Through keynote speeches, expert-led discussions, and collaborative breakout sessions, participants will explore the dual role of AI as both a threat and a defensive tool, strategies to prepare for quantum-era risks, and methods to translate technical risks into financial terms using CRQ. The seminar will also address governance, accountability, and resilience planning, equipping attendees with actionable insights to strengthen their cybersecurity frameworks.
This seminar is a vital opportunity for central bank community to come together, exchange knowledge, and build a stronger, more secure global financial system. As cyber risks grow in complexity and scale, the insights and collaborations fostered at this event will play a crucial role in shaping the future of cybersecurity and resilience.
About the conference
The BIS Cyber Resilience Coordination Centre is pleased to host the 7th BIS Annual Cyber Security Seminar, a key event that will bring together practitioners and cybersecurity experts to address critical cybersecurity challenges impacting the global financial system. This in-person seminar will take place on 21–22 April 2026 at the Bank for International Settlements (BIS) in Basel, Switzerland.
The seminar will focus on three critical themes: Artificial Intelligence (AI) and Cybersecurity, Post-Quantum Cryptography (PQC), and Cyber Risk Quantification (CRQ). These topics are increasingly important as central banks confront an evolving cyber threat landscape driven by technological advancements and emerging risks. The event will serve as a platform for participants to share research, discuss best practices, and collaborate on strategies to enhance cyber resilience and systemic stability.
Agenda
Day 1 - 21 April
| Welcome and opening remarks |
|---|
| Andréa M Maechler, Deputy General Manager, Bank for International Settlements |
| Keynote |
|---|
AI and Post-Quantum Cryptography – Redefining Trust and Resilience in the Financial System A forward-looking discussion on how AI and post-quantum cryptography (PQC) are transforming trust and resilience in the financial system. Gain insights into leveraging AI for analytical capabilities while preparing for quantum-era challenges. Speaker Steve Monaghan, Executive Chairman, Human AI |
| Session 1 |
|---|
AI and Cybersecurity - Defending, Governing, and Operationalising AI with Confidence This session equips central bank CISOs with a concise, risk-based view of artificial intelligence (AI) and its implications for cyber resilience. It addresses how AI amplifies existing threats and introduces fragile but high-impact dependencies. The focus is on practical controls, accountability, and measurable outcomes aligned with mandates for resilience, trust, and systemic stability. Attendees will also explore defensive AI use cases and the future of AI-driven identity management. Speakers
|
| Session 2 |
|---|
Post-Quantum Cryptography (PQC): From Silent Breakthroughs to Actionable Readiness Quantum risk is a current resilience priority, not a distant migration exercise. This session reframes PQC for central banks in practical, decision-focused terms: why quantum capability may advance without public signals, how long data-confidentiality lifetimes elevate near-term risk, and why "Harvest-Now-Decrypt-Later" (HNDL) is the most credible early threat. It translates PQC into concrete actions-crypto-asset discovery, data-secrecy horizon mapping, and crypto agility-while addressing systemic challenges across payment, settlement, and supervisory infrastructures. The session also highlights how to detect quantum-motivated activity with existing telemetry and convert detection insights into migration and investment priorities. Speakers
|
Day 2 - 22 April
| Welcome and Reflections |
|---|
Recap of Day 1 and CRCC 2026 priorities Speaker Randy Miskanic, Head of CRCC |
| Session 3 |
|---|
Cyber Risk Quantification (CRQ): Linking Decisions, Budgets, and Resilience This session introduces Cyber Risk Quantification (CRQ) as a practical decision-making tool that structures uncertainty and translates technical exposure into financial and operational terms that leaders can act upon. It positions the Chief Information Security Officer (CISO) to own the questions, controls, and decisions – in partnership with quantitative experts – ensuring that risk appetite and resilience remain central. CRQ enhances prioritisation and budgeting by comparing options based on expected loss reduction and return on security investment, enabling multi-year, risk-aligned roadmaps and clear trade-offs. The session extends CRQ to supervision and stress testing, employing institutional models to design sector-wide scenarios while balancing comparability with flexibility. Practical guidance focuses on thin-slice pilots for critical services, leveraging existing operational risk, incident, and business continuity management (BCM) data, and establishing an operating model (governance, refresh cadence, roles across cyber–risk–finance, tooling, and skills). A closing panel sets out proposed actions: enabling CRQ-backed decisions, supporting sector stress testing, and building internal capabilities to sustain and scale the program. Speakers
|
| Session 4 |
|---|
Project Raven : Financial sector cyber resilience Speakers
|
| Session 5 |
|---|
Rotating Breakout Sessions Collaborative Action & Strategic Planning These breakout sessions convert seminar insights on CRQ, AI, and PQC into institution-ready actions. Working with specialists and facilitators, teams will produce concise action plans with clear objectives, dependencies, milestones, and success measures. ready actions. Working with specialists and facilitators, teams will produce concise action plans with clear objectives, dependencies, milestones, and success measures. ready actions. Working with specialists and facilitators, teams will produce concise action plans with clear objectives, dependencies, milestones, and success measures. Groups will briefly report their plans, and a closing discussion will consolidate institutional and sectorlevel next steps and BISenabled collective action (shared scenarios, common metrics, joint training, data/methods collaboration). Expected outcomes: AI/cyber-clear ownership, prioritized defences, safe pilots; PQC-nearterm crypto agility, HNDL earlywarning, coordinated migration; CRQ-quantified, defensible decisions aligned to risk appetite and budgets, supporting sectorwide stress testing and supervisory dialogue. Facilitators: Group Leads |
| Commitments |
|---|
| Randy Miskanic, Head of CRCC, BIS |
| Closing remarks |
|---|
| Veronique Sani, Secretary General, BIS |
Speakers
Javier Fernández-Sanguino leads the cybersecurity practice at Banco de España, where he has served as Head of the Cybersecurity Unit for the past four years. He brings 25 years of experience in cybersecurity engineering, audit and operations, including a decade in IT consulting and 15 years in the central banking sector at both at Banco de España and the European Central Bank. He has led multiple Eurosystem-level task forces, among them an initiative focused on the transition to Post Quantum Cryptography. Javier holds a master’s degree in Telecommunications.
