What's new
Overview
This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.
What's new
Dutch Authority for the Financial Markets reports 94% approval of DORA registers, flags policy and incident-reporting gaps
The Dutch Authority for the Financial Markets reported that European Banking Authority approval of DORA registers rose from 40% in 2025 to 94% in 2026. It nevertheless identified gaps in firms’ policies and procedures and fewer incident reports than expected, while pointing insurance intermediaries to new threshold-calculation guidance.
Financial Markets Standards Board review identifies persistent gaps in enterprise-wide non-financial risk management
The Financial Markets Standards Board has found that many wholesale financial market firms still struggle to manage non-financial risk holistically despite stronger frameworks and controls. Its review promotes clearer ownership, integrated decision-making, sound judgment and greater visibility of interconnected risks, but does not introduce new standards or requirements.
New York State Department of Financial Services fines Order Express USD 250,000 for cybersecurity control failures
The New York State Department of Financial Services fined Order Express USD 250,000 for deficiencies in its cybersecurity program, including inadequate system-update policies and risk assessments. The licensed money transmitter has remediated the issues and is exempt from many other requirements under 23 NYCRR Part 500 because of its limited revenue.
HM Treasury and U.S. Department of the Treasury outline regulatory coordination on digital finance, resilience and market modernization
HM Treasury and the U.S. Department of the Treasury outlined discussions on digital assets, stablecoins, artificial intelligence, operational resilience and regulatory modernization at the latest UK-U.S. Financial Regulatory Working Group meeting. The dialogue also covered banking, non-bank finance, capital markets and the Transatlantic Taskforce for Markets of the Future, with the group due to reconvene in early 2027.
INTERPOL finds AI enables 55% of reported African cybercrime as losses reach USD 484 million
INTERPOL found that AI enables 55% of reported cybercrimes across Africa, while cybercrime-related losses have more than doubled since 2024 to USD 484 million. Gaps in real-time data sharing among banks, telecommunications companies and law enforcement are facilitating scams and synthetic identity fraud. The report calls for stronger cross-border cooperation, standardized digital forensics, AI training and formal public-private partnerships.
Hellenic Capital Market Commission signs cooperation memorandum with University of West Attica on sustainable finance and technology
The Hellenic Capital Market Commission and the University of West Attica established a cooperation framework covering sustainable finance, corporate governance, financial technology, artificial intelligence, cybersecurity and digital transformation. They will undertake joint research and educational initiatives, exchange expertise and support financial literacy and specialized workforce development.
Reserve Bank of India issues immediately effective cybersecurity and technology risk framework for commercial banks
The Reserve Bank of India has introduced an immediately effective cybersecurity, technology risk and resilience framework for commercial banks. It strengthens board and management accountability, mandates continuous security monitoring and detailed controls over systems and third parties, and requires cyber incidents to be reported within six hours. Critical systems are subject to vulnerability assessments at least every six months, annual penetration testing and half-yearly disaster recovery drills.
G7 Cyber Expert Group concludes cross-border cyber exercise and adopts long-term simulation strategy
The G7 Cyber Expert Group concluded a cross-border exercise simulating a large-scale cyberattack across all G7 jurisdictions. It also adopted a long-term strategy to increase the frequency and consistency of simulations involving financial authorities.
European Supervisory Authorities call for consistent risk-based supervision of frontier AI cyber risks
The European Supervisory Authorities called for consistent, risk-based supervision of cyber risks arising from frontier AI models. Financial entities should maintain robust governance and risk management frameworks, while DORA oversight of critical ICT third-party providers will also address these risks.
European Supervisory Authorities call for risk-based controls against frontier AI cyber risks
The European Supervisory Authorities called on financial entities to strengthen proportionate prevention, detection and management controls for cyber risks from frontier AI models. Firms should establish clear governance, update risk appetite and resilience arrangements, and enhance continuous monitoring and incident response. AI-related risks will also inform oversight of critical ICT third-party providers in 2027.
European Central Bank Banking Supervision identifies stress-testing gaps in 110 banks' geopolitical risk simulations
European Central Bank Banking Supervision found that most of the 110 participating banks could model geopolitical shocks meaningfully, but identified gaps in scenario sensitivity, solvency-liquidity interactions and the realism of mitigating actions. Bank-specific deficiencies may affect Pillar 2 requirements through the supervisory review, while Pillar 2 guidance will remain unchanged.
South Korea's Financial Services Commission suspends Lotte Card for 1.5 months and imposes KRW 5 billion fine over data breach
South Korea's Financial Services Commission suspended Lotte Card's new-customer card business from Aug. 1 to Sept. 15, 2026, and imposed a KRW 5 billion fine after a breach affecting 2.97 million customers. Existing customers may continue using most services, while the authorities pursue tougher penalties and stronger security governance for financial firms.
