Current thematic dossiers

Select a theme to view its dossier.

Cyber & operational resilience

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

Overview

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

  1. EuropeUnited KingdomPrudential Regulation AuthorityPolicy and regulation

    United Kingdom's Prudential Regulation Authority finalises operational incident and material third-party reporting rules effective 18 March 2027 and exempts credit unions under GBP 50 million

    The Prudential Regulation Authority (PRA), with the Financial Conduct Authority and the Bank of England, has finalized its policy on standardized reporting for operational incidents and material third-party arrangements. Effective March 2027, UK financial institutions must report incidents via FCA Connect and submit annual MTP registers, excluding certain credit unions and third-country branches. The rules aim to streamline data collection, reduce firm burden, and enhance supervisory consistency.

  2. EuropeEuropeEuropean Payments CouncilPolicy and regulation

    European Payments Council updates its guidelines on cryptographic algorithms usage and key management

    The European Payments Council has released its annual update to the Guidelines on cryptographic algorithms usage and key management, offering updated guidance on security protocols and key management practices for the European payments industry. The guidelines target payment service providers, including security officers and system designers, ensuring alignment with current cryptology research and development.

  3. EuropeGermanyBaFinData and reporting

    Germany's Federal Financial Supervisory Authority clarifies fluctuation reserve treatment for standalone cyber insurance and allows early build-up with seven-year data

    Germany's Federal Financial Supervisory Authority (BaFin) issued guidance on the fluctuation reserve for standalone cyber insurance, to be separately reported from 2025. BaFin states there is no obligation to build a cyber fluctuation reserve for 2025 due to the lack of a ten-year observation period for loss-ratio calculations. Insurers may apply for case-by-case approval to establish a reserve earlier, subject to specific criteria, while BaFin published net loss ratios and gross expense ratios for 2020-2024.

  4. EuropeUkraineNational Bank of UkraineCooperation

    National Bank of Ukraine signs memorandum with Mastercard to strengthen financial sector cyber resilience

    The National Bank of Ukraine (NBU) and Mastercard signed a Memorandum of Understanding to enhance cybersecurity cooperation, aiming to bolster Ukraine's financial sector's cyber resilience. The partnership will focus on promoting cybersecurity best practices, data exchange on cyber threats, and building competencies in threat prevention and response. This initiative aligns with Mastercard's Digital Country Partnership program in Ukraine.

  5. EuropeEuropeEuropean Securities and Markets AuthoritySupervision

    European Securities and Markets Authority warns of elevated systemic stress risks in its first 2026 risk monitoring report

    The European Securities and Markets Authority (ESMA) released its first 2026 risk monitoring report, indicating high market and systemic stress risks in EU financial markets despite resilient late 2025 performance. The report highlights potential significant price swings due to geopolitical tensions, stretched equity valuations, and an uncertain EU economic outlook, with increased contagion risk from higher cross-asset correlations and cyber threats. It also notes record-high global equity valuations, mixed credit-quality signals, persistent weakness in EU equity issuance, a crypto flash crash, and settlement-fail spikes at central securities depositories.

  6. EuropeNetherlandsDe Nederlandsche BankStrategy and priorities

    Netherlands' De Nederlandsche Bank publishes Payments Strategy 2026-2028 urging 72-hour cash buffers and more European payment options

    De Nederlandsche Bank (DNB) released its Payments Strategy 2026-2028, focusing on secure, reliable, and accessible payments amid geopolitical and technological changes. Priorities include enhancing operational resilience, reducing reliance on non-European providers, and promoting European digital payment instruments like Wero and the digital euro. The strategy emphasizes collaboration with banks, businesses, and civil society to ensure offline payment capabilities, maintain ATM availability, and bolster cybersecurity.

  7. EuropeGibraltarGibraltar Financial Services CommissionSupervision

    Gibraltar Financial Services Commission publishes thematic review findings and minimum expectations for TCSP cybersecurity data protection and resilience

    The Gibraltar Financial Services Commission released findings from its thematic review on cybersecurity, data protection, and resilience in the Trust and Corporate Service Providers sector, establishing minimum standards. The review highlights areas for improvement in governance, risk management, and resilience planning to help firms align with international standards and maintain robust controls.

  8. AfricaAfricaGABACProjects and initiatives

    Action Group against Money Laundering in Central Africa validates draft regional regulation on information systems security for financial intelligence units

    The Action Group against Money Laundering in Central Africa held a workshop in Brazzaville to draft a regional text on network and information system security for financial intelligence units. Participants validated a draft regulation and agreed on a roadmap for its integration into the Economic and Monetary Community of Central Africa process. The workshop addressed legal, technical, and operational aspects to enhance cybersecurity and network resilience.

