Current thematic dossiers

Select a theme to view its dossier.

Cyber & operational resilience

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

Overview

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

  1. EuropeNetherlandsDutch Authority for the Financial MarketsSupervision

    Dutch Authority for the Financial Markets reports 94% approval of DORA registers, flags policy and incident-reporting gaps

    The Dutch Authority for the Financial Markets reported that European Banking Authority approval of DORA registers rose from 40% in 2025 to 94% in 2026. It nevertheless identified gaps in firms’ policies and procedures and fewer incident reports than expected, while pointing insurance intermediaries to new threshold-calculation guidance.

  2. GlobalGlobalFinancial Markets Standards BoardProjects and initiatives

    Financial Markets Standards Board review identifies persistent gaps in enterprise-wide non-financial risk management

    The Financial Markets Standards Board has found that many wholesale financial market firms still struggle to manage non-financial risk holistically despite stronger frameworks and controls. Its review promotes clearer ownership, integrated decision-making, sound judgment and greater visibility of interconnected risks, but does not introduce new standards or requirements.

  3. North AmericaUnited StatesNew York State Department of Financial ServicesEnforcement

    New York State Department of Financial Services fines Order Express USD 250,000 for cybersecurity control failures

    The New York State Department of Financial Services fined Order Express USD 250,000 for deficiencies in its cybersecurity program, including inadequate system-update policies and risk assessments. The licensed money transmitter has remediated the issues and is exempt from many other requirements under 23 NYCRR Part 500 because of its limited revenue.

  4. EuropeUnited KingdomHM TreasuryCooperation

    HM Treasury and U.S. Department of the Treasury outline regulatory coordination on digital finance, resilience and market modernization

    HM Treasury and the U.S. Department of the Treasury outlined discussions on digital assets, stablecoins, artificial intelligence, operational resilience and regulatory modernization at the latest UK-U.S. Financial Regulatory Working Group meeting. The dialogue also covered banking, non-bank finance, capital markets and the Transatlantic Taskforce for Markets of the Future, with the group due to reconvene in early 2027.

  5. GlobalGlobalINTERPOL

    INTERPOL finds AI enables 55% of reported African cybercrime as losses reach USD 484 million

    INTERPOL found that AI enables 55% of reported cybercrimes across Africa, while cybercrime-related losses have more than doubled since 2024 to USD 484 million. Gaps in real-time data sharing among banks, telecommunications companies and law enforcement are facilitating scams and synthetic identity fraud. The report calls for stronger cross-border cooperation, standardized digital forensics, AI training and formal public-private partnerships.

  6. EuropeGreeceHellenic Capital Market CommissionCooperation

    Hellenic Capital Market Commission signs cooperation memorandum with University of West Attica on sustainable finance and technology

    The Hellenic Capital Market Commission and the University of West Attica established a cooperation framework covering sustainable finance, corporate governance, financial technology, artificial intelligence, cybersecurity and digital transformation. They will undertake joint research and educational initiatives, exchange expertise and support financial literacy and specialized workforce development.

  7. AsiaIndiaReserve Bank of IndiaPolicy and regulation

    Reserve Bank of India issues immediately effective cybersecurity and technology risk framework for commercial banks

    The Reserve Bank of India has introduced an immediately effective cybersecurity, technology risk and resilience framework for commercial banks. It strengthens board and management accountability, mandates continuous security monitoring and detailed controls over systems and third parties, and requires cyber incidents to be reported within six hours. Critical systems are subject to vulnerability assessments at least every six months, annual penetration testing and half-yearly disaster recovery drills.

  8. EuropeEuropeEuropean Securities and Markets AuthorityProjects and initiatives

    European Supervisory Authorities call for risk-based controls against frontier AI cyber risks

    The European Supervisory Authorities called on financial entities to strengthen proportionate prevention, detection and management controls for cyber risks from frontier AI models. Firms should establish clear governance, update risk appetite and resilience arrangements, and enhance continuous monitoring and incident response. AI-related risks will also inform oversight of critical ICT third-party providers in 2027.

  9. EuropeEuropeEuropean Central Bank - Banking SupervisionSupervision

    European Central Bank Banking Supervision identifies stress-testing gaps in 110 banks' geopolitical risk simulations

    European Central Bank Banking Supervision found that most of the 110 participating banks could model geopolitical shocks meaningfully, but identified gaps in scenario sensitivity, solvency-liquidity interactions and the realism of mitigating actions. Bank-specific deficiencies may affect Pillar 2 requirements through the supervisory review, while Pillar 2 guidance will remain unchanged.

  10. AsiaSouth KoreaSouth Korea Financial Services CommissionEnforcement

    South Korea's Financial Services Commission suspends Lotte Card for 1.5 months and imposes KRW 5 billion fine over data breach

    South Korea's Financial Services Commission suspended Lotte Card's new-customer card business from Aug. 1 to Sept. 15, 2026, and imposed a KRW 5 billion fine after a breach affecting 2.97 million customers. Existing customers may continue using most services, while the authorities pursue tougher penalties and stronger security governance for financial firms.

