Cybersecurity In The Tunisian Banking Sector Comprehensive assessment of cyber risk management, governance, resilience and digital transformation
Abstract
The digital transformation of the Tunisian banking sector has profoundly altered the ways in which financial services are accessed, transactions are processed and data is managed. This development simultaneously increases the attack surface of banking institutions and the importance of cybersecurity for financial stability, customer protection and business continuity. This article builds on the framework of the original study, which initially focused on a single bank, but extends it to a sector-wide approach covering all Tunisian banks. The study proposes an assessment framework structured around eight key areas: cyber governance and strategy, data protection and compliance, risk management, systems and identity security, incident management, resilience and business continuity, the human factor, and supplier security. The analysis is contextualised against the NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, international principles of operational resilience and the Tunisian regulatory framework, notably Decree-Law No. 2023-17 on cybersecurity. The results presented are a sector-based and documentary synthesis: they do not constitute a technical audit of the banks and should not be interpreted as official scores for individual banks. They highlight an overall maturity level ranging from intermediate to good, with likely variations between institutions and across different areas. Common priorities include, in particular, third-party risk governance, resilience to ransomware, the automation of identity management, the financial quantification of cyber risk, data protection by design, and the development of sector-wide threat intelligence capabilities.