AI
Sep 14, 2026


Mirzabek Bobojanov is Head of Unit at CERT-CBU, the Cybersecurity Center of the Central Bank of the Republic of Uzbekistan. His work sits at the intersection of financial cybersecurity, digital transformation, cyber resilience and risk-based supervision, with a focus on strengthening the security of Uzbekistan’s rapidly evolving digital financial infrastructure.
At the Silk Road Finance & Technology Forum in Tashkent, Bobojanov spoke with Tech Revolt about the changing cyber threat landscape, AI-driven fraud and Uzbekistan’s plans to strengthen cybersecurity across its financial sector.
[For more news, click here]
As financial services move further into the digital sphere, Bobojanov looks at how the rules, infrastructure and responsibilities around cybersecurity are evolving. For Uzbekistan, he argues, this means treating cybersecurity not simply as a technical safeguard, but as a fundamental part of the country’s digital infrastructure, institutional accountability and financial trust.
For Mirzabek Bobojanov, the answer begins with where data is stored, who is responsible for protecting it and how institutions assess risk.
His position reflects a wider shift in the country's regulatory thinking. Cybersecurity is no longer being treated simply as a checklist for financial institutions to satisfy. Instead, the focus is increasingly on understanding the specific risks facing each institution, while building the domestic infrastructure and expertise needed to manage those risks.
Inside Uzbekistan's cybersecurity strategy
Q1: The new cybersecurity strategy identifies AI-based cybersecurity technologies as a priority. At the same time, financial institutions are increasingly using AI to detect fraud and suspicious activity. How much of this capability should be developed domestically, and where's the right balance between adopting foreign technology and maintaining technological stability?
That's a really good question. I'll start from the beginning. Recently we finished our project on digitalization of the central bank, and that project covered many topics, one of them was cybersecurity, enhancing cybersecurity for the banking sector. As part of that, we developed a methodology for assessing the cybersecurity risk profile and maturity of financial institutions. As a regulator, we're starting to assess cybersecurity risks in commercial banks and payment organizations, and that also covers the use of AI.
On foreign versus local, when you get AI technology from foreign providers, your data goes there too, and that's a cybersecurity risk, a big one, I think. There's a law that recently changed allowing data to be stored in foreign countries, but only in countries on a list managed by the Cabinet of Ministers, and you can legally send your data to those countries. But in the banking sector specifically, we have a Central Bank rule that doesn't allow storing data outside Uzbekistan, because of the cybersecurity risks. Every country is doing something like this. Recently we've seen it in the European Union, in Germany, in France, everyone is moving toward digital sovereignty because of cybersecurity risk. We're following the same path, because we have to protect our citizens' data and our banking data.
Q2: And you're building the infrastructure here as well?
The central bank is planning to build its own infrastructure and give it to the financial sector, every financial institution could use it in future. There's also other infrastructure available to rent, as long as it's located inside Uzbekistan. Two or three years ago we didn't allow this, every bank had to have its own infrastructure, but now they can store data in the cloud.
Q3 As Uzbekistan attracts foreign capital into increasingly sophisticated digital infrastructure, what cybersecurity considerations should financial institutions and payment organizations have as their systems and data increasingly depend on third-party data centers, cloud infrastructure, and external providers?
There is a risk, it's a supply chain risk. From our side, as I mentioned, we'll make regulation in this space. The plan is that any third-party provider for a commercial bank should have a risk assessment carried out by the financial institution.
Q4: On data location, if a GCC investor, say from Saudi Arabia, wants to invest in Uzbekistan's IT sector but is concerned about their data being used, do you have any note on that?
Right now our rule says you can only store data on governmental data centers, but we're changing that, and soon we'll also allow public-sector data centers. There's no significant risk in commercial banks or other institutions using data centers here, because it's located inside Uzbekistan, so the risk of data leakage is minimal. Public partners themselves aren't regulated by the Central Bank of Uzbekistan (CBU), but if a bank wants to outsource its systems, it has to follow our rules.
Q5: Uzbekistan is planning a major expansion of AI compute and data center capacity. As banks and payment organizations increasingly rely on external cloud, data center, and AI infrastructure, how should responsibility for cybersecurity be divided between the infrastructure provider, the financial institution, and the regulator when a major cyberattack occurs?