  11. EuropeEuropeEuropean Insurance and Occupational Pensions AuthoritySupervision

    European Insurance and Occupational Pensions Authority flags elevated market risks and worsening cyber outlook for pension institutions

    The European Insurance and Occupational Pensions Authority found that market risks remain elevated for occupational pension institutions and that the 12-month outlook is worsening amid geopolitical tensions, high valuations and correction concerns. Cyber risks are also rising, although the sector remains resilient due to robust defined benefit scheme finances and positive portfolio performance.

  12. EuropeEuropeEuropean Insurance and Occupational Pensions AuthorityData and reporting

    European Insurance and Occupational Pensions Authority finds insurance sector risks stable at medium level, digitalisation and cyber risks rise to high

    The European Insurance and Occupational Pensions Authority assessed European insurance sector risks as stable at a medium level overall. Digitalisation and cyber risks rose to high, while geopolitical tensions weakened the outlook for macroeconomic and market risks.

  13. AsiaSingaporeMonetary Authority of SingaporeProjects and initiatives

    Monetary Authority of Singapore steps up AI cyber requirements and targets quantum resilience before decade-end

    The Monetary Authority of Singapore will require key financial institutions to assess and strengthen their defenses against AI-enabled cyber threats and will issue a roadmap for achieving quantum resilience before the end of the decade. The measures build on mandatory AI-assisted red teaming introduced on July 1 and include industry work on AI-based scam detection. MAS also reported that the financial system remains broadly resilient and recorded a SGD 20 billion net profit for the 2025/2026 financial year.

  14. EuropeCyprusCentral Bank of CyprusSupervision

    Central Bank of Cyprus finds financial stability risks remain elevated despite financial sector resilience

    The Central Bank of Cyprus found that the financial system remains resilient, although financial stability risks are elevated by geopolitical tensions, external shocks and cyber threats. It also warned that changes to the foreclosure framework could weaken payment discipline and increase borrowing costs. Macroprudential measures include a 1.5% countercyclical capital buffer from January 2026.

  15. EuropeUnited KingdomFinancial Conduct AuthorityProjects and initiatives

    Financial Conduct Authority and Prudential Regulation Authority outline expectations as critical third-party oversight regime goes live

    The Financial Conduct Authority and Prudential Regulation Authority outlined expectations under the UK’s now-live critical third-party oversight regime. Designated providers must manage and test the resilience of critical services and support coordination during incidents, while regulated firms remain responsible for their own operational resilience and third-party risks.

  16. EuropeEuropeEuropean Central Bank - Banking SupervisionEvents and speeches

    European Central Bank Banking Supervision requires cyber action plans by October, reinforces AI accountability

    European Central Bank Banking Supervision expects bank boards and senior management to remain accountable for AI use and associated risks. Banks must submit cyber action plans by October 2026 addressing resilience, incident response and critical third-party oversight. The ECB also plans to publish the outcome of its 2026 geopolitical reverse stress test.

  17. AsiaHong KongHong Kong Securities & Futures CommissionEnforcement

    Hong Kong Securities and Futures Commission reprimands and fines Luk Fook Securities HKD 2.1 million over cybersecurity failures

    The Hong Kong Securities and Futures Commission reprimanded Luk Fook Securities and fined it HKD 2.1 million for cybersecurity failures linked to its vulnerability and delayed recovery from a ransomware attack. The deficiencies covered network security, software maintenance, access controls, staff training, backups and business continuity.

  18. AsiaPhilippinesCentral Bank of the PhilippinesProjects and initiatives

    Central Bank of the Philippines urges banks and other supervised entities to strengthen cybersecurity against AI-driven threats

    The Central Bank of the Philippines has urged banks and other supervised entities to strengthen cybersecurity in response to AI-related cyber risks. Its memorandum calls for tighter security controls, better asset and vulnerability management, greater use of AI-based defensive tools, and stronger incident response and business continuity planning.

  19. AsiaThailandBank of ThailandCooperation

    Bank of Thailand and Monetary Authority of Singapore sign MoU on cybersecurity cooperation and digital fraud protection

    The Bank of Thailand and the Monetary Authority of Singapore signed a memorandum of understanding on cybersecurity cooperation and digital fraud protection, expanding existing collaboration across their financial sectors. It covers threat and incident information sharing, staff training and policy exchanges, and joint cross-border cybersecurity and crisis management exercises.

  20. North AmericaCanadaCanadian Public Accountability BoardSupervision

    Canadian Public Accountability Board publishes audit committee insights on AI, cybersecurity, IFRS 18 implementation and public inspection reports

    The Canadian Public Accountability Board published insights from its 2026 audit committee outreach, with AI, cybersecurity, IFRS 18 implementation and firm-specific public inspection reports identified as the main oversight issues. Discussions pointed to uneven IFRS 18 readiness, closer scrutiny of AI governance and auditors’ use of technology, and demand for timely inspection reports that can inform auditor assessments. IFRS 18 takes effect for annual periods beginning on or after January 1, 2027, with related Canadian Securities Administrators changes expected in fall 2026.