Current thematic dossiers

Select a theme to view its dossier.

Cyber & operational resilience

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

Overview

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

  1. EuropeFranceFrance Autorite des marches financiersSupervision

    France's Financial Markets Authority publishes lessons from SPOT inspections of asset managers’ operational risk management

    France's Financial Markets Authority (AMF) released findings from a SPOT inspection of portfolio management companies, revealing established governance but recurring gaps in loss measurement, incident assessment, and reporting quality. The review noted good practices like setting maximum tolerable risk impacts and poor practices such as non-harmonised incident registers and inadequate consideration of operational risks in outsourcing decisions.

  2. AsiaBrunei DarussalamCentral Bank of Brunei DarussalamCooperation

    Central Bank of Brunei Darussalam collaborates with Brunei Association of Banks to strengthen ATM controls after card-skimming incidents

    The Central Bank of Brunei Darussalam is collaborating with the Brunei Association of Banks to enhance security controls following ATM card-skimming incidents, emphasizing robust fraud prevention and response mechanisms. Expected actions include regular ATM inspections and enhanced monitoring, with banks implementing preventive measures and advising consumers on vigilance against unauthorized transactions.

  3. EuropePortugalPortuguese Securities Commission (CMVM)Strategy and priorities

    Portuguese Securities Commission publishes 2026 action priorities targeting crypto-asset supervision, digital resilience and investor fraud prevention

    The Portuguese Securities Commission (CMVM) outlined its 2026 priorities, focusing on supervisory, regulatory, and internal workstreams aligned with its 2025–2028 Strategic Plan. Key areas include enhanced supervision of high-risk sectors like crypto-assets and Digital Operational Resilience Act (DORA) compliance, corporate governance reviews, and AML/CFT risk management. The CMVM also aims to bolster investor protection against digital fraud, expand financial tools, and propose a regulatory sandbox for capital market development.

  4. PacificAustraliaAustralian Securities & Investments CommissionEvents and speeches

    Australian Securities and Investments Commission sets 2026 superannuation enforcement priorities and flags weak trustee complaints and scams controls

    The Australian Securities and Investments Commission (ASIC) outlined its 2026 priorities for the superannuation sector, focusing on governance, skills, and operations. Key areas include member service failures, scams, cyber risk, and retirement delivery. ASIC will address trustees' complaints analysis, scam communication, death benefits review recommendations, harmful switching behavior, market transparency, financial reporting, and enforce against poor private credit practices and fund collapses.

  5. PacificAustraliaAustralian Prudential Regulation AuthorityEvents and speeches

    Australian Prudential Regulation Authority signals heightened 2026 scrutiny of superannuation trustees and continued use of licence conditions

    The Australian Prudential Regulation Authority's Deputy Chair, Margaret Cole, emphasized an intensified supervisory focus on enhancing superannuation trustee standards in operational risk management, cyber controls, and investment governance to bolster fund resilience and safeguard retirement savings. APRA will maintain scrutiny on governance shortcomings and employ stricter licence conditions to address deficiencies promptly.

  6. EuropeEuropeEuropean Central BankEvents and speeches

    European Central Bank outlines supervisory approach to AI, tokenisation and operational resilience in banks’ digital transformation

    In a keynote speech, European Central Bank Supervisory Board member Patrick Montagner emphasized the need for banks to balance digital innovation with governance and risk controls, particularly in AI, tokenisation, and cybersecurity. The ECB highlighted AI's widespread use among banks, systemic concentration risks, and the importance of frameworks like the Digital Operational Resilience Act for managing digital risks, with plans to continue monitoring AI and third-party dependencies in 2026.

  7. AsiaHong KongHong Kong Monetary AuthorityProjects and initiatives

    Hong Kong Monetary Authority publishes Fintech Promotion Blueprint under Fintech 2030 with four flagship projects on AI DLT and quantum readiness

    The Hong Kong Monetary Authority has released a Fintech Promotion Blueprint to advance AI and distributed ledger technologies, emphasizing data excellence and cyber resilience. The plan includes four flagship projects: a Quantum Preparedness Index, a New Risk Data Strategy, a Fintech Cybersecurity Baseline, and competency development for AI and DLT-enabled financial services.

  8. EuropeNetherlandsDe Nederlandsche BankEvents and speeches

    De Nederlandsche Bank warns Europe’s digital dependence is a systemic risk and urges vault lines to strengthen financial-sector resilience

    De Nederlandsche Bank's Steven Maijoor highlighted Europe's growing reliance on a few IT service providers, particularly cloud hyperscalers, as a systemic risk to the financial system. He advocated for stronger structures and partnerships to reduce digital dependence, urging financial institutions to prepare for potential disruptions and suggesting long-term strategies to decrease reliance on non-European providers.