That's a good question. If something happens, first the institution will be responsible, because it should care most about its own data and infrastructure. Then the provider that rents them the infrastructure. Last is the central bank, because we're just the regulator, we publish regulation requirements, and everyone who follows them is in a safer position. If they don't follow them, they're at risk. We give them the minimum requirements, but the institution has to carry more responsibility than anyone else for its own security, because the financial risk is significant if there's a data leak or money is stolen.
Q6: Uzbekistan has been moving toward greater digital connectivity while changing its approach to data and globalization. For international technology and financial companies operating here, how should they understand the new rules around cross-border data, particularly when sensitive financial or personal data is processed outside the country?
As I mentioned before, the law says you can store citizens' data outside Uzbekistan, in countries that are on the approved list. But banking data shouldn't be stored outside the country. If it contains information about a client, a commercial bank, or financial information, it has to be located inside Uzbekistan. If you're licensed by the central bank, you have to follow this rule.
Q7: The new cybersecurity framework introduces stronger requirements around cybersecurity providers, vulnerability assessment, and national coordination. What still needs to be built over the next three to five years in terms of talent, technology, and institutional capability to keep cybersecurity in step with the country's digital growth?
First of all, we need more professional specialists, that's very hard to find in the financial sector here right now. That's one of the biggest problems in Uzbekistan today. A cybersecurity university was recently launched, so in a few years I think we'll see new graduates coming through and working in this area. Second, we need more investment. The governors and chairmen of the banks now understand that cybersecurity and fraud prevention is very sensitive, and they have to focus on it and invest more. That's the second challenge. And the third is the geopolitical situation around the world.
Q8: Is there anything about Uzbekistan's cybersecurity transformation that you think international technology companies fundamentally misunderstand?
I don't know about misunderstanding. Many companies are coming to Uzbekistan, opening offices here, and starting to do business, even cybersecurity companies are launching offices and starting to work with ministries, banks, and other organizations. Why are they choosing Uzbekistan? If you look at the statistics, Uzbekistan is growing very fast, six to seven percent GDP growth every year, that's a very good number. We also have a young generation, we're thirty eight, thirty nine million people. I think that's why most companies are coming to Uzbekistan, and our political approach has also completely changed over the last nine or ten years, we're much more open to others now.
Q9: Are there any numbers, facts, or forms of support you'd want included, for example for cybersecurity companies looking to open here?
There's the IT Park, which gives you many opportunities and a lower tax rate than a normal company pays in Uzbekistan if you're a member. You can also get investment through IT Park Ventures, there are many venture companies that can invest in your company inside the IT Park. The fintech sector is similar, the central bank has also launched a venture fund. If someone wants to open a fintech company in Uzbekistan, they'll review your organization and goals and can invest in your company, though there are other rules involved. I'm not a specialist in venture funding, so I can't go into more detail there.
Q10: Just to close, how do you see the future?
The future will be totally digital, in my opinion, even in Uzbekistan. We're more open-minded, we're ready to adopt technologies. Security will be one of the biggest problems around the world, because the more digital we become, the more we have to care about security. We need more investment in this area, not just in Uzbekistan but everywhere. We need much better specialists just to protect all these digital systems.
Building security into Uzbekistan's digital future
Bobojanov's outlook is ultimately straightforward. Uzbekistan is becoming more digital, and cybersecurity will have to evolve at the same pace.
His comments point to a financial system where data sovereignty, domestic infrastructure, third-party oversight and cybersecurity talent are becoming central to the country's technology ambitions.
For banks and technology companies entering the market, that creates both opportunity and responsibility. Uzbekistan is opening its financial and technology ecosystem to new investment, while establishing clearer expectations around how critical systems and data are protected.
The next phase of the country's digital transformation will be measured not only by how quickly new technologies are adopted, but by how effectively the institutions around them can manage the risks that come with them.
Related Articles
Uzbekistan Launches the Silk Road Finance & Technology Forum to Anchor Central Asia’s FinTech Future
Click’s Naima Mirzayeva on Uzbekistan’s Leap from Bank Cards to a Digital Economy
Stablecoins, Tokenisation and Talent: What Was Said on Day Two in Tashkent
Related Articles