Current thematic dossiers

Select a theme to view its dossier.

Cyber & operational resilience

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

Overview

Since the start of 2026, policy and guidance initiatives in relation to cyber and operational resilience have broadly centred around three focus areas:

  • Broader cyber and information and communication technology risk management frameworks, where authorities are formalising cyber resilience as a supervised governance and capability framework. The measures focus on whether institutions have clear accountability, current visibility over systems and assets, risk-based security controls, measurable cyber maturity and evidence that detection, response, recovery and assurance arrangements operate effectively.
  • Operational resilience, business continuity and incident management, where the focus is on institutions’ ability to maintain or restore critical services during disruption. The measures connect service identification, dependency mapping, impact tolerance or recovery-objective setting, continuity planning, fallback arrangements, escalation and reporting so that disruption management is organised around predefined service, governance and recovery processes.
  • Artificial intelligence-enabled cyber risk guidance, translating growing concerns that frontier models may accelerate vulnerability discovery and exploitation into sharpened expectations around prioritisation, speed and control effectiveness. The measures focus on firms knowing which systems matter most, shortening vulnerability triage and remediation where exposure is highest, strengthening layered defences where immediate remediation is not possible, and ensuring senior management, third-party oversight and recovery arrangements remain aligned with faster-moving cyber threats.

What's new

The Canadian Securities Administrators has proposed a harmonized national framework for the IT systems of key market infrastructure entities. It would consolidate existing requirements and covers marketplaces, clearing agencies, trade repositories, information processors and matching service utilities, while seeking input on international alignment and emerging technologies.

The Swedish Financial Supervisory Authority will update DORA incident reporting in Fidac on Oct. 19, including a redesigned form and automated reminders for overdue interim or final reports. The update also separates affected entity data into a dedicated table, adds reference code filtering and introduces a revised JSON schema.

The Bank for International Settlements’ Basel Committee approved a final machine-readable Pillar 3 standard, G-SIB assessment results and revisions to curb year-end window dressing. It will consult on stronger Pillar 2 guidance for interest rate risk and the treatment of European banking union exposures in the G-SIB framework. Updates on the cryptoasset standard review, liquidity principles and final Pillar 3 requirements are expected by the end of 2026.

Deep dive

Broader cyber / information and communication technology risk management

These broader cyber and ICT measures treat cyber resilience as a governed and measurable capability. Institutions are expected to define who is accountable for cyber risk, understand the systems, data assets and dependencies that support their operations, and apply controls according to the criticality of those assets and the institution’s risk profile. In several cases, authorities are also introducing measures to make cyber capabilities measurable through maturity frameworks, periodic self-assessments, risk-based classifications, cyber testing, supervisory submissions and capability roadmaps.

PhilippinesCentral Bank of the PhilippinesCybersecurity Maturity Framework and Cybersecurity Control Self-Assessment

The measure replaces the previous IT rating system with a supervisory assessment framework that uses the Cybersecurity Maturity Framework and four maturity tiers: Foundational, Established, Managed and Optimized. It requires institutions to conduct periodic and rigorous cybersecurity control self-assessments to benchmark current practices, assess control-area maturity and plan target maturity. Expected maturity is linked to institutional IT profile classifications, and the cybersecurity control self-assessment becomes an annual supervisory submission through ASTERiSC.

IndiaInternational Financial Services Centres AuthorityCyber security and cyber resilience guidelines for market infrastructure institutions

The guidelines require market infrastructure institutions to maintain a board-approved cyber security and cyber resilience policy, a documented risk appetite and tolerance statement, and a dedicated CISO reporting to the MD or CEO. Institutions must maintain current asset and dependency inventories, classify critical assets, assess cyber and post-quantum risks, and apply controls proportionate to asset criticality and business-continuity impact. The framework also adds operational assurance and reporting requirements, including 24x7x365 security operations capability, six-hour incident notification, interim and root-cause reporting, annual resilience testing, annual cyber audit and ISO 27001 certification.

