What's new
Overview
This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.
What's new
South Korea Financial Services Commission expands AI security testing eligibility to 75 firms
The South Korea Financial Services Commission expanded eligibility for its second frontier AI security test from 49 to 75 firms and will select up to 15 participants for one-year relief from network-separation rules. Selected firms must adopt alternative security controls and report their findings, while an interim review of the first round found that AI could scan large codebases rapidly and consistently for vulnerabilities.
Australia’s Council of Financial Regulators finds system resilient, backs unchanged macroprudential settings amid elevated risks
The Council of Financial Regulators maintained that Australia’s financial system remains resilient despite elevated geopolitical, market and cyber risks, and backed unchanged macroprudential settings. Borrower stress remains limited, but authorities emphasized sound lending standards and stronger operational resilience. A payments cyber crisis coordination framework will be published shortly, alongside ongoing work on critical third-party and AI-enabled cyber risks.
U.S. Securities and Exchange Commission proposes transfer agent rule overhaul, including one-day processing and new compliance safeguards
The U.S. Securities and Exchange Commission proposed a comprehensive modernization of registered transfer agent rules, including one-day processing and posting standards, six-year record retention and expanded reporting. The package would add compliance, safeguarding, cybersecurity and business continuity requirements while removing several existing exemptions. It would also regulate restrictive legend removal and require notifications to securityholders after 18 months of inactivity.
Australian Prudential Regulation Authority and Australian Securities and Investments Commission release superannuation CEO roundtable notes on AI and resilience
The Australian Prudential Regulation Authority and Australian Securities and Investments Commission have released notes from superannuation CEO roundtables on frontier AI, cyber and operational resilience, and crisis preparedness. Participants emphasized tested governance, individual accountability and stronger oversight of concentrated service-provider dependencies, reinforcing the regulators’ recent focus on converting cyber-risk awareness into operational readiness.
Bank of Mozambique sets data localization and cloud outsourcing requirements for financial institutions
The Bank of Mozambique requires credit institutions and financial companies to keep primary data centers and core systems in Mozambique and obtain approval for specified offshore and cloud arrangements. Banks, microbanks and electronic money institutions may use only private clouds, while outsourcing contracts must provide security, audit, regulatory access and exit protections. Existing institutions have 12 months after the rules take effect to comply fully.
Central Bank of Bahrain holds financial sector cybersecurity event focused on AI-era data risks
The Central Bank of Bahrain and the National Cyber Security Center held a cybersecurity awareness event for financial services professionals focused on data protection in the AI era. Sessions covered human risk, secure practices, artificial intelligence and emerging cyber threats.
Financial Stability Board chair warns of cyber risks from frontier AI models
Financial Stability Board Chair Andrew Bailey warned that frontier AI models could intensify cyber risk and called for safe model deployment, robust financial-sector recovery capabilities and resilient critical technology providers. He also cautioned that rising leverage, stretched valuations, market concentration and AI-related optimism could amplify a market correction.
Reserve Bank of Australia sets 2026/27 priorities for monetary policy, payments resilience and digital money
The Reserve Bank of Australia’s 2026/27 corporate plan prioritizes modernizing monetary policy implementation, strengthening payment infrastructure and advancing work on digital money. The RBA plans to complete its payments regulation review, test new crisis management powers and assess the case for a retail central bank digital currency. It will also progress cyber upgrades and maintain demanding availability targets for critical settlement services.
National Bank of the Kyrgyz Republic holds cybersecurity and financial literacy seminar for regional media
The National Bank of the Kyrgyz Republic trained regional journalists on financial literacy, cybersecurity, money mule activity and protection against financial fraud. Participants also developed crisis communication protocols and approaches to countering false information.
European Banking Authority launches consultation on proportionate operational risk framework, with lighter requirements below EUR 750 million
The European Banking Authority has consulted on harmonized standards for institutions’ governance, assessment and management of operational risk. The proposals cover management accountability, independent oversight, data, reporting, validation and audit, with lighter requirements for institutions whose business indicator is below EUR 750 million. The final standards will be submitted to the European Commission for adoption.
Australian Securities and Investments Commission sets 2026–27 priorities on consumer harm, AI oversight and regulatory burden
The Australian Securities and Investments Commission has set its 2026–27 priorities, combining stronger action on consumer harm and artificial intelligence risks with measures to reduce unnecessary regulatory burden. Its work will cover scams, debt collection, insurance intermediaries, buy now pay later, superannuation fee deductions and AI-related threats to consumers and markets.
INTERPOL operation against West African organized crime leads to 58 arrests and identification of 263 suspects
INTERPOL reported 58 arrests and the identification of 263 suspects following a 22-country operation against West African organized crime groups. Authorities disrupted major romance, investment and money laundering schemes, including by blocking 257 South African bank accounts and identifying a 196-person Crime-as-a-Service network in Argentina. The operation also found increased sextortion targeting minors and greater outsourcing of criminal activities through the dark web.
