What do the Bank of Zambia's cyber risk guidelines require?
The Bank of Zambia Cyber and Information Risk Management Guidelines, 2023 set minimum cyber-risk requirements for regulated entities. They expect board-approved policies, an independent chief information security officer, a security operations centre or equivalent monitoring, inventories of assets, accounts and third parties, regular vulnerability and penetration testing, immediate reporting of significant incidents to the Bank, and an annual maturity assessment.
The Guidelines were published as Gazette Notice No. 668 of 2023 in Government Gazette No. 7240 of 19 May 2023, under section 167(1) of the Banking and Financial Services Act 2017, section 43(1) of the National Payment Systems Act 2007 and section 63 of the Credit Reporting Act 2018. They took effect on publication and revoked Gazette Notice No. 333 of 2023.
They apply to all regulated entities, defined as financial service providers, payment systems, payment system businesses and credit reference agencies. The Bank uses an 'apply or explain' approach: larger, more complex entities are expected to apply the Guidelines fully, and entities that cannot apply a guideline must explain how they manage the risk. Microfinance institutions and other non-bank lenders should confirm with the Bank how the Guidelines apply to their licence category.
The requirements follow five control areas — Identify, Protect, Detect, Respond and Recover — which the Guidelines anchor on the NIST framework. Some definitions still point to the Cyber Security and Cyber Crimes Act, 2021, which has since been repealed by the Cyber Security Act 2025.
Governance and the CISO
The board must set the tone for cyber-risk awareness, approve cyber-risk appetite, the risk management framework and policies, and review work plans for cyber and information risk, business continuity and disaster recovery (para 7.1). Senior management must oversee risks introduced by third-party service providers (para 7.2(7)), designate a suitably qualified chief information security officer independent of day-to-day IT operations (para 7.2(8)), and establish a security operations centre or, at a minimum, a mechanism to monitor threats continuously and respond to incidents promptly (para 7.2(13)). Policies must be approved by the board and regularly reviewed (para 7.3).
Identify: inventories and risk assessment
- An inventory of physical devices, applications and systems, maintained and updated regularly, with third-party information systems catalogued (para 8.1).
- An up-to-date inventory of critical functions, key roles, processes, information assets, third-party service providers and interconnections, and a network topology of the infrastructure that supports critical functions (para 8.2).
- An inventory of all individual users, system accounts, and privileged and remote-access accounts (para 8.2(11)).
- Regular risk assessments that determine likelihood and impact, assign risk responses and identify residual risk (para 8.3).
- Cyber and information audits at a planned interval (para 8.4(5)).
Protect: access, patching, outsourcing and testing
- Least-privilege access with regular reviews of user access privileges, and strong authentication such as multi-factor authentication for remote access where appropriate (para 9.1).
- Change and patch management, including identifying systems approaching end of life (para 9.1.8).
- For material outsourcing: a risk assessment, due diligence and the Bank's approval before engaging the provider (para 9.1.9).
- Vulnerability assessments at least quarterly or when there is a significant change, and annual intelligence-led penetration tests of internal and external networks and critical systems by suitably accredited testers (para 9.1.10).
- Periodic backup testing and regular testing of incident response, business continuity and disaster recovery plans (para 9.1.10).
- Ongoing awareness programmes and role-based security training (para 9.2).
- An inventory of all sensitive information stored, processed or transmitted, including at remote service providers (para 9.3).
Detect: monitoring and logging
Entities must detect anomalous activity in a timely manner, establish a baseline of network operations and expected data flows, correlate event data from multiple sources and set incident alert thresholds (para 10.1). Continuous monitoring should cover the network, privileged account activity, external service providers and unauthorised devices, and include vulnerability scans. Event logs should be mirrored to a separate system reviewed by personnel independent of IT operations (para 10.2).
Respond and recover
Entities must maintain an incident response plan and an incident repository (para 11.1(4)), inform the Bank of Zambia immediately a medium or highly classified incident is discovered and before any media interaction (para 11.1(5)), and submit a formal incident report after investigation that includes root-cause analysis and corrective actions (para 11.1(6)).
Recovery planning must define recovery point and recovery time objectives, rest on a business impact analysis, and be updated regularly (para 12).
Annual maturity assessment
Each regulated entity must conduct a cyber and information security maturity assessment every year, commensurate with its size and complexity, and submit the methodology, tools and results to the Bank (para 13). ICTM does not produce this assessment; its compliance readiness scores, control mappings and findings history can be inputs to it.