PakistanState Bank of PakistanCyber Shield cyber resilience strategy for regulated entities

The strategy sets a 2025–2030 roadmap for regulated entities covering cyber defence, cyber governance, sector collaboration, workforce development and periodic review of cyber strategy and programmes. It prioritises cyber-testing, tiered cybersecurity governance expectations, maturity assessment, cyber-risk scenarios in disaster recovery, zero-trust planning for critical infrastructure and enhanced resilience of financial market infrastructures. It also strengthens sector capability through threat-intelligence sharing, standardised IT and cyber incident reporting, multi-year cyber exercises, FinCERT development, cyber skills assessment and annual cyber threat landscape reporting.

Operational resilience including incident management and reporting and business continuity management

Policy and guidance in this area treat operational resilience as the ability to maintain or restore critical services during disruption. The core expectation is that institutions know which services, operations or market functions matter most, understand the dependencies that support them, and define the level of disruption they can tolerate. Business continuity, disaster recovery and crisis management arrangements are expected to translate that understanding into workable recovery plans, fallback options, communication procedures and tested response capabilities. Incident management sits within this wider framework: firms are expected to escalate material disruptions, notify supervisors where required, provide structured updates, identify root causes and track remediation. Where critical services depend on third parties, firms are also expected to understand those dependencies and incorporate them into continuity planning, testing and reporting.

InternationalInternational Association of Insurance SupervisorsApplication Paper on operational resilience objectives and toolkit

The application paper provides an outcomes-based supervisory framework for embedding operational resilience into insurance governance, operational risk management and internal control arrangements, without creating new IAIS requirements. It frames resilience around the ability of insurers to identify critical services and interdependencies, set tolerances for disruption, and maintain arrangements to withstand, mitigate, recover and learn from operational disruptions. It also covers supervisory practices and tools for board and senior management oversight, critical service mapping, impact tolerances, scenario testing, lessons learned, incident management, technology risk, controlled change and third-party dependencies.

United KingdomPrudential Regulation AuthorityOperational incident and material third-party reporting policy

The policy establishes standardised reporting for operational incidents and material third-party arrangements across banks, building societies, PRA-designated investment firms, relevant branches and insurers. Firms are required to submit a single operational incident report that is updated across initial, intermediate and final phases, with initial reporting expected within 24 hours of determining that the reporting threshold has been met. The policy also requires material third-party notifications for new or significantly changed arrangements and annual register submissions for material third-party arrangements through aligned supervisory reporting platforms.

Dubai International Financial CentreDubai Financial Services AuthorityConsultation on operational resilience

The consultation proposes an operational resilience regime requiring Authorised Persons to carry out regular identification of critical business services, with Governing Body approval of the identification exercise. Firms with critical business services would be required to set impact tolerances, map the resources and dependencies needed to deliver those services, and test their ability to remain within tolerance under severe but plausible scenarios. The proposal also adds immediate notification to the DFSA where disruption to a critical business service breaches, or comes reasonably close to breaching, its impact tolerance.

OmanCentral Bank of OmanBusiness Continuity Management Framework

The framework requires licensed banks and finance and leasing companies to establish a board-approved business continuity management framework covering all activities, including those delivered through outsourcing and third-party arrangements. Institutions must identify critical business services, conduct business impact analysis and dependency mapping, set impact tolerances and SRTO/RTO/RPO metrics, and maintain business continuity, recovery, IT disaster recovery, cyber resilience and crisis management plans. The framework also adds testing, training, audit and reporting expectations, including incident reports, comprehensive post-incident reporting, BCM test reports, internal audit review and framework finalisation by 30 June 2026.

PhilippinesCentral Bank of the PhilippinesPeso RTGS incident management requirements

The amendments require Peso RTGS participants to coordinate with the Central Bank through official channels when connectivity or system-availability issues affect operational processes such as report generation, transaction monitoring or settlement notifications. Participant-originated incidents must be investigated immediately, handled under the participant’s internal incident management framework and reported to the Central Bank within one hour of discovery. The requirements also add continuity and fallback arrangements for unresolved issues, including BCP activation, alternative settlement mechanisms, secure transaction-file upload, on-behalf uploading and annual BCP testing.