  9. AsiaJapanJapan Financial Services AgencySupervision

    Japan Financial Services Agency applies revised supervisory guidelines to strengthen cyber risk response

    The Japan Financial Services Agency finalized revisions to its Comprehensive Supervisory Guidelines to enhance firms' cyber risk responses, effective 27 February 2026. The revisions, following a public consultation, cover major banks, small and medium-sized financial institutions, affiliated institutions, and the fishermen’s cooperative system credit business, including guidance on electronic payment instruments. Feedback not directly related to the revisions will inform future financial administration.

  10. EuropeIrelandCentral Bank of IrelandStrategy and priorities

    Central Bank of Ireland publishes Regulatory and Supervisory Outlook 2026 prioritising operational resilience as market and AI risks rise

    The Central Bank of Ireland's Regulatory & Supervisory Outlook 2026 highlights high operational, asset valuation, and market risks, with reduced inflation and interest rate risks. It emphasizes supervisory priorities like operational and cyber resilience, consumer protection, and technological adaptation, aiming to enhance regulatory efficiency through an integrated supervisory approach and improved gatekeeping processes.

  11. Middle EastUnited Arab EmiratesCentral Bank of the UAEProjects and initiatives

    Central Bank of the UAE partners with Core42 to build a sovereign financial cloud services infrastructure

    The Central Bank of the UAE has partnered with Core42 to develop the Sovereign Financial Cloud Services Infrastructure, the first dedicated financial cloud ecosystem. Part of the Financial Infrastructure Transformation programme, it aims to enhance data sovereignty, cybersecurity, and operational agility for the UAE financial sector. The platform will incorporate AI and advanced analytics for intelligent automation and real-time data analysis, offering a unified framework for managing multi-cloud services.

  12. EuropeEuropeEuropean Central BankEvents and speeches

    European Central Bank sets supervisory expectations for banks’ AI governance and signals more targeted scrutiny of generative AI

    In a keynote speech, ECB Banking Supervision emphasized its focus on banks' increasing use of artificial intelligence, particularly generative AI, due to dependencies on third-party providers and cloud infrastructure. The ECB highlighted uneven governance practices and stressed the need for senior management oversight and alignment with European Banking Authority principles. Looking ahead, the ECB plans to intensify monitoring of AI, focusing on generative AI applications, under its 2026-28 supervisory priorities on operational resilience and ICT capabilities.

  13. PacificNew ZealandNew Zealand Financial Markets AuthorityProjects and initiatives

    New Zealand Financial Markets Authority publishes operational resilience thematic review findings for peer-to-peer lending and crowdfunding providers

    The New Zealand Financial Markets Authority (FMA) released findings from its operational resilience thematic review, based on voluntary surveys of peer-to-peer lending platforms and crowdfunding service providers. The review assessed resilience maturity, identified risks, and provided recommendations for improvement, aligning with the FMA's 2025 Financial Conduct Report.

  14. EuropeEuropeEuropean Banking AuthorityPeer reviews and country evaluations

    European Banking Authority follow-up peer review reports progress in ICT risk assessment under SREP and urges further supervisory convergence under DORA

    The European Banking Authority's follow-up peer review highlights improvements in EU authorities' ICT risk assessment within the Supervisory Review and Evaluation Process, attributed to the Digital Operational Resilience Act. Despite progress, the report calls for further investment to ensure consistent ICT risk supervision across the EU. It urges authorities to fully integrate ICT risk methodologies and enhance supervisory convergence and operational resilience.

  15. North AmericaUnited StatesU.S. Department of the TreasuryProjects and initiatives

    U.S. Department of the Treasury concludes AI cybersecurity initiative and will release six risk management resources for financial services

    The U.S. Department of the Treasury concluded a public-private initiative to enhance cybersecurity and risk management for artificial intelligence in the financial sector. Led by the Artificial Intelligence Executive Oversight Group, the initiative will produce six resources focusing on governance, data practices, transparency, fraud, and digital identity, aimed at supporting secure AI use, particularly for small and mid-sized institutions.