Jaime Gómez García is a leading figure in quantum security, recognized for advancing quantum safe cryptography and industry collaboration. As the Chair of the Europol Quantum Safe Financial Forum, he works to ensure a seamless transition to quantum-safe technologies. Jaime has received multiple accolades, including the Quantum Security 25: The Top 25 Most Influential People in Quantum Security, and the Keyfactor Quantum Leap Award.
James Hanbury leads KPMG's cyber risk quantification business and co-founded Cyber Risk Insights. He specializes in helping organizations integrate quantified risk into decision-making and regulatory frameworks. James is also a co-founder of the Enterprise Risk Quantification Institute (ERQI).
Arnaud Lacour leads AI adoption and innovation at Ping Identity, focusing on data privacy and identity management. With a Master's in Computer Science from CY Tech Paris and additional education from MIT, Arnaud brings expertise in containerization and disruptive technologies.
Dr Peter Levin is a prominent cybersecurity and AI leader, best known for advancing the resilience of critical infrastructure sectors. He led the development of AI-readiness models for public-sector agencies and contributes to policy and technology initiatives that shape advanced cyber surveillance and detection. With a strong commitment to fairness, integrity, and security, Dr. Levin is a mentor and advocate for protecting systems and communities.
Steve Monaghan is the Executive Chairman of Human AI Pte Ltd and serves on the Boards of Rakbank, Pulse Global, and other ventures. With a career spanning commercial aviation, banking, and technology, Steve has introduced innovative business models across Asia and filed 6 patents in FinTech. He has held leadership roles at Dell, Citigroup, DBS Bank, AIA, and more, driving transformations in mobile payments, AI, and digital banking. Steve holds an EMBA from the Helsinki School of Economics and has attended senior leadership programs at IMD and Wharton.
Matthias Pouyanne co-founded Rule 3, specializing in translating cyber risk into financial terms for board-level decisions. He contributes to EU policy on operational resilience and focuses on systemic risk and supply chain resilience.
Vasily Pozdyshev joined BIS in 2020, bringing decades of expertise in banking regulation and supervision. As a former Deputy Governor of the Central Bank of Russia, he contributed to global financial stability and served on the Basel Committee on Banking Supervision. He is currently leading Cyber Tech at the BIS Innovation Hub.
Olivier Schraner is a Chief Security Advisor at Microsoft, with a background spanning CISO, CTO, and enterprise architecture roles. He combines deep technical expertise in cloud, cybersecurity, and infrastructure with a strong focus on building resilient, compliant, and well‑governed digital environments. Passionate about collaboration and innovation, he works closely with organizations to strengthen cyber resilience and align security strategy with business outcomes.
Tryfonas Theophilou serves as a senior technical advisor at the Bank of England, focusing on cyber risk and operational resilience. With a background in consulting, industry, and fintech, he has extensive experience in managing cyber risks and delivering resilience capabilities in the financial sector.
David White is a pioneer in cyber risk quantification, helping organizations understand risks in financial terms. As Co-founder of Axio, he collaborates with regulators and critical infrastructure sectors to enhance resilience. David also serves as co-founder and co-chair of the Enterprise Risk Quantification Institute (ERQI).
Marcelo Yannuzzi leads Cisco Innovation’s work in zero-trust technologies and AI security, focusing on access control and enterprise data protection. With a Ph.D. in Computer Science, more than 90 patent applications, and extensive experience in security and networking, he has also held academic and corporate strategy roles.