Securities and Exchange Board of India launches centralized cyber information portal for securities markets
The Securities and Exchange Board of India has launched a centralized portal for securities market participants to access cybersecurity circulars, vulnerability warnings and incident insights.
Securities and Exchange Board of India signs partnership to strengthen cybersecurity, market intelligence and technical innovation
The Securities and Exchange Board of India signed a long-term partnership with Rashtriya Raksha University and the National Institute of Securities Markets. The collaboration covers cybersecurity and emerging-technology training, research and open-source intelligence, and includes a planned Technical Innovation Unit for joint operations and innovation in the securities market.
Securities and Exchange Board of India mandates IT resilience index for market infrastructure institutions by February 2027
The Securities and Exchange Board of India will require market infrastructure institutions to calculate a system-driven IT Resilience Index every six months. Institutions must implement the index, early warnings and real-time service monitoring by February 28, 2027. The first submission will cover the half-year ending March 31, 2027.
Securities and Exchange Board of India aligns cyber incident reporting portal with FSB FIRE format
The Securities and Exchange Board of India has aligned its Cyber Incident Reporting Portal with the Financial Stability Board’s FIRE framework. Regulated entities must provide standardized, staged reports from initial notification through updates and final closure, alongside existing six-hour email and 24-hour portal reporting requirements.
Danish Financial Supervisory Authority urges financial firms to strengthen defenses against AI-enabled cyberattacks
The Danish Financial Supervisory Authority has urged all financial firms to assess AI-enabled cyber threats and strengthen their cybersecurity and operational resilience proportionately. Firms should establish clear management accountability, improve vulnerability monitoring and patching, and test response and recovery plans against AI-driven attacks. The authority will analyze the sector’s AI use and related risks in the second half of 2026.
Norwegian Ministry of Finance extends parts of DORA to additional financial sector entities
The Norwegian Ministry of Finance has extended parts of the Digital Operational Resilience Act framework to finance undertakings, real estate brokerage firms, debt collection firms and the Norwegian Natural Perils Pool.
Australian Prudential Regulation Authority sets 2026-27 agenda for cyber resilience, system risk and burden-neutral reform
The Australian Prudential Regulation Authority’s 2026-27 Corporate Plan prioritizes cyber and AI threats, technology-provider concentration, geopolitical risk and financial-sector interconnections. Planned measures include bank lending reviews, a new system-risk stress test and reforms covering superannuation capital, governance, bank capital and liquidity. APRA aims to offset new requirements through regulatory simplification.
Australian Prudential Regulation Authority outlines trustee priorities as retirement-age accounts are projected to grow by 3.9 million
The Australian Prudential Regulation Authority outlined stronger operational resilience, investment governance and liquidity expectations for superannuation trustees as retirement-age accounts are projected to grow by 3.9 million over the next decade. It also highlighted continued scrutiny of Retirement Income Covenant compliance, revised capital treatment for longevity products and increased reporting transparency.
Central Bank of Kuwait launches sixth cohort of Cybersecurity Leaders Program
The Central Bank of Kuwait has launched the sixth cohort of its three-month Cybersecurity Leaders Program for Kuwaiti nationals. Delivered with the SANS Institute, the program includes a final workshop involving the Bank for International Settlements, with applications open through Sept. 24, 2026.
Agency for Regulation and Development of the Financial Market of the Republic of Kazakhstan details mandatory cybersecurity requirements for all financial market participants
Kazakhstan’s financial regulator detailed mandatory minimum information security requirements applying to all financial market participants since July 12, 2026, with stricter controls for banks. Compliance is monitored through reporting and supervisory reviews, while consumers are urged to verify suspicious requests through official channels.
Central Bank of the Philippines sets guidelines for rural bank cloud core banking support, including 36-month subscriptions
The Central Bank of the Philippines has set rules for supporting qualified rural banks’ migration to cloud-based core banking systems. Assistance covers implementation for up to six months and a 36-month subscription, subject to capital, readiness, outsourcing and supervisory assessments. Applications open one month after issuance, with the deadline to be announced separately.
Bank of Italy reports 49 technical cooperation activities involving more than 750 experts from 61 central banks
The Bank of Italy reported that more than 750 experts from 61 central banks joined 49 technical cooperation activities in the first half of 2026. Topics included artificial intelligence, supervisory technology, operational resilience, the digital euro, payments and market infrastructures.
Australian Prudential Regulation Authority brings civil penalty case against Bendigo Bank over admitted cyber control breaches, parties propose AUD 8 million penalty
The Australian Prudential Regulation Authority has brought civil penalty proceedings against Bendigo Bank over admitted accountability, cyber control and testing failures linked to a 2023 attack on its Alliance Bank business. The parties propose an AUD 8 million penalty, subject to court approval. The historical weaknesses have been remediated, and APRA has no current concerns about the bank’s information security controls.