BoG releases draft cybersecurity directive for banks, seeks public input

By Praisebell Rosemond Larbi
The Bank of Ghana (BoG) has released an exposure draft of a new Cyber and Information Security Directive, inviting comments from the banking industry and the public.
The move is part of efforts to strengthen the country’s financial sector against rising cyber risks.
In a notice issued in Accra, the central bank said the draft directive, published in line with the Procedures for the Issuance of Directives, 2020, is available on its website (www.bog.gov.gh).
BoG pledged to review all submissions and provide written explanations on how material comments are incorporated into the final version.
Objective of the Directive
The proposed framework aims to create a secure digital environment for Ghana’s financial services industry. Specifically, it seeks to: Foster trust and confidence in ICT systems; Safeguard the integrity of electronic transactions; Provide an assurance framework for robust security policies and Promote adherence to global cyber and information security standards through regular assessments.
BoG emphasised that the directive will help financial institutions mitigate cyber threats, enhance resilience, and protect consumers in an increasingly digitised banking landscape.
Governance Structure
The draft outlines clear governance responsibilities for regulated financial institutions (RFIs): Boards of RFIs must define the institution’s cyber and information security strategy, approve policies on cybersecurity, outsourcing, survivability, backup and disaster recovery, and oversee risk management.
Senior Management is tasked with implementing and maintaining the cyber risk framework, formulating institutional policies, and ensuring ongoing compliance
Policy documents presented to the Board must cover the cyber threat environment, potential impacts on the institution, risk management approaches, and key principles for safeguarding information systems.
Rising Cybersecurity Risks
BoG noted that Ghana’s financial sector relies heavily on digital infrastructure to process transactions and transfer funds, making it an attractive target for cybercriminals.
High-profile attacks in recent years have underscored the need for stronger preventive measures.
“Financial institutions face the challenge of balancing robust security with efficient, reliable operations for customers,” the Bank observed.
It added that the directive will help RFIs meet that challenge by embedding international best practices in their operations.



