Central Bank of Kuwait Launches 6th Cohort of Cybersecurity Leaders Program
The Central Bank of Kuwait has launched the sixth cohort of its Cybersecurity Leaders Program, delivered with the SANS Institute and the Bank for International Settlements.

A modern banking sector training centre with laptops and desks, representing Kuwait's cybersecurity leadership development programme
The Central Bank of Kuwait has launched the sixth cohort of its Cybersecurity Leaders Program, continuing a structured, multi-year effort to build specialised cybersecurity leadership specifically within the country's banking and financial sector. CBK Governor and Chairman of the Kuwait Institute of Banking Studies Basel Al-Haroun announced the new cohort on 16 August, targeting Kuwaiti nationals seeking to specialise in cybersecurity as a career track. Applications opened the same day and remain open through Thursday, 24 September 2026, submitted via the programme's dedicated portal at Kafaakw.org.
What distinguishes this programme from a generic training initiative is the calibre of its delivery partners. The programme runs in cooperation with the SANS Institute, widely regarded as one of the world's leading cybersecurity training and certification bodies, and concludes with a workshop delivered jointly with the Bank for International Settlements, the institution that functions as a central bank for the world's central banks. Pairing SANS's technical training pedigree with BIS's standing in global financial stability gives this programme a credibility bar considerably higher than a typical domestic upskilling initiative, and it signals that Kuwait's central bank is treating cybersecurity leadership development as a matter connected to international financial system resilience, not simply local workforce planning.
Al-Haroun described the programme's purpose in direct terms: developing a generation of specialists capable of designing and implementing effective programmes to protect information systems across Kuwait's banking and financial sector, in line with international best practices. That framing matters. The programme is not oriented toward general IT security awareness. It is explicitly aimed at producing the kind of senior technical leadership capable of architecting institutional-level security programmes, the roles that sit between line-level security analysts and executive risk committees, and that gap is precisely where many financial institutions across the region report the most acute talent shortages. As documented in the MDR in the GCC analysis published on this site, the GCC faces some of the world's most acute cybersecurity talent shortfalls, with more than 35,000 unfilled cybersecurity roles in Saudi Arabia alone, a figure that understates the regional picture when Kuwait and the broader Gulf financial sector are factored in.
The programme sits within Kuwait's broader Kafa'a initiative, a joint effort between the Central Bank, Kuwaiti banks and KIBS aimed at developing and qualifying national talent for leadership roles across cybersecurity and related fields. Al-Haroun was explicit that the goal extends beyond simply staffing existing roles. The programme is designed to enable Kuwait's financial sector to adopt emerging technologies while ensuring the associated risks are effectively managed and mitigated, an acknowledgement that technology adoption and security capability need to scale together rather than security perpetually playing catch-up to whatever new system or platform a bank has already deployed. That alignment challenge sits at the heart of the threat landscape the IMF has flagged as posing systemic risk to global financial infrastructure, with the GCC's banking sector specifically named as carrying heightened exposure due to the region's deep integration between digital financial services and critical national infrastructure.
Structurally, the programme runs three months, concluding with the joint workshop held in cooperation with BIS. Selection follows objective criteria, with mandatory testing and personal interviews required of applicants. Al-Haroun noted the programme builds directly on the progress and outcomes achieved across its five previous cohorts through the same partnership structure, indicating this is a sustained institutional commitment rather than a one-off initiative launched and then allowed to lapse.
For the wider GCC cybersecurity landscape, Kuwait's approach offers a useful data point in a broader regional pattern: central banks and financial regulators increasingly treating cybersecurity workforce development as core financial sector infrastructure, on par with capital adequacy or liquidity requirements, rather than a discretionary training line item. The BFSI sector research published on this site documents that financial services organisations absorb cyberattacks at 1.6 times the global average, with mean breach containment times of 263 days. A banking sector's resilience against threats of that frequency and sophistication is only as strong as the depth of specialised talent capable of designing and running its defences, and a sixth consecutive cohort, delivered through the same high-calibre international partnerships each time, suggests Kuwait's financial sector is treating that talent pipeline as a long-term structural investment. The UAE Government Cybersecurity Summit convened earlier this year placed GCC cybersecurity workforce development alongside AI-driven threat readiness as twin priorities on the institutional security agenda, and Kuwait's CBK programme is a concrete regional example of how that institutional commitment is being operationalised.
For financial institutions and fintech companies operating in or alongside Kuwait's banking sector, graduates emerging from a programme built around SANS certification standards and BIS-level engagement represent a credible, pre-vetted talent pool worth tracking directly, both as a recruitment channel and as an external signal of where the country's financial cybersecurity capability is heading over the medium term. The Kuwait NCSC National Basic Cybersecurity Controls mandate issued earlier this year already established enforceable compliance obligations for Kuwaiti enterprises across credential governance, access controls, and network security. A central bank programme specifically building the human capacity to design and run those controls at institutional scale is the workforce investment that makes regulatory mandates operationally meaningful rather than simply documented. With applications open until 24 September, this is also a live recruitment and sponsorship window worth flagging to any GCC financial institution's talent or GRC team tracking regional cybersecurity capacity building.
Layla Haddad
Cyber Policy & Digital Risk CorrespondentLayla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.