What's new
Overview
This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.
What's new
France's Financial Markets Authority publishes lessons from SPOT inspections of asset managers’ operational risk management
France's Financial Markets Authority (AMF) released findings from a SPOT inspection of portfolio management companies, revealing established governance but recurring gaps in loss measurement, incident assessment, and reporting quality. The review noted good practices like setting maximum tolerable risk impacts and poor practices such as non-harmonised incident registers and inadequate consideration of operational risks in outsourcing decisions.
Central Bank of Brunei Darussalam collaborates with Brunei Association of Banks to strengthen ATM controls after card-skimming incidents
The Central Bank of Brunei Darussalam is collaborating with the Brunei Association of Banks to enhance security controls following ATM card-skimming incidents, emphasizing robust fraud prevention and response mechanisms. Expected actions include regular ATM inspections and enhanced monitoring, with banks implementing preventive measures and advising consumers on vigilance against unauthorized transactions.
Portuguese Securities Commission publishes 2026 action priorities targeting crypto-asset supervision, digital resilience and investor fraud prevention
The Portuguese Securities Commission (CMVM) outlined its 2026 priorities, focusing on supervisory, regulatory, and internal workstreams aligned with its 2025–2028 Strategic Plan. Key areas include enhanced supervision of high-risk sectors like crypto-assets and Digital Operational Resilience Act (DORA) compliance, corporate governance reviews, and AML/CFT risk management. The CMVM also aims to bolster investor protection against digital fraud, expand financial tools, and propose a regulatory sandbox for capital market development.
Australian Securities and Investments Commission sets 2026 superannuation enforcement priorities and flags weak trustee complaints and scams controls
The Australian Securities and Investments Commission (ASIC) outlined its 2026 priorities for the superannuation sector, focusing on governance, skills, and operations. Key areas include member service failures, scams, cyber risk, and retirement delivery. ASIC will address trustees' complaints analysis, scam communication, death benefits review recommendations, harmful switching behavior, market transparency, financial reporting, and enforce against poor private credit practices and fund collapses.
Australian Prudential Regulation Authority signals heightened 2026 scrutiny of superannuation trustees and continued use of licence conditions
The Australian Prudential Regulation Authority's Deputy Chair, Margaret Cole, emphasized an intensified supervisory focus on enhancing superannuation trustee standards in operational risk management, cyber controls, and investment governance to bolster fund resilience and safeguard retirement savings. APRA will maintain scrutiny on governance shortcomings and employ stricter licence conditions to address deficiencies promptly.
European Central Bank outlines supervisory approach to AI, tokenisation and operational resilience in banks’ digital transformation
In a keynote speech, European Central Bank Supervisory Board member Patrick Montagner emphasized the need for banks to balance digital innovation with governance and risk controls, particularly in AI, tokenisation, and cybersecurity. The ECB highlighted AI's widespread use among banks, systemic concentration risks, and the importance of frameworks like the Digital Operational Resilience Act for managing digital risks, with plans to continue monitoring AI and third-party dependencies in 2026.
Hong Kong Monetary Authority publishes Fintech Promotion Blueprint under Fintech 2030 with four flagship projects on AI DLT and quantum readiness
The Hong Kong Monetary Authority has released a Fintech Promotion Blueprint to advance AI and distributed ledger technologies, emphasizing data excellence and cyber resilience. The plan includes four flagship projects: a Quantum Preparedness Index, a New Risk Data Strategy, a Fintech Cybersecurity Baseline, and competency development for AI and DLT-enabled financial services.
De Nederlandsche Bank warns Europe’s digital dependence is a systemic risk and urges vault lines to strengthen financial-sector resilience
De Nederlandsche Bank's Steven Maijoor highlighted Europe's growing reliance on a few IT service providers, particularly cloud hyperscalers, as a systemic risk to the financial system. He advocated for stronger structures and partnerships to reduce digital dependence, urging financial institutions to prepare for potential disruptions and suggesting long-term strategies to decrease reliance on non-European providers.
European Insurance and Occupational Pensions Authority finds European insurance risks stable at a medium level in January 2026 Insurance Risk Dashboard
The European Insurance and Occupational Pensions Authority's January 2026 Insurance Risk Dashboard indicates that risks in the European insurance sector remain stable at a medium level, despite geopolitical tensions affecting the macroeconomic and market risk outlook. The sector is supported by solid capital positions, stable profitability, and strong premium growth, with vigilance required for geopolitical, trade disruption, and cyber risks.
