Banking Law And Cooperative Cybersecurity Frameworks Kuwait .

BANKING LAW AND COOPERATIVE CYBERSECURITY FRAMEWORKS IN KUWAIT

1. Introduction

Cooperative cybersecurity frameworks in Kuwait's banking sector refer to regulatory arrangements under which banks, financial institutions, regulators and other relevant stakeholders coordinate, exchange information and collectively strengthen cyber resilience. Modern banking systems are highly interconnected. A cyber incident affecting one bank, payment provider or technology supplier may consequently create operational risks for several financial institutions.

The principal banking regulator is the Central Bank of Kuwait (CBK). In 2020, the CBK introduced its Cybersecurity Framework for the Kuwaiti banking sector. It expressly sought to improve preparedness, cooperation, information sharing, standardisation and cybersecurity maturity across regulated institutions.

The framework has since evolved substantially. In December 2025, the CBK launched its Cyber and Operational Resilience Framework (CORF) for local banks and financial institutions. CORF moves the regulatory approach from basic cybersecurity compliance toward a resilience-first and maturity-oriented system under which regulated institutions should be capable of anticipating, withstanding, recovering from and adapting to disruptions.

2. Legal and Regulatory Framework

A. Central Bank of Kuwait Law

The foundation of banking supervision remains Law No. 32 of 1968 concerning Currency, the Central Bank of Kuwait and the Organisation of Banking Business, as subsequently amended.

The legislation gives the CBK extensive supervisory authority over banks. Article 82, for example, permits the CBK to require banks to provide information, statements and statistical data necessary for its functions. Banks are required to provide information requested under the regulatory system established by the CBK.

Importantly for cooperative supervision, Article 82 also recognises exchanges of information between the CBK and other central banks or banking supervisory authorities for consolidated banking supervision, subject to agreed arrangements.

This demonstrates that information cooperation is already embedded within Kuwait's banking-supervision structure.

B. CBK Cybersecurity Framework 2020

The 2020 framework represented a major development in sector-wide cyber regulation.

The CBK described six integrated initiatives. They included an Information Security Working Group, principles for managing cyber risks, baseline security requirements, cyber-risk assessments and mechanisms supporting coordination.

The Information Security Working Group was particularly relevant to cooperative cybersecurity because it brought the CBK and Kuwaiti banks into a coordinated structure. Confidentiality, privacy and conflicts of interest were expressly recognised as important considerations.

The framework also addressed governance, compliance, crisis management, response and recovery, collaboration and information sharing.

Thus, cybersecurity was treated not merely as the private technical responsibility of each individual bank but as a sector-wide resilience problem.

3. Cyber and Operational Resilience Framework 2025

The CBK's CORF represents the newer stage of Kuwait's approach.

The framework applies to local banks and financial institutions and was introduced as an evolution of the 2020 Cybersecurity Framework. The CBK states that regulated entities need capabilities extending beyond protection of infrastructure to effective incident and crisis response and rapid restoration of business operations.

The legal significance is important. Cybersecurity regulation increasingly asks:

Can the bank continue delivering critical financial services when preventive controls fail?

Consequently, operational resilience, incident management, recovery capabilities, governance and coordination become part of banking supervision rather than purely technical IT matters.

4. Key Principles of Cooperative Cybersecurity

Information Sharing

Banks can benefit from sharing relevant threat intelligence concerning emerging attack patterns, vulnerabilities and significant incidents through authorised channels.

Such cooperation may help institutions recognise sector-wide threats earlier. However, information sharing must operate consistently with confidentiality and data-protection requirements.

Common Security Standards

Cooperation is ineffective if every institution operates according to completely different security standards.

The 2020 CBK framework therefore established baseline information-security controls applicable to regulated institutions, including governance, risk management, infrastructure and operational security, third-party risks and electronic payment systems.

Incident Response and Recovery

Cyber resilience requires preparation for incidents that cannot be completely prevented.

Banks therefore need effective mechanisms for identifying, containing and responding to incidents and restoring important banking services.

The transition to CORF strengthens this approach by concentrating on the ability to anticipate, withstand, recover and adapt.

Third-Party Cooperation

Modern banks depend upon cloud providers, payment processors, telecommunications infrastructure, software suppliers and other technology providers.

Cybersecurity regulation therefore extends beyond the bank's internal network. CBK itself has recognised growing dependence on third parties for infrastructure, technology management and operational support as an important cybersecurity driver.

Payment-System Security

Cybersecurity cooperation is particularly significant for payment infrastructure because interconnected payment systems can transmit operational problems across institutions.

Kuwait has progressively modernised its payment infrastructure. CBK states that its payment initiatives incorporate cybersecurity, business continuity, governance, risk-management and customer-protection requirements.

5. Confidentiality and Data Protection

Cybersecurity information sharing cannot mean unrestricted disclosure of banking information.

Article 85 bis of the CBK banking legislation prohibits bank directors, managers, employees and workers from improperly disclosing information concerning the affairs of the bank, its customers or other banks obtained through their positions, subject to legally permitted situations.

