
ARABIAN TIMES NEWS NETWORK
Kuwait’s banking sector has steadily built a strong, multi-layered system to protect customers from electronic fraud. What began as basic safeguards for online banking has evolved into a much broader framework that combines technology, customer awareness, transaction monitoring and stronger regulatory oversight. The Central Bank of Kuwait began strengthening digital banking security in 2009 by introducing two-factor authentication. This was followed by the establishment of specialised customer complaint units in 2011 and a 24-hour customer service line in 2013. In 2015, the Bank Customer Protection Guide further strengthened the responsibility of banks to safeguard customers’ deposits, savings and financial assets.
As digital payments became increasingly common, additional layers of protection were introduced. In 2017, banks were required to adopt verification codes and 3D Secure for online purchases, while measures were also introduced to control repeated incorrect PIN attempts and require customers to activate their cards. The focus then shifted towards helping customers identify suspicious transactions quickly. In 2018, SMS transaction alerts were introduced, giving account holders an immediate warning whenever activity took place on their accounts.
Cybersecurity became an even greater priority in 2020 with the introduction of the Strategic Cybersecurity Framework for Kuwait’s banking sector. A year later, banks and major payment networks, including K-Net and Cy-Net, obtained ISO/IEC 27001 certification. The Central Bank also launched the “Let’s Be Aware” campaign to educate the public about electronic fraud and encourage safer digital banking habits. Kuwait continued tightening its safeguards in 2023 by strengthening controls over electronic payment links. These measures included displaying beneficiary details on statements, limiting the validity of payment links to 24 hours and setting transaction limits.
In June 2024, customers were required to review important payment information—including the amount, beneficiary and purpose, before completing transactions. OTP messages were also required to clearly state the transaction amount, making it easier for customers to detect suspicious requests. The next major step came in 2025 with the launch of the Fraud Shield Initiatives Acceleration Program, bringing banks, payment providers, fintech companies and regulators together to develop faster and smarter ways to detect fraud before customers suffer losses.
The updated Bank Customer Protection Guide, issued in October 2025, further reinforced banks’ responsibility to protect customer information and combat financial fraud. In December 2025, the Central Bank introduced the Cyber and Operational Resilience Framework, replacing the 2020 cybersecurity framework and reflecting the increasingly sophisticated nature of cyber threats. Kuwait’s journey shows how banking security has evolved—from simply protecting account access to creating several interconnected layers of defence designed to detect, prevent and respond to fraud while keeping customers at the centre of the system.