Central Bank of Russia issues new information security requirements for socially important card payment systems
The Central Bank of Russia has issued updated requirements for hardware and software in socially important card payment systems, focusing on information security for infrastructure components like hardware security modules, payment devices, ATMs, and payment cards. These new parameters replace the 2020 approaches and aim to enhance data protection and support import substitution.
International Association of Insurance Supervisors publishes Roadmap 2026-2027 and targets November 2026 adoption of new ICS reporting and disclosure standards
The International Association of Insurance Supervisors (IAIS) released its Roadmap 2026-2027, focusing on standard setting, implementation support, and supervisory cooperation. Priorities include monitoring life insurance sector changes and finalizing Insurance Capital Standard (ICS) standards for Internationally Active Insurance Groups by November 2026. The roadmap addresses climate metrics, digital innovation, and cyber risk, with a new committee structure effective January 2026 and deadlines for comments on draft standards set for February 2026.
Bank for International Settlements Innovation Hub publishes Project FuSSE findings on modular settlement engine scalability and quantum readiness
The Bank for International Settlements Innovation Hub released a report on Project FuSSE, a proof-of-concept for a modular, microservices-based settlement engine architecture aimed at enhancing scalability, adaptability, and cyber resilience in financial market infrastructures. The report discusses the potential benefits and operational trade-offs, including processing up to 10,000 transactions per second and integrating post-quantum cryptography, while noting the project's experimental nature and lack of production-ready components.
Germany's Federal Financial Supervisory Authority publishes Risks in Focus 2026 warning of high potential for sudden market corrections
Germany's Federal Financial Supervisory Authority (BaFin) released its Risks in Focus 2026 assessment, highlighting elevated market valuations and a fragile backdrop as threats to financial stability, including abrupt market corrections and consumer over-indebtedness. BaFin's supervisory priorities for 2026 include intensified monitoring of credit risk, scrutiny of banks' linkages with non-bank intermediaries, and stricter oversight of consumer lending compliance.
National Bank of Moldova sets 2026-2027 insurance supervision priorities focused on governance, underwriting, solvency and ICT risk
The National Bank of Moldova outlined its supervisory priorities for the insurance sector for 2026-2027, focusing on governance, underwriting risk, solvency and asset sufficiency, and information and communications technology risk. This agenda is driven by an annual risk assessment and considers the partial liberalisation of mandatory motor third-party liability pricing.
Chile Financial Market Commission opens second consultation on service externalization requirements for insurance and reinsurance companies
The Chile Financial Market Commission has released a revised draft regulation for a second consultation, detailing principles and requirements for insurance and reinsurance companies on service externalization. The proposal clarifies requirements, applies proportionality based on entity size, complexity, and risk profile, enhances the supervisory framework, and aligns with General Rule No. 454 on operational risk management and cybersecurity.
State Bank of Vietnam issues 2026 directive to accelerate banking digital transformation and mandate stronger information security controls
The State Bank of Vietnam issued Directive No. 02/CT-NHNN outlining 2026 priorities for digital transformation and enhanced information security in the banking sector, mandating at least 15% of budgets for cybersecurity. It emphasizes senior accountability, periodic training, proactive risk management, and strengthened cybersecurity networks, applying to SBV units, credit institutions, foreign bank branches, and related service providers.
Dutch Authority for the Financial Markets sets 2026 supervision priorities on DORA cyber resilience responsible AI and financial crime
The Dutch Authority for the Financial Markets has released its Agenda 2026, emphasizing enhanced supervision of digital operational resilience, responsible artificial intelligence use, and financial crime prevention. Key initiatives include intensified oversight of AI risks, strengthened digital resilience under the Digital Operational Resilience Act, and coordinated actions against investment fraud and money laundering.
Bank of Italy publishes research building a cyber risk vulnerability indicator for Italian non-financial firms
The Bank of Italy's study, “The Cyber Risk of Non-Financial Firms,” introduces an indicator for assessing cyber risk in Italian non-financial companies, advocating its inclusion in credit risk assessments. Using natural language processing and a large language model to analyze financial statements, news, and cyber reports, it reveals increased cyberattacks in Italy since 2019, with post-incident vulnerability often surpassing defensive benefits.
Prudential Regulation Authority sets 2026 supervisory priorities for UK deposit takers and plans wider shift to two-year periodic summary meeting cycles
The Prudential Regulation Authority has written to CEOs of PRA-regulated UK banks and building societies setting out its 2026 supervisory priorities, emphasising strategic risk management, operational and financial resilience, data risk, and support for innovation aligned with its secondary objectives on competition, international competitiveness and growth. Key expectations include enhanced oversight of changing risk profiles, implementation of updated significant risk transfer and model risk management standards, strengthened operational resilience and cyber preparedness, and preparation for Basel 3.1 and the Strong and Simple Framework. The PRA will also rebase variable Pillar 2 requirements in 2026 and continue modernising reporting and authorisation processes.
United Kingdom's Prudential Regulation Authority sets 2026 insurance supervision priorities and plans move to two-year Periodic Summary Meetings
The UK Prudential Regulation Authority has set 2026 supervisory priorities for insurers, focusing on resilience and risk management amid competitive pressures in the bulk purchase annuity market, a softening general insurance underwriting cycle, and the need to strengthen operational resilience. Life insurance supervision will centre on pricing discipline, funded reinsurance and liquidity and credit risks in evolving investment strategies, while general insurers face closer scrutiny of underwriting, reserving, internal model assumptions, exposure data and delegated authority oversight. Cross-sector work will intensify on operational resilience testing, third-party risk, legacy technology, cyber risk and AI governance.
United Kingdom's Prudential Regulation Authority sets 2026 supervisory priorities for UK-active international banks and plans move to two-year PSM cycle
The Prudential Regulation Authority has written to chief executives of PRA-regulated international banks and designated investment firms in the UK setting out its 2026 supervisory priorities, emphasising risk management and governance, operational and financial resilience, and data risk, while adjusting supervision to support innovation and reduce regulatory burden. Key expectations include stronger counterparty credit and model risk management, prudent adoption of technologies such as artificial intelligence and distributed ledger technology, enhanced operational resilience and cyber capabilities, and preparations for Basel 3.1 and the Strong and Simple Framework. The PRA will also move remaining firms from annual to two-year Periodic Summary Meeting cycles in 2026 and is encouraging engagement on streamlined reporting and regulatory permissions ahead of capital regime changes.
Bank of Mozambique mandates standard templates and channels for technology and cyber incident reporting effective 9 March 2026
The Bank of Mozambique issued a circular mandating the use of specific reporting templates for technological and cyber incidents by credit institutions and financial companies. Reports must be submitted primarily via the Banking Supervision Application portal, detailing incident type, severity, impacts, and remediation actions. Email reporting is permitted only when other channels are unavailable.
Canadian Investment Regulatory Organization confirms phishing breach impacted around 750,000 investors and begins notifications with credit monitoring
The Canadian Investment Regulatory Organization (CIRO) confirmed a phishing attack affecting data of approximately 750,000 Canadian investors, with no evidence of misuse. CIRO is offering credit monitoring and identity theft protection, has secured systems, and will notify affected individuals starting January 14, 2026.
Bank of England and UK regulators sign MoU with European Supervisory Authorities on oversight of critical third parties
The Bank of England, Financial Conduct Authority, and Prudential Regulation Authority signed a Memorandum of Understanding with European Supervisory Authorities to enhance cross-border cooperation on overseeing critical third parties under the UK's regime and the EU's Digital Operational Resilience Act. This framework aims to manage risks to financial stability and market confidence while minimizing regulatory burdens for third-party providers operating across jurisdictions.
World Federation of Exchanges calls on regulators to balance post-quantum cryptography expectations with immediate AI and cyber resilience risks
The World Federation of Exchanges (WFE) highlighted a gap between regulatory and industry expectations on quantum computing risk preparedness, urging regulators to align post-quantum cryptography migration with immediate threats. A WFE survey revealed members prioritize generative AI risks over quantum preparedness, estimating a 5–10+ year window before quantum computers become a threat, while taking preparatory steps like monitoring developments and conducting risk assessments.