ITU's 160 anniversary

Connecting the world and beyond

Digital Financial Services (DFS) Security Clinics - Somalia

The International Telecommunication Union (ITU), in collaboration with the National Communications Authority of Somalia, is pleased to invite you to the Stakeholder Engagement Workshop on Digital Financial Services (DFS) planned to take place 10 - 11 December 2025 from 09:00 - 13:00 EAT (GMT+3), which will be held online via zoom. The clinic aims to provide DFS stakeholders with practical guidance and insights into the best practices that regulators and DFS providers should adopt to enhance the security of DFS applications and supporting infrastructure.​

The main objectives of the DFS Security Clinic are to: 

Target audience: The main audience for the DFS Security Clinic are telecommunications regulators, national cybersecurity agencies, central banks, financial service providers, banks, mobile network operators, fintech companies, IT security solution providers, relevant government ministries, and other stakeholders.​

Register here



Programme

Day 1, 10 December 2025 (EAT)​

​10:00 - 10:10​​​Welcome Remarks
​10:10-11:10
Introduction to ITU DFS Security Lab and Knowledge Sharing Platform
​This session will provide a general overview of the ITU DFS Security  Lab and the assistance that it provides to developing countries to adopt the DFS Security recommendations. This session will also introduce the ITU knowledge sharing platform. The ITU DFS Security Knowledge Sharing Platform is designed to foster collaboration among regulators and other stakeholders in the development and implementation of security guidelines and best practices for Digital Financial Services (DFS).​
​11:10-11:20
Coffee Break
11:20-13:00
ITU DFS security recommendations
​This session will present the security measures from the ITU DFS security recommendations to be adopted by DFS regulators and providers to secure the telecom infrastructure and payment system infrastructure.
The following recommendations will be presented:

Day 2, 11 December 2025 (EAT)

​10:00 - 10:50DFS application security best practices and DFS Application Security testing
Following up on the ITU DFS security recommendations on Day 1, this session continues the elaboration of the security control measures to the application layer. As DFS cyber threats continue to evolve, protecting applications from vulnerabilities become paramount. The DFS application security best practices included in the ITU DFS security recommendations can be adopted by regulators to establish a minimum-security baseline for DFS providers to build in security at the design phase. 
This session will explore the security tests that are conducted in the ITU DFS security lab to verify compliance of mobile payment apps against the Security best practices. 
10:50 - 11:00​Coffee Break
​11:00 - 11:30
​​​​DFS Security Assurance Framework and Audit guideline
This session discussed the DFS security assurance framework that can be implemented by DFS providers to better manage the risks and mitigate their impact.

Related Reports:​
Arnold Kibuuka – Project Officer, ITU​
11:30-13:00​Open discussion: Adopting the ITU DFS security recommendations 

In this session ITU will present the results of the gap analysis survey on the DFS security recommendations and open the discussion to NCA and CBS to openly discuss the implementation of the relevant DFS security recommendations. The output of this session is a draft document for the adoption of the relevant recommendations by NCA and CBS.​