → reviewed → acted upon.
Detection technology alone is insufficient if organisational procedures prevent meaningful response.
31. Case 7 – Van Buren v United States, 593 U.S. 374 (2021)
This US Supreme Court case concerned a police officer who had authorised database access but used information for an improper purpose.
The Court interpreted the relevant federal computer-access statute relatively narrowly.
Governance relevance
The case demonstrates the distinction between:
technical ability to access information
and
organisational authority to use information for a particular purpose.
This distinction is highly relevant to banks.
An employee may technically be capable of opening a customer record while organisational policy prohibits access without a legitimate business reason.
32. Case 8 – United States v Nosal
The Nosal litigation also concerned employee access to computer systems and the boundaries of authorised use.
Although American computer-crime legislation does not govern Kuwaiti banks, the case provides a useful comparative lesson.
Information-security governance should clearly define:
permitted access;
prohibited access;
credential use;
access after employment;
confidential information.
Technical access controls should support these organisational rules.
33. Practical Example
Suppose a Kuwaiti bank migrates important customer-information systems to a cloud provider.
The board approves the digital-transformation strategy.
Six months later, the bank discovers that privileged administrator accounts are not adequately monitored.
Information-security governance requires more than simply correcting the software configuration.
The institution should consider:
Risk assessment
How serious is the weakness?
Exposure
Which systems and information were potentially accessible?
Investigation
Is there evidence that the weakness was exploited?
Containment
Should particular credentials or permissions be changed?
Governance
Why was the weakness not identified earlier?
Third-party management
Did the cloud provider satisfy contractual security requirements?
Regulatory considerations
Does the issue require regulatory escalation?
Recovery
Can critical systems remain safely operational?
Lessons learned
What changes are required to prevent recurrence?
This demonstrates the difference between technical security and security governance.
Technical security fixes the vulnerable account.
Governance determines why the weakness existed, who was responsible, what consequences resulted and how the institution prevents recurrence.
34. Information Security as Banking Governance
Information security should no longer be viewed as a narrow technology subject.
Modern banking converts traditional legal duties into digital controls.
For example:
Bank confidentiality → access control and encryption
Internal controls → identity management and segregation of duties
Audit → logging and monitoring
Operational continuity → cyber resilience
Third-party oversight → technology-provider governance
Board responsibility → cyber-risk oversight
This is why information-security governance now forms an important component of banking law.
35. Main Principles for Kuwaiti Banks
An effective information-security governance framework should therefore address at least the following:
board oversight;
senior-management accountability;
cybersecurity strategy;
risk assessment;
independent security functions;
identity and access management;
segregation of duties;
data confidentiality;
third-party risk;
incident management;
business continuity;
operational resilience;
internal audit;
staff training;
regulatory reporting.
These controls operate together.
Strong cybersecurity technology without effective governance can still leave a bank exposed.
Conclusion
Banking Law and Information Security Governance in Kuwait has evolved from conventional banking confidentiality and internal-control requirements into a sophisticated framework for cybersecurity and operational resilience.
The Central Bank of Kuwait possesses extensive supervisory and inspection powers under Kuwait's banking legislation. Article 78 allows it to inspect regulated institutions and require correction of unsound positions.
The 2020 Cybersecurity Framework established a coordinated approach built around governance, risk management, compliance, cybersecurity baselines, maturity assessment, crisis management, threat intelligence and training.
The framework evolved significantly on 3 December 2025, when the CBK introduced CORF—the Cyber and Operational Resilience Framework for local banks and financial institutions. CORF moves Kuwait from a predominantly compliance-oriented cybersecurity approach toward a resilience-first and maturity-oriented model requiring institutions to develop the capacity to anticipate, withstand, recover from and adapt to disruption.
There are not yet six reported Kuwaiti cases specifically interpreting CORF, so such cases should not be invented. Comparative authorities such as WM Morrison Supermarkets, Lloyd v Google, Vidal-Hall, Philipp v Barclays, Singularis v Daiwa, Van Buren and Nosal instead demonstrate important principles concerning insider access, data governance, payment fraud, escalation of suspicious activity and authorised system use.
The central principle is that information security in banking is a governance responsibility, not merely an IT function. Kuwaiti banks therefore need technical controls supported by board oversight, management accountability, risk management, confidentiality, independent assurance, third-party supervision, incident response and operational resilience.

comments