  16. AsiaPakistanState Bank of PakistanProjects and initiatives

    State Bank of Pakistan launches Cyber Shield cyber resilience strategy for regulated entities

    The State Bank of Pakistan has launched "Cyber Shield – the Cyber Resilience Strategy for Regulated Entities" to enhance cyber resilience in banks and financial institutions. The strategy focuses on prevention, rapid response, and recovery from cyber incidents, prioritizing governance, cooperation, talent development, and updated security practices. The State Bank will monitor cyber developments and update the strategy to address emerging threats.

  17. EuropeSpainSpanish Securities Commission (CNMV)Policy and regulation

    Spanish Securities Commission publishes 74-question FAQ on the Digital Operational Resilience Act

    The Spanish Securities Commission (CNMV) released a FAQ document on Regulation (EU) 2022/2554, the Digital Operational Resilience Act (DORA), to guide financial entities on applying the framework and cybersecurity standards. The document addresses 74 questions on DORA’s pillars, emphasizing proportionality based on entity size, risk profile, and service complexity, and includes a CNMV channel for DORA-related inquiries.

  18. GlobalGlobalInternational Association of Insurance SupervisorsPolicy and regulation

    International Association of Insurance Supervisors publishes final Application Paper on operational resilience objectives and toolkit

    The International Association of Insurance Supervisors published its final Application Paper on operational resilience, setting out outcomes-based objectives and a practical toolkit to help supervisors and insurers embed resilience expectations within existing Insurance Core Principles governance and risk management frameworks, including oversight, operational risk integration, and third-party/technology dependencies.

  19. EuropeLuxembourgLuxembourg Commission de Surveillance du Secteur FinancierData and reporting

    Luxembourg Commission de Surveillance du Secteur Financier sets 2026 DORA register of information submission process and extends filing to third-country branches

    The Luxembourg CSSF has issued instructions for the 2026 submission of the DORA register, covering ICT service arrangements for entities not under ECB supervision. Third-country branches must submit their register by 31 December 2025 via the CSSF’s eDesk Portal, with validation checks on additional data fields. Entities are advised to submit early for corrections.

  20. AfricaAlgeriaAlgeria Market Authority (COSOB)Projects and initiatives

    Algeria Market Authority installs governance committee for Algerian FinTech Academy

    The Algeria Market Authority has set up the governance committee for the Algerian Financial Technology Academy with the Banking Training Institute. The committee will direct the academy's strategy, oversee training in digital finance and cybersecurity, and link established market participants with FinTech innovators.

  21. EuropeLuxembourgLuxembourg Commission de Surveillance du Secteur FinancierAlert and warning

    Luxembourg Commission de Surveillance du Secteur Financier warns supervised entities of active Ivanti EPMM remote code execution exploits and reminds incident notification duties

    The Luxembourg Commission de Surveillance du Secteur Financier (CSSF) issued an alert about vulnerabilities CVE-2026-1281 and CVE-2026-1340 in Ivanti Endpoint Manager Mobile (EPMM), enabling unauthenticated remote code execution. The CSSF urged entities using EPMM to follow guidance and implement mitigating actions, emphasizing severe server compromise risks. Entities were reminded to report such incidents under relevant CSSF Circulars.

  22. AsiaJapanJapan Financial Services AgencyProjects and initiatives

    Japan Financial Services Agency launches consultation on draft policy to strengthen cybersecurity in crypto asset exchange businesses

    Japan's Financial Services Agency has released a draft policy to enhance cybersecurity in the crypto asset exchange sector, addressing recent cyberattacks and asset outflows. The policy promotes operator-led security initiatives, industry mutual assistance, and public support measures, with public comments open until 11 March 2026.

  23. GlobalGlobalIOSCOStrategy and priorities

    International Organization of Securities Commissions publishes 2026 work program prioritising market resilience, investor protection and technological transformation

    The International Organization of Securities Commissions (IOSCO) released its 2026 Work Program, highlighting five priorities: financial resilience, investor protection, market evolution, technological transformation, and regulatory cooperation. Key initiatives include reviewing IOSCO principles, over-the-counter derivatives, and operational resilience. IOSCO will focus on investor protection via a TechSprint with the UK Financial Conduct Authority and develop crypto and digital assets assessment methodologies.

  24. EuropeItalyBank of ItalyEvents and speeches

    Bank of Italy presents 2025 findings and operational guidance on DORA Registers of Information for ICT third party risk

    The Bank of Italy hosted a workshop in Rome with financial sector associations on digital operational resilience, focusing on ICT third party risk and the Registers of Information under EU Regulation 2022/2554 on Digital Operational Resilience (DORA). The event aimed to enhance awareness of register data quality and completeness, emphasizing the need for strong governance and periodic supplier assessments.