  9. EuropeEuropeEuropean Insurance and Occupational Pensions AuthoritySupervision

    European Insurance and Occupational Pensions Authority finds European insurance risks stable at a medium level in January 2026 Insurance Risk Dashboard

    The European Insurance and Occupational Pensions Authority's January 2026 Insurance Risk Dashboard indicates that risks in the European insurance sector remain stable at a medium level, despite geopolitical tensions affecting the macroeconomic and market risk outlook. The sector is supported by solid capital positions, stable profitability, and strong premium growth, with vigilance required for geopolitical, trade disruption, and cyber risks.

  10. EuropeRussiaCentral Bank of RussiaPolicy and regulation

    Central Bank of Russia issues new information security requirements for socially important card payment systems

    The Central Bank of Russia has issued updated requirements for hardware and software in socially important card payment systems, focusing on information security for infrastructure components like hardware security modules, payment devices, ATMs, and payment cards. These new parameters replace the 2020 approaches and aim to enhance data protection and support import substitution.

  11. GlobalGlobalInternational Association of Insurance SupervisorsStrategy and priorities

    International Association of Insurance Supervisors publishes Roadmap 2026-2027 and targets November 2026 adoption of new ICS reporting and disclosure standards

    The International Association of Insurance Supervisors (IAIS) released its Roadmap 2026-2027, focusing on standard setting, implementation support, and supervisory cooperation. Priorities include monitoring life insurance sector changes and finalizing Insurance Capital Standard (ICS) standards for Internationally Active Insurance Groups by November 2026. The roadmap addresses climate metrics, digital innovation, and cyber risk, with a new committee structure effective January 2026 and deadlines for comments on draft standards set for February 2026.

  12. GlobalGlobalBank for International Settlements - Innovation HubProjects and initiatives

    Bank for International Settlements Innovation Hub publishes Project FuSSE findings on modular settlement engine scalability and quantum readiness

    The Bank for International Settlements Innovation Hub released a report on Project FuSSE, a proof-of-concept for a modular, microservices-based settlement engine architecture aimed at enhancing scalability, adaptability, and cyber resilience in financial market infrastructures. The report discusses the potential benefits and operational trade-offs, including processing up to 10,000 transactions per second and integrating post-quantum cryptography, while noting the project's experimental nature and lack of production-ready components.

  13. EuropeGermanyBaFinSupervision

    Germany's Federal Financial Supervisory Authority publishes Risks in Focus 2026 warning of high potential for sudden market corrections

    Germany's Federal Financial Supervisory Authority (BaFin) released its Risks in Focus 2026 assessment, highlighting elevated market valuations and a fragile backdrop as threats to financial stability, including abrupt market corrections and consumer over-indebtedness. BaFin's supervisory priorities for 2026 include intensified monitoring of credit risk, scrutiny of banks' linkages with non-bank intermediaries, and stricter oversight of consumer lending compliance.

  14. EuropeMoldovaNational Bank of MoldovaStrategy and priorities

    National Bank of Moldova sets 2026-2027 insurance supervision priorities focused on governance, underwriting, solvency and ICT risk

    The National Bank of Moldova outlined its supervisory priorities for the insurance sector for 2026-2027, focusing on governance, underwriting risk, solvency and asset sufficiency, and information and communications technology risk. This agenda is driven by an annual risk assessment and considers the partial liberalisation of mandatory motor third-party liability pricing.

  15. Latin AmericaChileChile Financial Market CommissionPolicy and regulation

    Chile Financial Market Commission opens second consultation on service externalization requirements for insurance and reinsurance companies

    The Chile Financial Market Commission has released a revised draft regulation for a second consultation, detailing principles and requirements for insurance and reinsurance companies on service externalization. The proposal clarifies requirements, applies proportionality based on entity size, complexity, and risk profile, enhances the supervisory framework, and aligns with General Rule No. 454 on operational risk management and cybersecurity.

  16. AsiaVietnamState Bank of VietnamStrategy and priorities

    State Bank of Vietnam issues 2026 directive to accelerate banking digital transformation and mandate stronger information security controls

    The State Bank of Vietnam issued Directive No. 02/CT-NHNN outlining 2026 priorities for digital transformation and enhanced information security in the banking sector, mandating at least 15% of budgets for cybersecurity. It emphasizes senior accountability, periodic training, proactive risk management, and strengthened cybersecurity networks, applying to SBV units, credit institutions, foreign bank branches, and related service providers.

  17. EuropeNetherlandsDutch Authority for the Financial MarketsSupervision

    Dutch Authority for the Financial Markets sets 2026 supervision priorities on DORA cyber resilience responsible AI and financial crime

    The Dutch Authority for the Financial Markets has released its Agenda 2026, emphasizing enhanced supervision of digital operational resilience, responsible artificial intelligence use, and financial crime prevention. Key initiatives include intensified oversight of AI risks, strengthened digital resilience under the Digital Operational Resilience Act, and coordinated actions against investment fraud and money laundering.

