
New Cybersecurity Rules for Uzbekistan’s Financial Sector: Key Changes for Banks
An overview of major regulatory updates
On August 6, the Central Bank of Uzbekistan implemented Decree No. 3492-1 (May 2, 2026), establishing strict cybersecurity requirements for commercial banks and introducing financial liability for non-compliance. The mandated standards focus on five key technological domains:
1. MANDATORY SIEM IMPLEMENTATION AND CERT-CBU INTEGRATION
In accordance with paragraphs 11.34 and 11.47, banks must deploy a Security Information and Event Management (SIEM) system. This system collects, analyzes, and monitors security events 24/7.
Institutions must also ensure direct integration with CERT-CBU, the Central Bank's security monitoring center. This creates real-time visibility into threats across the banking sector.
2. SECURING ONLINE BANKING, WEB RESOURCES, AND APIS
Paragraphs 11.60 and 11.75 require protection of all internet-facing systems: remote banking platforms, mobile applications, and web services. Banks must deploy:
- Web Application Firewalls (WAF) to block attacks.
- Anti-DDoS solutions to prevent traffic floods.
These technologies shield customer-facing infrastructure from sophisticated cyber threats.
3. NETWORK SEGMENTATION, DATA CENTER SECURITY, AND NGFW WITH MFA
Internal networks now require strict security controls:
- Next-Generation Firewalls (NGFW) at network perimeters and data center entry points (minimum Category 2 under O'z DSt 2815:2014 standard).
- Network segmentation to isolate critical systems.
- Multi-Factor Authentication (MFA) + VPN for all remote employee access (paragraphs 11.10, 11.48, 11.65).
This layered approach prevents unauthorized access even if perimeter defenses are compromised.
4. ADVANCED ENDPOINT THREAT PROTECTION
Banks must now deploy Endpoint Detection and Response (EDR) technology to protect:
- Workstations and servers.
- Critical hardware (ATMs, POS terminals).
Paragraphs 11.63 and 11.15 also mandate centralized antivirus protection with daily database updates across all endpoints.
5. REGULAR PENETRATION TESTING AND VULNERABILITY MANAGEMENT
Mandated by paragraphs 11.39 and 11.46, banks must conduct:
- Vulnerability assessments at least twice yearly.
- Penetration testing (unauthorized access checks) on systems, applications, and infrastructure.
- Compliance audits to verify adherence to cybersecurity requirements.
REGULATORY CONTEXT: A SHIFT TOWARD MATURE SECURITY
The Central Bank's new mandates represent a deliberate evolution in Uzbekistan's financial sector security posture. Rather than focusing solely on perimeter defense, regulators now demand a holistic security culture.
This includes:
- ISO 27001 and PCI DSS compliance for data centers.
- Privileged Access Management (PAM) for administrative controls.
- Application source code analysis.
- Continuous vulnerability auditing.
Banks that implement these measures will modernize their IT infrastructure, strengthen customer digital trust, and build resilient cybersecurity architecture.
IMPLEMENTATION CHALLENGES
The primary challenge facing banks is building a layered, transparent, and manageable security architecture within existing infrastructure. Many institutions struggle with:
- Configuring network microsegmentation correctly.
- Integrating disparate security tools into a unified SIEM system.
- Securing web applications and APIs without disrupting customer experience.
- Maintaining continuous vulnerability scanning at scale.
HOW FINANCIAL INSTITUTIONS ARE APPROACHING COMPLIANCE
Banks seeking expert implementation support typically engage technology partners to help with:
- Solution selection and procurement.
- Infrastructure design and deployment.
- Staff training and knowledge transfer.
- Ongoing maintenance and optimization.
Green Light specializes in helping financial institutions navigate these requirements. Our approach:
• We configure and deploy cutting-edge cybersecurity solutions (SIEM, WAF, EDR, NGFW, MFA) tailored to your infrastructure.
• We handle installation and initial management, then transfer full control to your internal security team.
• We ensure strict compliance with Central Bank regulations and InfoSec governance frameworks.
• We act as a technology partner—not a replacement for your internal team.
NEXT STEPS
If your financial institution is working toward full compliance with the Central Bank of Uzbekistan's new standards, Green Light's experts can help you:
1. Assess your current security posture against decree requirements.
2. Develop a phased implementation roadmap.
3. Select the optimal suite of technologies for your infrastructure.
4. Deploy and configure solutions with minimal operational disruption.
5. Train your internal team for long-term ownership.
Submit a request to schedule a consultation with our team.