Therefore, cooperative cybersecurity requires a balance between two objectives:

sharing enough information to protect the financial system while maintaining banking secrecy, confidentiality and customer privacy.

Information-sharing arrangements should consequently establish clear purposes, authorised recipients and appropriate confidentiality safeguards.

6. Governance and Board Responsibility

Cybersecurity is no longer merely an IT department issue. It is increasingly a matter of bank governance and regulatory accountability.

Senior management and boards should ensure that cybersecurity risk forms part of enterprise risk management. Appropriate governance structures should identify responsibilities, oversee risk assessments and ensure adequate resources for resilience.

The CBK's approach reflects this governance model. Its cybersecurity framework expressly addresses governance, risk management and compliance alongside technical controls.

Accordingly, outsourcing technical functions does not automatically eliminate the regulated institution's responsibility for managing associated risks.

7. Case Laws and Comparative Judicial Principles

Published Kuwaiti judgments specifically interpreting the CBK's cooperative cybersecurity framework are limited. It would therefore be misleading to invent Kuwait-specific cybersecurity precedents. The following established comparative cases provide useful judicial principles relevant to cyber-risk governance.

1. Lloyd v Google LLC [2021] UKSC 50

The UK Supreme Court considered claims concerning unlawful processing of personal data.

Principle: Cybersecurity and banking information-sharing arrangements must distinguish legitimate security cooperation from unlawful or inadequately justified processing of personal information.

2. Various Claimants v WM Morrison Supermarkets plc [2020] UKSC 12

This case concerned deliberate disclosure of employee data by a rogue employee.

Principle: Organisations require strong internal controls, although liability for an employee's independent wrongful conduct depends upon established legal principles rather than arising automatically.

For Kuwaiti banks, the case illustrates the importance of insider-risk management.

3. Dittman v UPMC, 196 A.3d 1036 (Pa. 2018)

The Pennsylvania Supreme Court recognised that an employer collecting and storing employees' sensitive information could owe a duty to exercise reasonable care in protecting that information.

Principle: Institutions controlling sensitive electronic information may face legal responsibility where reasonable security measures are neglected.

4. FTC v Wyndham Worldwide Corp., 799 F.3d 236 (3d Cir. 2015)

The litigation followed significant cybersecurity breaches.

Principle: Inadequate cybersecurity practices may become a regulatory and consumer-protection issue rather than remaining merely an internal technical failure.

5. Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems (C-311/18), CJEU, 2020

The CJEU examined international transfers and protection of personal information.

Principle: Cross-border information cooperation must maintain legally adequate safeguards for protected data.

This principle is relevant where financial-sector cybersecurity cooperation involves international service providers or foreign supervisory authorities.

6. Wirtschaftsakademie Schleswig-Holstein (C-210/16), CJEU, 2018

The CJEU addressed responsibility where multiple actors participated in processing personal information.

Principle: Digital ecosystems can involve shared or interconnected responsibilities. Financial institutions should therefore clearly allocate cybersecurity and data-governance responsibilities when cooperating with technology providers and other entities.

8. Enforcement and Regulatory Consequences

Cybersecurity obligations can ultimately be supported through ordinary banking supervisory powers.

Article 85 of Kuwait's banking legislation provides for regulatory consequences where a bank violates the banking law or decisions and instructions issued under it. Available measures include warnings and financial penalties, subject to the applicable statutory conditions.

This means cybersecurity requirements issued through CBK's regulatory authority should not be regarded simply as voluntary technical recommendations where they constitute binding regulatory instructions.

The newer CORF reinforces the direction of supervision: banks are expected not only to demonstrate individual security controls but also broader cyber and operational resilience.

9. Conclusion

Cooperative cybersecurity in Kuwait represents the transition from individual bank security to collective financial-sector resilience. The CBK's 2020 Cybersecurity Framework established important foundations through common controls, governance requirements, information sharing, risk assessments, cooperation and an Information Security Working Group. The 2025 CORF takes the system further by adopting a resilience-first approach covering the capacity to anticipate, withstand, recover from and adapt to cyber and operational disruption.

Kuwait's broader banking legislation supports this structure through CBK supervisory powers, information requirements, confidentiality duties and regulatory enforcement. At the same time, cooperation must respect banking secrecy and customer-data protection.

Although extensive reported Kuwaiti case law specifically interpreting these cybersecurity frameworks is not presently available, comparative decisions such as Lloyd v Google, Morrison, Dittman, FTC v Wyndham, Schrems II and Wirtschaftsakademie demonstrate important principles concerning data security, organisational responsibility, regulatory accountability and controlled information sharing.

Therefore, the central principle of Kuwaiti cooperative cybersecurity regulation is clear: cyber resilience is a shared banking-system responsibility, but cooperation must remain governed, confidential, risk-based and subject to effective regulatory oversight.

LEAVE A COMMENT