Green LightGreen Light
All news
New Cybersecurity Rules for Uzbekistan’s Financial Sector: Key Changes for Banks
UzbekistanNewsCybersecurityFinancial SectorCentral Bank

New Cybersecurity Rules for Uzbekistan’s Financial Sector: Key Changes for Banks

An overview of major regulatory updates

On August 6, the Central Bank of Uzbekistan implemented Decree No. 3492-1 (May 2, 2026), establishing strict cybersecurity requirements for commercial banks and introducing financial liability for non-compliance. The mandated standards focus on five key technological domains:

1. MANDATORY SIEM IMPLEMENTATION AND CERT-CBU INTEGRATION

In accordance with paragraphs 11.34 and 11.47, banks must deploy a Security Information and Event Management (SIEM) system. This system collects, analyzes, and monitors security events 24/7.

Institutions must also ensure direct integration with CERT-CBU, the Central Bank's security monitoring center. This creates real-time visibility into threats across the banking sector.

2. SECURING ONLINE BANKING, WEB RESOURCES, AND APIS

Paragraphs 11.60 and 11.75 require protection of all internet-facing systems: remote banking platforms, mobile applications, and web services. Banks must deploy:

- Web Application Firewalls (WAF) to block attacks.

- Anti-DDoS solutions to prevent traffic floods.

These technologies shield customer-facing infrastructure from sophisticated cyber threats.

3. NETWORK SEGMENTATION, DATA CENTER SECURITY, AND NGFW WITH MFA

Internal networks now require strict security controls:

- Next-Generation Firewalls (NGFW) at network perimeters and data center entry points (minimum Category 2 under O'z DSt 2815:2014 standard).

- Network segmentation to isolate critical systems.

- Multi-Factor Authentication (MFA) + VPN for all remote employee access (paragraphs 11.10, 11.48, 11.65).

This layered approach prevents unauthorized access even if perimeter defenses are compromised.

4. ADVANCED ENDPOINT THREAT PROTECTION

Banks must now deploy Endpoint Detection and Response (EDR) technology to protect:

- Workstations and servers.

- Critical hardware (ATMs, POS terminals).

Paragraphs 11.63 and 11.15 also mandate centralized antivirus protection with daily database updates across all endpoints.

5. REGULAR PENETRATION TESTING AND VULNERABILITY MANAGEMENT

Mandated by paragraphs 11.39 and 11.46, banks must conduct:

- Vulnerability assessments at least twice yearly.

- Penetration testing (unauthorized access checks) on systems, applications, and infrastructure.

- Compliance audits to verify adherence to cybersecurity requirements.

REGULATORY CONTEXT: A SHIFT TOWARD MATURE SECURITY

The Central Bank's new mandates represent a deliberate evolution in Uzbekistan's financial sector security posture. Rather than focusing solely on perimeter defense, regulators now demand a holistic security culture.

This includes:

- ISO 27001 and PCI DSS compliance for data centers.

- Privileged Access Management (PAM) for administrative controls.

- Application source code analysis.

- Continuous vulnerability auditing.

Banks that implement these measures will modernize their IT infrastructure, strengthen customer digital trust, and build resilient cybersecurity architecture.

IMPLEMENTATION CHALLENGES

The primary challenge facing banks is building a layered, transparent, and manageable security architecture within existing infrastructure. Many institutions struggle with:

- Configuring network microsegmentation correctly.

- Integrating disparate security tools into a unified SIEM system.

- Securing web applications and APIs without disrupting customer experience.

- Maintaining continuous vulnerability scanning at scale.

HOW FINANCIAL INSTITUTIONS ARE APPROACHING COMPLIANCE

Banks seeking expert implementation support typically engage technology partners to help with:

- Solution selection and procurement.

- Infrastructure design and deployment.

- Staff training and knowledge transfer.

- Ongoing maintenance and optimization.

Green Light specializes in helping financial institutions navigate these requirements. Our approach:

We configure and deploy cutting-edge cybersecurity solutions (SIEM, WAF, EDR, NGFW, MFA) tailored to your infrastructure.

We handle installation and initial management, then transfer full control to your internal security team.

We ensure strict compliance with Central Bank regulations and InfoSec governance frameworks.

We act as a technology partner—not a replacement for your internal team.

NEXT STEPS

If your financial institution is working toward full compliance with the Central Bank of Uzbekistan's new standards, Green Light's experts can help you:

1. Assess your current security posture against decree requirements.

2. Develop a phased implementation roadmap.

3. Select the optimal suite of technologies for your infrastructure.

4. Deploy and configure solutions with minimal operational disruption.

5. Train your internal team for long-term ownership.

Submit a request to schedule a consultation with our team.