Cyberattacks on government bodies, mandatory personal data localisation and State Security Service certification of security officers for critical infrastructure make information security the main priority of the Uzbek market.
January 2026 cyberattacks on government agencies — 60,000 records leaked
On 27–30 January 2026 three government agencies were hit by cyberattacks. 60,000 records were confirmed: 24 photographs of interior ministry staff, 15,874 records of the National Social Protection Agency, 446 mortgage records. The national cyber hub blocked 7 million threats in 2024, 107 million in 2025, with a 2026 forecast of over 200 million.
Gazeta.uz · Minister of Digital Technologies
PP-167: certification of security officers for critical infrastructure facilities
Presidential Resolution No. PP-167 of 31 May 2023. Staff responsible for cybersecurity at critical information infrastructure facilities must be certified by the State Security Service every 3 years. It covers banks, telecoms, energy, transport and healthcare — this is a requirement of law, not a recommendation.
Lex.uz · PP-167
Law ZRU-547: mandatory personal data localisation inside Uzbekistan
Article 27.1 of the personal data law requires physical storage and processing of Uzbek citizens' personal data on servers inside the country. Databases are registered with the authorised body. Non-compliance is grounds for blocking websites and services.
Lex.uz · Law No. ZRU-547
CISO of a state bank ahead of privatisation
A bank with 75–100% state ownership, in the top 10 by assets, preparing for pre-sale due diligence. International advisers from EY, KPMG and IFC are asking questions about information security maturity.
Out of 700+ IT staff, only 2 people hold international information security certifications (CISA/CISSP). There is practically no local market for third-line monitoring centre specialists in the country.
"I need a partner with State Security Service clearance, ISO 27001 on the production perimeter, experience with article 27.1 and engineers who will not leave for Dubai in six months. I have 14 months until privatisation — I cannot afford another leak."
CIO of a large state enterprise
A critical information infrastructure facility under PP-167. Energy, mining, railways. 20,000+ employees, regional branches across the republic.
Industrial control systems and office networks are still connected — a legacy of the 2010s. Foreign-currency contracts with Western manufacturers go through the finance ministry with a delay of 2–3 months.
"I have to pass State Security Service certification, move 12 contractor services to my.gov.uz and not bring down the control systems at the power plants — all at once. We do not have that many competencies in-house, and will not have them within three years."
CTO of a private commercial bank
A mid-sized bank with a digital retail focus; the mobile app is the main channel. Subject to article 27.1 (personal data localisation) and Central Bank operational resilience requirements.
Every new service needs an architectural decision: how to keep personal data inside Uzbekistan while still letting a vendor work with anonymised data. The attacks of early 2026 pushed the board to raise the information security budget.
"After the attacks on government bodies our board no longer asks how much a monitoring centre costs — it asks why ours is not running around the clock yet. I need a partner who designs for data localisation from day one instead of bolting it on after the audit."