MozambiqueBank of MozambiqueTechnology and cyber incident reporting templates

The circular requires credit institutions and financial companies to report technology and cyber incidents, and aggregated incident information, using prescribed templates and supervisory submission channels. Incident reports must classify incident type and severity, identify affected components and business, control or support areas, and record actions taken, service-provider involvement and operational, reputational and financial impact. Final reporting adds fields covering interruption duration, incident origin, entry vector, exposed vulnerabilities, internal escalation, crisis-management activation, investigation ownership and remediation or action plans.

Management of AI-enabled cyber risk

The AI-enabled cyber risk guidance translates concerns about faster vulnerability discovery and exploitation into practical expectations for cyber governance, prioritisation and control effectiveness. Notably, firms are expected to adapt cybersecurity controls to shorter vulnerability triage and remediation cycles, higher volumes of security updates and greater pressure on existing control environments. The requirements focus on current technology inventories, identification of externally exposed, business-critical and third-party-dependent systems, and prioritisation of remediation for assets that support critical services or client activity. Where vulnerabilities cannot be remediated immediately, firms are expected to rely on compensating controls that limit exposure and contain potential compromise. These include tighter access and privilege management, segmentation of networks and critical systems, stronger controls over external inputs and secure development practices, and enhanced detection and monitoring. The guidance also places emphasis on tested recovery arrangements, including reliable backups, pre-planned containment options and incident response procedures that can operate at the speed required. Governance and third-party oversight remain part of the same control environment: boards and senior executives are expected to understand exposure, resourcing and risk acceptance, while third-party expectations focus on whether firms can identify the external software, vendors and service providers that support business-critical systems, confirm that urgent fixes and support can be delivered quickly, monitor third-party code and applications for abnormal behaviour, and incorporate critical providers into response and recovery planning.

Hong KongSecurities and Futures CommissionEnhanced cybersecurity measures for AI-enabled cyberattacks

The circular requires licensed firms to maintain up-to-date technology asset inventories covering hardware, software, network infrastructure, databases and cloud services, with externally exposed, business-critical and third-party-dependent components identified for same-day prioritisation and containment decisions. Firms must enhance patching and vulnerability management, including prompt remediation of known vulnerabilities, urgent and critical fixes outside routine patching cycles and sufficient resources to handle higher patching demand. The circular also strengthens layered controls through least-privilege access, privileged-account safeguards, firewalls, micro-segmentation, adversarial treatment of external inputs, maker-checker controls, threat detection, third-party supply-chain assessments, tested incident response, backups and material-incident notification.

United StatesNew York State Department of Financial ServicesCybersecurity guidance for heightened threat environments

The guidance sets out additional cybersecurity measures for regulated entities to consider based on their information systems, supply-chain dependencies and usage, sector-specific risks and existing cybersecurity programme. It covers attack-surface controls, including remediation of known exploited vulnerabilities, disabling unnecessary ports and protocols, phishing-resistant MFA, stronger MFA enrolment controls, network access protections, segmentation, cloud configuration review, privileged-access review, secure programming and input validation. It also adds detection, readiness, resilience and response measures, including updated intrusion-prevention and detection tools, log and alert coverage, threat-intelligence review, third-party code monitoring, critical-provider engagement, backup restorability testing, recovery-time validation, threat-relevant incident response and business continuity procedures.

AustraliaAustralian Securities and Investments CommissionOpen letter on cyber resilience and frontier AI

The open letter asks licensees and market participants to reassess cyber plans, governance and escalation frameworks so that critical risks, cumulative vulnerabilities and decision-making responsibilities are prioritised and resourced. It covers execution of core cyber resilience controls, including critical-asset protection, control validation, reduced exposure to untrusted networks, user-access reviews, prompt patching, strengthened patch-management processes and layered defences. It also places board and senior executive focus on evidence-based assurance, proportionate capability and resourcing, meaningful reporting on end-to-end control effectiveness, tested incident response and continuity playbooks, third-party risk management, AI risk integration and defensive use of AI where appropriate.

Key sources