  18. EuropeItalyBank of ItalyResearch

    Bank of Italy publishes research building a cyber risk vulnerability indicator for Italian non-financial firms

    The Bank of Italy's study, “The Cyber Risk of Non-Financial Firms,” introduces an indicator for assessing cyber risk in Italian non-financial companies, advocating its inclusion in credit risk assessments. Using natural language processing and a large language model to analyze financial statements, news, and cyber reports, it reveals increased cyberattacks in Italy since 2019, with post-incident vulnerability often surpassing defensive benefits.

  19. EuropeUnited KingdomPrudential Regulation AuthorityStrategy and priorities

    Prudential Regulation Authority sets 2026 supervisory priorities for UK deposit takers and plans wider shift to two-year periodic summary meeting cycles

    The Prudential Regulation Authority has written to CEOs of PRA-regulated UK banks and building societies setting out its 2026 supervisory priorities, emphasising strategic risk management, operational and financial resilience, data risk, and support for innovation aligned with its secondary objectives on competition, international competitiveness and growth. Key expectations include enhanced oversight of changing risk profiles, implementation of updated significant risk transfer and model risk management standards, strengthened operational resilience and cyber preparedness, and preparation for Basel 3.1 and the Strong and Simple Framework. The PRA will also rebase variable Pillar 2 requirements in 2026 and continue modernising reporting and authorisation processes.

  20. EuropeUnited KingdomPrudential Regulation AuthorityStrategy and priorities

    United Kingdom's Prudential Regulation Authority sets 2026 insurance supervision priorities and plans move to two-year Periodic Summary Meetings

    The UK Prudential Regulation Authority has set 2026 supervisory priorities for insurers, focusing on resilience and risk management amid competitive pressures in the bulk purchase annuity market, a softening general insurance underwriting cycle, and the need to strengthen operational resilience. Life insurance supervision will centre on pricing discipline, funded reinsurance and liquidity and credit risks in evolving investment strategies, while general insurers face closer scrutiny of underwriting, reserving, internal model assumptions, exposure data and delegated authority oversight. Cross-sector work will intensify on operational resilience testing, third-party risk, legacy technology, cyber risk and AI governance.

  21. EuropeUnited KingdomPrudential Regulation AuthorityStrategy and priorities

    United Kingdom's Prudential Regulation Authority sets 2026 supervisory priorities for UK-active international banks and plans move to two-year PSM cycle

    The Prudential Regulation Authority has written to chief executives of PRA-regulated international banks and designated investment firms in the UK setting out its 2026 supervisory priorities, emphasising risk management and governance, operational and financial resilience, and data risk, while adjusting supervision to support innovation and reduce regulatory burden. Key expectations include stronger counterparty credit and model risk management, prudent adoption of technologies such as artificial intelligence and distributed ledger technology, enhanced operational resilience and cyber capabilities, and preparations for Basel 3.1 and the Strong and Simple Framework. The PRA will also move remaining firms from annual to two-year Periodic Summary Meeting cycles in 2026 and is encouraging engagement on streamlined reporting and regulatory permissions ahead of capital regime changes.

  22. AfricaMozambiqueBank of MozambiqueData and reporting

    Bank of Mozambique mandates standard templates and channels for technology and cyber incident reporting effective 9 March 2026

    The Bank of Mozambique issued a circular mandating the use of specific reporting templates for technological and cyber incidents by credit institutions and financial companies. Reports must be submitted primarily via the Banking Supervision Application portal, detailing incident type, severity, impacts, and remediation actions. Email reporting is permitted only when other channels are unavailable.

  23. North AmericaCanadaCanadian Investment Regulatory OrganizationData and reporting

    Canadian Investment Regulatory Organization confirms phishing breach impacted around 750,000 investors and begins notifications with credit monitoring

    The Canadian Investment Regulatory Organization (CIRO) confirmed a phishing attack affecting data of approximately 750,000 Canadian investors, with no evidence of misuse. CIRO is offering credit monitoring and identity theft protection, has secured systems, and will notify affected individuals starting January 14, 2026.

  24. EuropeUnited KingdomBank of EnglandCooperation

    Bank of England and UK regulators sign MoU with European Supervisory Authorities on oversight of critical third parties

    The Bank of England, Financial Conduct Authority, and Prudential Regulation Authority signed a Memorandum of Understanding with European Supervisory Authorities to enhance cross-border cooperation on overseeing critical third parties under the UK's regime and the EU's Digital Operational Resilience Act. This framework aims to manage risks to financial stability and market confidence while minimizing regulatory burdens for third-party providers operating across jurisdictions.

  25. GlobalGlobalWorld Federation of ExchangesOther

    World Federation of Exchanges calls on regulators to balance post-quantum cryptography expectations with immediate AI and cyber resilience risks

    The World Federation of Exchanges (WFE) highlighted a gap between regulatory and industry expectations on quantum computing risk preparedness, urging regulators to align post-quantum cryptography migration with immediate threats. A WFE survey revealed members prioritize generative AI risks over quantum preparedness, estimating a 5–10+ year window before quantum computers become a threat, while taking preparatory steps like monitoring developments and conducting risk assessments.