Key obligations and how ICTM helps
A summary of provisions that affect how organisations manage ICT. It is not exhaustive — read the legislation for the full requirements.
| Obligation | Source | What it requires | How ICTM helps |
|---|---|---|---|
| Appoint an independent CISO | BoZ Cyber and Information Risk Management Guidelines, 2023, para 7.2(8) | Designate a suitably qualified chief information security officer who is independent of day-to-day IT operations. | — |
| Operate a SOC or continuous monitoring | BoZ Cyber and Information Risk Management Guidelines, 2023, paras 7.2(13) and 10.2 | Establish a security operations centre or, at a minimum, a mechanism to monitor threats on an ongoing basis and respond promptly. | Network detection and response on NetFlow, IPFIX and sFlow; collection of syslog, Windows event logs and Linux authentication logs with threshold rules; scheduled vulnerability scans; CVE and CISA KEV matching. |
| Maintain asset and system inventories | BoZ Cyber and Information Risk Management Guidelines, 2023, paras 8.1 and 8.2 | Keep inventories of devices, applications, systems, information assets, third-party providers and interconnections, and a network topology. | Asset register and CMDB with assignment history and dependency mapping, a software catalogue, subnet discovery for IP address management, and a network topology map maintained by your team. |
| Inventory accounts and review access | BoZ Cyber and Information Risk Management Guidelines, 2023, paras 8.2(11) and 9.1.3 | Keep an inventory of users, system, privileged and remote-access accounts, and regularly review access privileges against least privilege. | Active Directory synchronisation with an access-review report; scans for dormant and orphaned accounts; time-limited privilege elevation with approval. |
| Test vulnerabilities regularly | BoZ Cyber and Information Risk Management Guidelines, 2023, para 9.1.10 | Assess vulnerabilities at least quarterly or on significant change, and commission annual intelligence-led penetration tests by accredited testers. | Scheduled network and web-application scanning with CVE matching, authenticated role-based testing and remediation deadlines by severity. It supports internal testing and does not replace accredited external testers. |
| Manage outsourcing and third-party risk | BoZ Cyber and Information Risk Management Guidelines, 2023, paras 7.2(7) and 9.1.9 | Assess and oversee third-party providers, and seek the Bank's approval before a material outsourcing arrangement. | Vendor register and contracts with linked SLA policies; vendor dependencies per application with single-point-of-failure flags and concentration-risk analysis. |
| Report incidents to the Bank | BoZ Cyber and Information Risk Management Guidelines, 2023, para 11.1(5)–(6) | Inform the Bank immediately a medium or highly classified incident is discovered and before any media interaction; then submit a formal report with root-cause analysis and corrective actions. | Incident register with severity and export, and root-cause analysis records (5-whys and fishbone) for the formal report. |
| Plan recovery from a business impact analysis | BoZ Cyber and Information Risk Management Guidelines, 2023, paras 9.1.10 and 12 | Define RPOs and RTOs, base the recovery strategy on a business impact analysis, and test backups and recovery plans. | Business impact analyses with RTO, RPO and maximum tolerable downtime; versioned continuity plans; DR exercises recording target versus actual recovery times; scheduled backups with compliance scoring. |
| Submit an annual maturity assessment | BoZ Cyber and Information Risk Management Guidelines, 2023, para 13 | Conduct an annual cyber and information security maturity assessment and submit the methodology, tools and results to the Bank. | Readiness scores and control mappings against the NIST CSF 2.0 control set provide evidence for the assessment; the assessment itself remains yours. |
Frequently asked questions
Who do the Bank of Zambia cyber risk guidelines apply to?
They apply to all regulated entities, which the Guidelines define as financial service providers, payment systems, payment system businesses and credit reference agencies. The Bank uses an 'apply or explain' approach, so larger and more complex entities are expected to apply them fully, while others must explain how they manage any requirement they do not apply.
Do the guidelines apply to microfinance institutions?
The Guidelines apply to financial service providers as defined in the Banking and Financial Services Act 2017, and to payment system businesses and credit reference agencies. Whether a particular microfinance institution or non-bank lender is covered depends on its licence, so confirm applicability with the Bank of Zambia. Many institutions adopt the requirements as good practice regardless.
How quickly must a cyber incident be reported to the Bank of Zambia?
Paragraph 11.1(5) requires a regulated entity to inform the Bank immediately a medium or highly classified cyber and information risk incident is discovered, and before any media interaction about it. A formal incident report, including root-cause analysis and corrective actions, must follow after the investigation (para 11.1(6)).
How often is penetration testing required under the guidelines?
Paragraph 9.1.10 calls for annual intelligence-led penetration tests of internal and external network infrastructure and critical systems, performed by suitably accredited testers, and vulnerability assessments at least quarterly or whenever there is a significant change to the information-processing infrastructure.
What is the annual maturity assessment?
Under paragraph 13, each regulated entity must assess its cyber and information security maturity every year, in proportion to its size and complexity, and submit the methodology, the tools used and the results to the Bank of Zambia. It is the entity's own assessment, so keep the evidence behind each rating.
Does ICTM include a Bank of Zambia control set?
No. ICTM includes control sets for NIST CSF 2.0, ISO/IEC 27001:2022, PCI DSS 4.0 and others, plus the registers and monitoring tools mapped on this page. Many of the Guidelines' requirements can be evidenced with them, but you map the Guidelines to your own controls and remain responsible for reporting to the Bank.
Sources
This page is general information about Zambian law as reviewed on 13 September 2026. It is not legal advice. Laws and regulator guidance change — check the current legislation or consult a qualified legal adviser before relying on it. Ontech ICTM helps you organise records and evidence; it does not by itself make an organisation compliant.