Overview
Since the start of 2026, supervisory practices in relation to cyber and operational resilience have focused on strengthening cooperation and crisis coordination, improving information sharing, building practical cyber resilience capacity and equipping supervisors with more structured tools for cyber and operational resilience supervision.
What's new
Argentina's National Securities Commission Vice President Sonia Salvatierra outlined the regulator’s cyberfraud prevention priorities, including stronger supervision, transparency, investor protection and financial education. She emphasized coordination with the Financial Intelligence Unit, the Central Bank of Argentina and the private sector.
The National Bank of the Kyrgyz Republic participated in the first meeting of an interagency commission on information security and cybersecurity. The initiative covers threat assessment, rapid information sharing and stronger coordination to protect financial infrastructure and information systems.
The National Bank of the Kyrgyz Republic joined the first meeting of an interagency commission on information security and cybersecurity. The work covers threat assessment, rapid information sharing and stronger coordination to protect financial infrastructure and information systems.
Deep dive
Cooperation
Authorities have formalised cooperation across jurisdictions and between supervisors, public authorities and private sector partners. This includes ongoing supervisory cooperation as well as crisis coordination arrangements that clarify roles, escalation routes, contingency planning and communication during severe ICT or cyber incidents.
European Supervisory Authorities and UK financial regulators signed a memorandum of understanding setting out cooperation and coordination procedures for the oversight of EU critical ICT third-party providers and UK critical third parties. The MoU establishes a framework for coordination and information sharing, including during incidents such as power outages or cyberattacks.
National Bank of Ukraine and Mastercard signed a memorandum of understanding covering joint cybersecurity initiatives, international cyber protection standards, cyber threat data and analytical insights, and the resilience of Ukraine’s financial sector.
Japan Financial Services Agency established a public-private working group involving financial institutions, IT vendors, industry associations, the Bank of Japan, the National Cyber Office and other public authorities. Its mandate includes developing a shared understanding of AI-related cyber threats, examining countermeasures and strengthening financial-sector preparedness.
Norway's Finanstilsynet adopted a new mandate for the Financial Infrastructure Emergency Committee, clarifying its role in severe ICT incidents and crises. The Committee is a sector coordination forum for alerts, information sharing, contingency planning, crisis management and annual exercises that brings together public and private sector participants including observers from telco, power and national security bodies.
European Union / United Kingdom
European Supervisory Authorities and UK financial regulators signed a memorandum of understanding setting out cooperation and coordination procedures for the oversight of EU critical ICT third-party providers and UK critical third parties. The MoU establishes a framework for coordination and information sharing, including during incidents such as power outages or cyberattacks.
Ukraine
National Bank of Ukraine and Mastercard signed a memorandum of understanding covering joint cybersecurity initiatives, international cyber protection standards, cyber threat data and analytical insights, and the resilience of Ukraine’s financial sector.
Japan
Japan Financial Services Agency established a public-private working group involving financial institutions, IT vendors, industry associations, the Bank of Japan, the National Cyber Office and other public authorities. Its mandate includes developing a shared understanding of AI-related cyber threats, examining countermeasures and strengthening financial-sector preparedness.
Norway
Norway's Finanstilsynet adopted a new mandate for the Financial Infrastructure Emergency Committee, clarifying its role in severe ICT incidents and crises. The Committee is a sector coordination forum for alerts, information sharing, contingency planning, crisis management and annual exercises that brings together public and private sector participants including observers from telco, power and national security bodies.
Capacity building
Authorities have expanded specialist training and practical exercises to strengthen cyber skills, incident response and recovery.
Central Bank of Kuwait launched an Advanced Cybersecurity Leaders Program for experienced professionals, covering cloud security, threat detection and security architecture and providing a pathway to GIAC certification.
Central Bank of Uzbekistan and Mastercard delivered cyber-crisis training for central bank and commercial bank staff, using practical exercises and simulations to practise decision-making, coordination, impact mitigation, data security, business continuity and system recovery.
Kuwait
Central Bank of Kuwait launched an Advanced Cybersecurity Leaders Program for experienced professionals, covering cloud security, threat detection and security architecture and providing a pathway to GIAC certification.
Uzbekistan
Central Bank of Uzbekistan and Mastercard delivered cyber-crisis training for central bank and commercial bank staff, using practical exercises and simulations to practise decision-making, coordination, impact mitigation, data security, business continuity and system recovery.
Information sharing
Authorities have introduced more structured channels for exchanging cyber threat intelligence, incident-related information and supervisory data that can support a more system-wide view of cyber and operational resilience.
FINRA launched the Financial Intelligence Fusion Center, a secure portal through which FINRA and member firms can share cybersecurity and fraud intelligence and coordinate responses. The portal is intended to collect, analyze and dissemintate threat intelligence.
Bank of Italy and the Guardia di Finanza signed an agreement on cybersecurity information sharing and cooperation to strengthen prevention and protection against cyberattacks.
United States
FINRA launched the Financial Intelligence Fusion Center, a secure portal through which FINRA and member firms can share cybersecurity and fraud intelligence and coordinate responses. The portal is intended to collect, analyze and dissemintate threat intelligence.
Italy
Bank of Italy and the Guardia di Finanza signed an agreement on cybersecurity information sharing and cooperation to strengthen prevention and protection against cyberattacks.
Supervisory toolkits
Alongside these measures, 2026 has also seen the release of several new supervisory toolkits, intended to support authorities in structuring and carrying out cyber and operational resilience supervision.
- IMF published a good practices report that consolidates lessons from its cyber risk regulation and supervision work and sets out practical guidance for financial sector authorities on regulatory framework design, supervisory governance, offsite and onsite supervision, thematic reviews, cybersecurity testing, cyber simulation exercises, and monitoring system-wide cyber risk, including risks involving FMIs and critical third-party service providers.
- International Association of Insurance Supervisors (IAIS) published its Application Paper on operational resilience objectives and toolkit for the insurance sector. The paper combines operational resilience objectives with a toolkit of practices identified through an IAIS member survey, designed to help supervisors consider practical implementation approaches suited to their own market context.
- Basel Committee on Banking Supervision published a range of practices report on ICT risk management, focused on non-malicious ICT incidents affecting banks’ critical operations and services. The report identifies observed bank practices and regulatory and supervisory approaches across jurisdictions, and is intended to serve as a reference point for banks and supervisory authorities adapting ICT risk management and operational resilience practices to their circumstances.
Global
IMF published a good practices report that consolidates lessons from its cyber risk regulation and supervision work and sets out practical guidance for financial sector authorities on regulatory framework design, supervisory governance, offsite and onsite supervision, thematic reviews, cybersecurity testing, cyber simulation exercises, and monitoring system-wide cyber risk, including risks involving FMIs and critical third-party service providers.
Global
International Association of Insurance Supervisors (IAIS) published its Application Paper on operational resilience objectives and toolkit for the insurance sector. The paper combines operational resilience objectives with a toolkit of practices identified through an IAIS member survey, designed to help supervisors consider practical implementation approaches suited to their own market context.
Global
Basel Committee on Banking Supervision published a range of practices report on ICT risk management, focused on non-malicious ICT incidents affecting banks’ critical operations and services. The report identifies observed bank practices and regulatory and supervisory approaches across jurisdictions, and is intended to serve as a reference point for banks and supervisory authorities adapting ICT risk management and operational resilience practices to their circumstances.