US Treasury Seeks Enhanced G7 Cybersecurity Cooperation

0
3

Key Takeaways

  • The G7 Cyber Expert Group (CEG) completed its 2026 cross‑border coordination exercise (CBCE) on 18 May, simulating a large‑scale cyber‑attack across all G7 jurisdictions.
  • The exercise involved finance ministries, central banks, bank supervisors, financial market authorities, and private‑sector participants, testing incident response, recovery, and crisis‑communication improvements identified in prior simulations.
  • Building on a long‑term exercise strategy, the CEG will increase the frequency and consistency of such simulations to boost collective preparedness.
  • The U.S. Treasury, set to assume the G7 presidency in 2027, pledged to deepen practical cooperation through the CEG and advance a more secure, resilient global financial system.
  • The UK’s HM Treasury released a July 2026 report highlighting that cyber risk is becoming more severe and complex, with rising disruption costs and growing exposure through third‑party and platform dependencies.
  • The CEG has produced several recent publications, including a framework for collective cyber incident response, a roadmap for transitioning to post‑quantum cryptography, and a statement on the opportunities and risks of quantum computing.
  • These efforts underscore the G7’s commitment to strengthening cyber resilience in the financial sector amid evolving threats and technological shifts.

Overview of the G7 Cyber Expert Group Exercise
The G7 Cyber Expert Group (CEG) is a multi‑year working group that coordinates cybersecurity policy and strategy across the G7 jurisdictions to enhance the cyber resilience of the financial sector. Established in 2015, the CEG brings together finance ministries, central banks, bank supervisors, and financial market authorities from Canada, France, Germany, Italy, Japan, the United Kingdom, and the United States, with the European Union participating as a non‑enumerated member. Its core mission is to foster cross‑border cooperation, share best practices, and develop joint capabilities to counter cyber threats that could destabilise the global financial system.


Details of the 2026 Cross‑Border Coordination Exercise
On 18 May 2026, the CEG concluded its cross‑border coordination exercise (CBCE), a simulated large‑scale cyber‑attack that unfolded across all G7 member jurisdictions. The exercise engaged ministries of finance, central banks, bank supervisors, financial market authorities, and selected private‑industry participants. Scenarios were designed to test the participants’ ability to detect, contain, and recover from a coordinated cyber incident that could disrupt payment systems, securities markets, and critical financial infrastructures. The exercise built upon lessons learned from earlier drills, incorporating refinements in incident response protocols, recovery timelines, and crisis‑communication procedures.


Objectives and Outcomes of the Exercise
The primary objectives of the 2026 CBCE were to validate the improvements identified in previous simulations, strengthen collective preparedness, and enhance the speed and effectiveness of cross‑border responses. According to the press notice released on 31 July, the exercise “tested key improvements identified through previous simulations and workshops focused on incident response, recovery and crisis communication, further advancing collective preparedness.” Participants reported that the drill clarified decision‑making hierarchies, improved information‑sharing mechanisms, and highlighted gaps in technical and organisational controls that will be addressed in forthcoming workstreams.


Expansion of CEG Activities
Following the successful completion of the 2026 CBCE, G7 authorities agreed to expand the CEG’s activities. The group will continue its recurring workstreams—annual incident‑response tests and quadrennial cross‑border cyber exercises—while also developing ad‑hoc workstreams that produce targeted reports on emerging cybersecurity topics relevant to the financial sector. A long‑term exercise strategy has been adopted to increase the frequency and consistency of simulations, thereby ensuring that participating jurisdictions maintain a high state of readiness against evolving cyber threats.


Statements from Officials
In the U.S. Treasury’s press statement, PDO Deputy Secretary Francis Brooke emphasised that “cyber threats do not respect borders, and neither can our response.” He highlighted that the G7 Cross‑Border Coordination Exercise strengthens the collective ability to respond to cyber incidents that could affect the global financial system. Brooke also noted that, as the United States prepares to assume the G7 presidency from France (which holds the 2026 presidency), the U.S. Department of the Treasury looks forward to deepening practical cooperation through the CEG and advancing a more secure and resilient global financial system. Similar sentiments were echoed by officials from other G7 members, underscoring a shared commitment to collaborative defence.


Frequency and Future of Simulations
The CEG’s press notice announced that a long‑term exercise strategy has now been adopted to increase the frequency and consistency of these simulations. This approach aims to embed regular cyber‑drill cycles into the operational routines of financial authorities, reducing the likelihood of surprise when real incidents occur. By institutionalising frequent exercises, the G7 seeks to build muscle memory across jurisdictions, ensuring that response playbooks are continuously refined and that lessons are rapidly disseminated.


Relation to Previous Exercises
The 2026 CBCE follows a similar undertaking conducted a couple of years earlier in 2024. That earlier exercise involved 23 financial authorities, including ministries of finance, central banks, bank supervisors, market authorities, and private industry participants. The 2024 drill laid the groundwork for the improvements tested in 2026, particularly in the areas of incident response coordination and recovery planning. The progression from biennial to more frequent simulations reflects the G7’s recognition that cyber threats are accelerating and that preparedness must evolve in tandem.


UK HM Treasury Report on Cyber Resilience
Just a month before the CBCE conclusion, the UK’s HM Treasury published a report titled “The Value of Resilience: Cyber Resilience in Financial Services” (8 July 2026). The report concluded that cyber risk is becoming more severe and more complex, especially within increasingly digital and interconnected operating environments. Survey data, incident records, and sector‑level analysis indicated rising disruption, higher recovery costs, and growing exposure through third‑party and platform dependencies. Senior decision‑makers in financial services view these risks as both firm‑level and sector‑level concerns, noting that cyber incidents can generate material profit‑and‑loss impacts, affect firm value, and erode trust by revealing weaknesses in governance, controls, or operational resilience.


G7 CEG Publications and Quantum Initiatives
The CEG has produced several recent outputs that complement its exercise work. In September 2025, it released a seven‑page document entitled “G7 Fundamental Elements of Collective Cyber Incident Response and Recovery in the Financial Sector.” In January 2026, it issued a five‑page “Statement on Advancing a Coordinated Roadmap for the Transition to Post‑Quantum Cryptography in the Financial Sector.” Earlier, in September 2024, the group published a three‑page “Statement on Planning for the Opportunities and Risks of Quantum Computing.” These publications demonstrate the CEG’s commitment to addressing both immediate cyber‑incident readiness and longer‑term technological shifts, such as the advent of quantum computing, which could undermine current cryptographic protections.


Conclusion and Implications for the Global Financial System
The successful completion of the 2026 G7 Cyber Expert Group cross‑border coordination exercise marks a significant step toward strengthening the cyber resilience of the international financial architecture. By institutionalising regular, sophisticated simulations, expanding the CEG’s mandate, and producing actionable guidance on incident response, post‑quantum cryptography, and quantum risk, the G7 is positioning itself to anticipate and mitigate cyber threats that transcend national borders. The forthcoming U.S. Treasury presidency in 2027 promises to deepen this cooperation, fostering a more unified defence posture that safeguards financial stability, protects market integrity, and sustains public trust in an increasingly digital world.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here