Westminster Policy News & Legislative Analysis

G7 Financial Authorities Complete 2026 Cross-Border Cyber Drill

The G7 Cyber Expert Group said its 2026 Cross-border Coordination Exercise concluded successfully on 18 May 2026, marking the latest joint test of how G7 authorities would respond to a major cyber incident affecting the financial sector. The government statement also said the group has adopted a long-term exercise strategy to run these simulations more often and on a more consistent basis. That moves the work from occasional testing towards a standing preparedness cycle across the G7.

The exercise builds on the 2024 Cross-border Coordination Exercise, which was designed to improve how financial authorities coordinate and communicate during a large cross-border cyber event. This year's sessions were used to test changes identified in earlier simulations and workshops, with a particular focus on incident response, recovery and crisis communication. For policy officials, that matters because a cyber response is not only about stopping an attack. It is also about whether ministries, supervisors and central banks can share information quickly enough to support market confidence and keep decision-making orderly.

According to the statement, the 2026 scenario simulated a large-scale cyber-attack across all G7 jurisdictions. It brought together ministries of finance, central banks, bank supervisors and market authorities in a single exercise designed to rehearse a unified response. That mix of institutions is significant. A serious cyber incident in finance can move quickly from a technical problem inside one organisation to a wider issue for payments, liquidity, supervision and market functioning, especially where firms and services operate across borders.

The government statement presents the initiative as a way to better align the operational and strategic elements required for an effective response. In practical terms, that includes who convenes, what information is exchanged, how public messaging is cleared and how recovery steps are sequenced across jurisdictions. Those questions can become urgent when an incident affects payment systems, trading venues or critical service providers at the same time. Delays or conflicting messages from authorities can add pressure even where the original breach is being contained.

The statement places cross-border coordination, incident response preparedness and timely information sharing among the G7's continuing priorities. The emphasis reflects the structure of modern finance, where banks, markets and service firms often depend on systems and counterparties in several countries at once. A disruption in one jurisdiction can therefore create supervisory, liquidity and communications problems elsewhere within hours. Regular joint exercises are one of the few ways public authorities can test those pressures before a real event forces decisions in live conditions.

No new binding rules for firms were announced alongside the exercise. The policy significance lies instead in readiness: clearer contacts between institutions, better-tested communications channels and a more regular schedule for reviewing what worked and what failed. For firms in the financial sector, that is still relevant. When public authorities rehearse crisis coordination more frequently, supervisory expectations around reporting, recovery planning and operational resilience often become more exact, even where formal requirements do not change immediately.

According to the government statement, the G7 Cyber Expert Group is responsible for coordinating cybersecurity policy and strategy across G7 jurisdictions, with a stated mission to improve financial-sector resilience through preparedness, shared threat awareness and more consistent risk mitigation. The statement also points to a broader work programme, including a 2025 statement on AI and cybersecurity, a 2025 reconnection framework best-practice document and a 2026 roadmap on the move to post-quantum cryptography. Read together, those publications show a group working on both immediate crisis response and longer-term technical change, with the 2026 exercise serving as the operational test of whether authorities can act in step when a cross-border cyber attack threatens financial stability.