נב"ת — Bank of Israel Cyber & IT Risk Directive
Who needs it
Banking corporations and credit card companies regulated by the Bank of Israel's Banking Supervision Department.
Key requirements
Board and management governance over cyber risk, a risk-assessment framework covering internal systems and third-party/outsourced providers, continuous monitoring and threat detection, incident response and resilience planning, periodic drills, and organization-wide staff training.
Cyber implications
Third-party and vendor remote access to critical systems must use strong, multi-factor authentication. The framework is deliberately technology-neutral, so evidence of a working risk process matters more than any specific tool.
Assessment methodology
Gap assessment against Directive 364's consolidated requirements, third-party/vendor risk review, incident-response readiness test, and a governance review of board-level cyber oversight.
Implementation phases
Assess
Map current controls against Directive 364, including the former 357/361/363 scope.
Remediate
Close governance, vendor-risk and monitoring gaps ahead of the transition deadline.
Evidence
Document board oversight, risk assessments and drill results in an audit-ready form.
Evidence & documentation requirements
Board and management minutes showing active cyber-risk oversight, asset and third-party risk assessments, incident-response logs, vendor due-diligence records, and periodic drill reports, all reviewable by the Banking Supervision Department.
Common mistakes
Treating נב"ת as an IT-only policy instead of a board-level governance obligation; assuming legacy Directive 361 controls alone satisfy 364's broader consolidated scope; and under-scoping third-party and vendor remote-access risk.
Related standards
Expert review
FAQ
Request a Gap Assessment
See exactly where your controls stand against Directive 364's consolidated requirements before your transition deadline.
Request a Gap Assessment →