The Agency for Regulation and Development of the Financial Market (ARDFM) will conduct full-scale supervisory cyber drills for Kazakhstan’s banks in 2027. The regulator will test players controlling about 90% of the sector’s assets, Kursiv Media reports, citing the agency’s First Deputy Chairman Timur Abilkassymov.
The regulator’s plans were announced at the KazHackStan 2026 cybersecurity conference in Astana. Previously, the agency limited itself to pilot checks. These helped assess financial institutions’ ability to repel attacks and their system recovery speeds after incidents.
Two stages of assessment
With fraudsters increasingly using artificial intelligence, the regulator is changing its approach to supervision. Now, the assessment of banks’ cyber resilience will consist of two mandatory blocks.
The first focuses on corporate governance. The ARDFM will check whether a bank has enough resources to protect its infrastructure, how its information security teams are staffed, and how effectively its internal processes are built.
The second block includes the full-scale drills themselves, which will show the real picture of the defenses.
For Kazakhstan’s financial market, this means stricter requirements for IT infrastructure. The ARDFM is actively revising the rules of the game across multiple segments: Finteqstan previously reported that the regulator is preparing the first update to the capital market law in 23 years. Introducing systemic cyber drills continues this trend.
The regulator is shifting cybersecurity assessment from spot tests to a systemic process, checking not only technical barriers but also the quality of IT resource management.