European Insurance and Occupational Pensions Authority flags elevated market risks and worsening cyber outlook for pension institutions
The European Insurance and Occupational Pensions Authority found that market risks remain elevated for occupational pension institutions and that the 12-month outlook is worsening amid geopolitical tensions, high valuations and correction concerns. Cyber risks are also rising, although the sector remains resilient due to robust defined benefit scheme finances and positive portfolio performance.
European Insurance and Occupational Pensions Authority finds insurance sector risks stable at medium level, digitalisation and cyber risks rise to high
The European Insurance and Occupational Pensions Authority assessed European insurance sector risks as stable at a medium level overall. Digitalisation and cyber risks rose to high, while geopolitical tensions weakened the outlook for macroeconomic and market risks.
Monetary Authority of Singapore and Association of Banks in Singapore establish task force on AI-driven cyber risks
The Monetary Authority of Singapore and the Association of Banks in Singapore have established an industry task force to address cyber and technology risks from frontier AI models. It will support information sharing, test AI-enabled defence tools and develop guidance for financial institutions.
Monetary Authority of Singapore steps up AI cyber requirements and targets quantum resilience before decade-end
The Monetary Authority of Singapore will require key financial institutions to assess and strengthen their defenses against AI-enabled cyber threats and will issue a roadmap for achieving quantum resilience before the end of the decade. The measures build on mandatory AI-assisted red teaming introduced on July 1 and include industry work on AI-based scam detection. MAS also reported that the financial system remains broadly resilient and recorded a SGD 20 billion net profit for the 2025/2026 financial year.
Central Bank of Cyprus finds financial stability risks remain elevated despite financial sector resilience
The Central Bank of Cyprus found that the financial system remains resilient, although financial stability risks are elevated by geopolitical tensions, external shocks and cyber threats. It also warned that changes to the foreclosure framework could weaken payment discipline and increase borrowing costs. Macroprudential measures include a 1.5% countercyclical capital buffer from January 2026.
Bank of Greece reports improved bank fundamentals and prioritizes geopolitical, climate and digital resilience
The Bank of Greece reported stronger profitability, capital and asset quality across Greek banks in 2025, while the insurance market remained resilient. Its supervisory priorities focus on capital adequacy, geopolitical and climate risks, corporate governance, digitalization and AI-related cyberthreats.
Financial Conduct Authority and Prudential Regulation Authority outline expectations as critical third-party oversight regime goes live
The Financial Conduct Authority and Prudential Regulation Authority outlined expectations under the UK’s now-live critical third-party oversight regime. Designated providers must manage and test the resilience of critical services and support coordination during incidents, while regulated firms remain responsible for their own operational resilience and third-party risks.
European Central Bank Banking Supervision requires cyber action plans by October, reinforces AI accountability
European Central Bank Banking Supervision expects bank boards and senior management to remain accountable for AI use and associated risks. Banks must submit cyber action plans by October 2026 addressing resilience, incident response and critical third-party oversight. The ECB also plans to publish the outcome of its 2026 geopolitical reverse stress test.
Hong Kong Securities and Futures Commission reprimands and fines Luk Fook Securities HKD 2.1 million over cybersecurity failures
The Hong Kong Securities and Futures Commission reprimanded Luk Fook Securities and fined it HKD 2.1 million for cybersecurity failures linked to its vulnerability and delayed recovery from a ransomware attack. The deficiencies covered network security, software maintenance, access controls, staff training, backups and business continuity.
Bank of the Lao PDR calls for joint China ASEAN governance of AI related financial risks
The Bank of the Lao PDR called for joint China-ASEAN governance mechanisms to manage cybersecurity and systemic risks from AI in finance. Its deputy governor also joined the launch of an AI and finance cooperation project and discussions on AI-enabled local-currency cooperation.
Central Bank of the Philippines urges banks and other supervised entities to strengthen cybersecurity against AI-driven threats
The Central Bank of the Philippines has urged banks and other supervised entities to strengthen cybersecurity in response to AI-related cyber risks. Its memorandum calls for tighter security controls, better asset and vulnerability management, greater use of AI-based defensive tools, and stronger incident response and business continuity planning.
Bank of Thailand and Monetary Authority of Singapore sign MoU on cybersecurity cooperation and digital fraud protection
The Bank of Thailand and the Monetary Authority of Singapore signed a memorandum of understanding on cybersecurity cooperation and digital fraud protection, expanding existing collaboration across their financial sectors. It covers threat and incident information sharing, staff training and policy exchanges, and joint cross-border cybersecurity and crisis management exercises.
Canadian Public Accountability Board publishes audit committee insights on AI, cybersecurity, IFRS 18 implementation and public inspection reports
The Canadian Public Accountability Board published insights from its 2026 audit committee outreach, with AI, cybersecurity, IFRS 18 implementation and firm-specific public inspection reports identified as the main oversight issues. Discussions pointed to uneven IFRS 18 readiness, closer scrutiny of AI governance and auditors’ use of technology, and demand for timely inspection reports that can inform auditor assessments. IFRS 18 takes effect for annual periods beginning on or after January 1, 2027, with related Canadian Securities Administrators changes expected in fall 2026.