Westminster Policy News & Legislative Analysis

G7 2026 Cross-Border Cyber Exercise Sets Regular Drill Cycle

According to the GOV.UK notice, the G7 Cyber Expert Group completed its 2026 Cross-border-coordination exercise on 18 May 2026. The exercise was designed to test how G7 financial authorities would co-ordinate during a major cyber incident affecting more than one jurisdiction, and the group said a long-term exercise strategy has now been adopted to make future simulations more frequent and more consistent. That change is notable because the announcement presents the exercise as part of a standing preparedness programme rather than a one-off event. For finance ministries, central banks and regulators, repeat testing is intended to improve shared awareness, shorten response times and reduce the risk of fragmented public communication during a cross-border crisis.

The 2026 exercise built on the earlier 2024 CBCE, which aimed to strengthen the ability of G7 financial authorities to co-ordinate and communicate in response to a major cross-border cyber attack on the financial sector. This year's sessions, the notice says, tested improvements identified through previous simulations and workshops, with a stated focus on incident response, recovery and crisis communication. The scenario simulated a large-scale cyber attack across all G7 jurisdictions. Ministries of finance, central banks, bank supervisors and market authorities were brought into the exercise, reflecting the fact that a serious operational incident in finance can quickly move beyond a single institution and require aligned decisions across several public bodies.

The official statement places particular weight on frequency and consistency. In policy terms, that points to a more standard approach to contact arrangements, escalation routes and decision-making across borders, especially where authorities must exchange information quickly while sustaining market confidence. For firms operating in more than one market, the message is straightforward. Public authorities are continuing to test whether response plans, recovery procedures and communication arrangements work across jurisdictions rather than inside domestic silos alone.

The wider concern is financial stability. Cyber incidents affecting payment systems, trading venues, banks or other market infrastructure can interrupt services, delay settlement and create uncertainty well beyond the original point of compromise. The G7 statement therefore treats cross-border co-ordination, preparedness and timely information sharing as standing priorities. That emphasis reflects the degree of interconnection across the financial system. Where institutions, counterparties and market utilities operate across national borders, public-sector response cannot depend on ad hoc links assembled after the event. Regular joint exercises are meant to ensure those relationships are operational before a crisis begins.

The Cyber Expert Group's role, as described in the GOV.UK announcement, is to co-ordinate cyber security policy and strategy across G7 jurisdictions and strengthen the resilience of the financial sector. Its remit includes building preparedness, supporting a shared picture of cyber threats and encouraging common approaches to risk reduction. The group's recent publications show that the work extends beyond incident drills alone. The notice highlights a 2025 statement on AI and cybersecurity, a 2025 best-practice reconnection framework and a 2026 statement on the transition to post-quantum cryptography. Together, those documents place exercise planning within a broader programme of operational and strategic cyber policy.

The next stage is unlikely to be a single follow-up announcement so much as a continuing cycle of technical work between authorities. The long-term strategy adopted after the 2026 exercise indicates that G7 members want repeat testing to become routine, with lessons carried forward between simulations rather than restarted each time. For regulated firms and market operators, the practical reading is that supervisory attention will remain fixed on governance, incident escalation, recovery planning and external communications during cyber stress. The signal from the 18 May 2026 exercise is clear: cross-border cyber readiness is being treated as a financial-stability discipline, not only an information-technology issue.