At the Silk Road Finance & Technology Forum held in Tashkent on August 24-26, during a panel discussion titled “Trust at SI Speed: Ensuring Payment System Security and Protection from Fraud,” experts emphasized the need for Central Asian countries to cooperate in cybersecurity, exchange data continuously, and improve financial literacy. They also noted the importance of abandoning outdated approaches and acting based on today’s realities when developing protection mechanisms.
Artyom Saidov, Head of Cybersecurity at KPMG Uzbekistan, noted that Central Asia is at the peak of digital transformation. This process, by accelerating the movement of funds domestically and across borders, has significantly changed methods of protection against cybercrime and fraud. According to him, artificial intelligence equally enhances the capabilities of both fraudsters and financial institutions. Fraudsters use automated intelligence and complex social engineering, while financial institutions rely on scoring, behavioral analysis, predictive risk modeling, and automated response measures. Trust is now based not on static compliance but on active and dynamic resilience.
According to Mirzabek Bobojonov, Head of Department at the Central Bank of Uzbekistan, the volume of digital payments in the country has been growing rapidly in recent years. While the level of digital payment usage was 39% in 2021, it reached 72% by 2025. This is explained by the young population ready to test new technologies and projects. However, with the growth of digital payments, the importance of security is increasing. Bobojonov noted that the Central Bank is transitioning from a compliance-based approach to a risk-based approach. In this regard, a cybersecurity strategy for the banking sector and a methodology for assessing risks based on the maturity level of commercial banks and payment organizations have been developed. The new system will be implemented next year and will include four maturity levels, with systemically important banks required to comply with the strictest rules.
According to Bobojonov, since the beginning of this year, commercial banks and payment organizations have suspended about 18 million suspicious transactions. This is due to the requirement for financial organizations to have an AI-based anti-fraud system. Nevertheless, due to low financial literacy of citizens, this does not guarantee 100% protection. Therefore, everyone must be more vigilant, as threats and fraudsters’ methods change daily.
Nikolay Bernstein, Senior Director for Consulting and Analytics at Visa, emphasized that proper risk management and the human factor are central to fraud prevention. According to him, the weakest link in the cyberattack chain is the human. Fraudsters exploit people’s trust. Moreover, as the volume of digital payments grows, so does the field of cyber risks. Bernstein noted that the main problem is not the payment systems or the ecosystem itself, but the weakest link — the human. Therefore, serious attention must be paid to improving the financial literacy and awareness of customers.
Umid Khakimov, Chief Executive Officer of “Ipak Yo‘li Bank,” citing official statistics from the Ministry of Internal Affairs, reported that over the past five years, the number of cybercrimes has grown from 4,800 to more than 62,000. During this period, the recognized total losses of individuals and companies exceeded 3.8 trillion soums. Khakimov called this a “very large figure” and noted that approximately half of this amount falls in 2025. He focused on two aspects: first, it is necessary to improve financial literacy, as the increase in digital payment usage from 39% to 72% means many new users lack basic security knowledge. Second, small and medium-sized businesses are vulnerable to cyber threats, as they often lack IT or cybersecurity specialists, shifting responsibility to commercial banks.
Speaking about mistakes that could prove costly for Central Asian countries, Nikolay Bernstein noted that fraudsters need only minutes to invent and create new cyberattack methods, while creating protection mechanisms takes time due to outdated approaches and bureaucratic processes. According to him, social engineering has become very easy: creating phishing emails, malware, and deepfakes takes minutes. Protection, however, continues to operate based on outdated approaches rather than today’s realities. Bernstein emphasized that artificial intelligence can help in the fight against fraud, but it is not a panacea and requires investment, training, and adaptation.
Zohir Mirzayev, Director of the Information Security Department at “Asaka Bank,” confirmed the importance of rapid response to cyberattacks. According to him, if previously it took from 6 to 12 hours to detect an attack, now this period has sharply decreased. If an attack is not detected within an hour and a half or half an hour, the attacker can breach the system. Mirzayev noted that artificial intelligence has become a great assistant in ensuring information security, helping to reduce resource and time barriers, test applications, find vulnerabilities, and eliminate them in a timely manner.
At the end of the discussion, a question was posed about which direction — capability, technology, governance, or cooperation — the financial sector of Central Asia should develop in the coming year to maintain trust in payments. Experts unanimously emphasized the priority of cooperation. According to Mirzabek Bobojonov, sharing data on fraud and cybercrime in real time greatly helps financial organizations. No bank, regulator, or provider can single-handedly counter attacks. Nikolay Bernstein also stated that exchanging experience in cybersecurity is a must, citing fraudsters who share experience within their ecosystems. He said that in Scandinavia, if one bank is attacked, another is attacked within hours or days, so information sharing is important for society, even under closed agreements. Zohir Mirzayev supported the importance of data and experience exchange, expressing confidence that in the future, information exchange between banks will become automatic. He also noted the importance of bank transparency and cyber hygiene among users, which should start in schools.
Source: www.gazeta.uz