Don’t do SECURITY. Do business SECURELY.

Bank of Israel issues Cyber Defence Directive 361

The Bank of Israel issues Directive 361, requiring banks to appoint a cyber defence manager and adopt a board-approved strategy.

The Bank of Israel’s Banking Supervision Department issues Proper Conduct of Banking Business Directive 361 on Cyber Defense Management.

Key points

  • A board-approved cyber defence strategy.
  • A cyber defence manager.
  • Risk assessment and supply chain controls.
  • Monitoring, incident reporting and regular testing.

UK technology providers serving Israeli banks and credit card companies should expect Directive 361 requirements in contracts. The directive was one of the earliest board-level cyber regulations for banks and set a model later followed by other regulators. Suppliers may be asked to demonstrate supply chain security, testing and incident reporting capabilities.

Source: Proper Conduct of Banking Business Directive 361 – Cyber Defense Management (Bank of Israel)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights