Current thematic dossiers

Select a theme to view its dossier.

Cyber & operational resilience

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

Overview

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

  1. AsiaIndiaSecurities & Exchange Board of IndiaPolicy and regulation

    Securities and Exchange Board of India revises stock broker technical glitch rules and limits scope to brokers with over 10,000 clients

    The Securities and Exchange Board of India (SEBI) has revised its framework for managing technical glitches in stock brokers' electronic trading systems, narrowing applicability, expanding exemptions, and simplifying reporting. The framework, which supersedes the November 2022 circular, applies to brokers with over 10,000 clients and includes detailed guidelines on incident reporting, capacity planning, and financial disincentives.

  2. AsiaIndonesiaOJKPolicy and regulation

    Financial Services Authority issues new IT governance and cybersecurity rules for Indonesia’s rural banks and Sharia rural banks

    Indonesia’s Financial Services Authority (OJK) has introduced new IT operation requirements for rural banks and Sharia rural banks to enhance digital security, focusing on IT governance, risk management, and data protection. The framework, effective one year post-promulgation, will replace existing regulations and mandates local data center and disaster recovery facilities.

  3. EuropeLatviaCentral Bank of LatviaStrategy and priorities

    Central Bank of Latvia sets 2026–2028 supervision priorities and approves 2026 inspection plan focused on resilience and accessible services

    The Central Bank of Latvia outlined its 2026–2028 financial market supervision priorities, emphasizing resilience, accessibility, and transparency, while reducing firms' administrative burdens. The 2026 plan includes 12 on-site inspections across sectors, focusing on risks like credit underwriting standards, bank profitability, insurers' claims practices, and fintech compliance with the Digital Operational Resilience Act (DORA).

  4. Middle EastOmanCentral Bank of OmanPolicy and regulation

    Central Bank of Oman issues new business continuity management framework and sets 30 June 2026 deadline for banks and finance and leasing companies

    The Central Bank of Oman has introduced a Business Continuity Management (BCM) Framework for licensed banks and finance and leasing companies, emphasizing operational resilience through a service-centric approach. It mandates governance by boards and senior management, recovery objectives, and integration into risk management, with requirements for business impact analysis, IT disaster recovery, and cyber resilience. It also outlines incident reporting timelines and testing protocols, replacing the previous BCM guidelines from August 2010.

  5. GlobalGlobalInternational Monetary FundResearch

    International Monetary Fund publishes good practices for cyber risk regulation and supervision in the financial sector

    The IMF's Monetary and Capital Markets Department released a paper on "good practices" for cyber risk regulation in financial institutions, emphasizing integrating ICT and cyber-risk management. It recommends balancing principles-based and prescriptive elements, applying proportionality by firm size and systemic importance, and highlights tools like governance requirements, cybersecurity testing, and third-party risk management.