What's new
Overview
This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.
What's new
Polish Financial Supervision Commission issues recommendations on Frontier AI cyber risks for financial market entities
The Polish Financial Supervision Commission has issued recommendations telling financial market entities to reassess ICT risk management and operational resilience for cyber threats linked to Frontier AI. Firms should incorporate AI threat scenarios into DORA processes, prioritize vulnerability management, third-party risk and protection of internet-facing assets, and ensure senior management allocates sufficient resources. UKNF said the adequacy and effectiveness of firms' measures will be tested through ongoing supervision and inspections.
Vietnam State Securities Commission holds cybersecurity warning and guidance conference for securities sector with police cyber unit
The Vietnam State Securities Commission held a conference with the Ministry of Public Security's cyber unit to warn and guide securities-sector entities on cybersecurity risks and incident coordination. Discussions covered the legal framework, attack methods, monitoring and operational controls, alongside firms' practical challenges. The commission asked market participants to upgrade systems, review processes and strengthen response preparedness and staff training.
National Bank of the Kyrgyz Republic holds CYBERFINANCE-2026 forum, creates cyber cooperation platform
The National Bank of the Kyrgyz Republic held the CYBERFINANCE-2026 forum and created a cooperation platform for the central bank, banks, the IT sector and universities to address cyber risks. More than 130 participants discussed social engineering, phishing and consumer protection, alongside cyber exercises designed to identify talent for the banking sector.
Bank for International Settlements bulletin examines frontier AI cyber risks and urges swift defensive adoption
The Bank for International Settlements published a bulletin warning that frontier AI can strengthen both cyber offence and defence, but that cost asymmetries may leave attackers with an advantage. It says the impact on systemic cyber risk will depend on access to advanced models, compute and incentives, and it calls for rapid defensive adoption of these tools. The bulletin also highlights the need for stronger domestic and cross-border coordination, especially around vulnerability remediation, third-party risk and resilience planning.
Superintendency of the Securities Market of the Dominican Republic signs cooperation agreement with INDOTEL on digital governance and cyber risk
The Superintendency of the Securities Market of the Dominican Republic signed a cooperation agreement with the Dominican Institute of Telecommunications to deepen technical and regulatory coordination. The agreement focuses on digital governance, interoperability, regulatory innovation and electronic trust services, and also covers cooperation on cybersecurity, data protection and technology incident management.
Bank of Italy tells directly supervised intermediaries to strengthen digital resilience and submit action plans by 31 December 2026
The Bank of Italy has told directly supervised intermediaries to strengthen digital operational resilience and cyber controls, warning that advanced AI models are accelerating the exploitation of software vulnerabilities. It expects boards to review governance, cyber hygiene, asset inventories, patching, monitoring, testing and outsourcing controls, and to submit a report and remediation plan to supervisors by 31 December 2026.
Canadian Securities Administrators publish cybersecurity guidance after review of 73 registered firms, identify gaps in controls and incident planning
The Canadian Securities Administrators issued updated cybersecurity guidance after a compliance review of 73 registered firms. The review found that many firms had solid frameworks, especially larger firms, but also highlighted gaps in areas including controls, third-party oversight and incident response. Firms are expected to assess the guidance against their own operations and address weaknesses.
China's National Financial Regulatory Administration launches consultation on cybersecurity management rules for banks insurers and financial holding companies
China's National Financial Regulatory Administration is consulting on draft cybersecurity management measures for banking institutions, insurance institutions and financial holding companies. The 72-article draft sets requirements on governance, operations, risk monitoring, incident response and critical information infrastructure, with stricter standards for higher-risk infrastructure. The authority plans to revise the text after consultation and publish final rules later.
HM Treasury designates four cloud providers as Critical Third Parties from 13 July 2026
HM Treasury has designated Microsoft, Google Cloud, Amazon Web Services and Oracle entities as Critical Third Parties from 13 July 2026. Their systemic services to the UK financial sector will come under joint oversight by the Bank of England, Prudential Regulation Authority and Financial Conduct Authority. The regime is risk-based and may be extended to other providers over time.
Dutch Central Bank and Dutch regulators urge joint IT contracting and procurement changes to strengthen digital autonomy
The Dutch Central Bank and four other Dutch regulators have issued a joint report urging governments, businesses and IT providers to strengthen digital autonomy in IT services. They call for digital autonomy to be built into procurement decisions, more use of open standards and interoperability, and greater scope for companies to collaborate when contracting with suppliers. The aim is to reduce dependence on a small number of non-European providers and improve resilience and switching options.
Bank of Italy publishes 2025 ICT incident analysis showing higher volumes and significant third party provider involvement
The Bank of Italy has published its 2025 analysis of major ICT incidents reported under DORA. It found more incidents than in the previous year, mostly operational rather than cyber-related, with around one quarter involving cybersecurity. The report also highlights significant involvement of external ICT service providers and stresses the need for strong ICT and third party risk controls.
Hong Kong Securities and Futures Commission requires internet brokers and virtual asset trading platform operators to replace OTP logins with phishing resistant authentication within 12 months
The Hong Kong Securities and Futures Commission has ordered internet brokers and virtual asset trading platform operators to replace OTP-based client login and device binding with phishing-resistant authentication. Firms must implement the change as soon as practicable and within 12 months, while large internet brokers are expected to act immediately. The circular also requires stronger monitoring, incident response and client alert measures, with senior management accountable for control lapses.
Guernsey Financial Services Commission tells firms to review technology risk controls as AI speeds vulnerability discovery
The Guernsey Financial Services Commission has told regulated firms to review technology risk management after advances in AI increased the speed and scale of software vulnerability discovery. Its Dear CEO letter focuses on vulnerability management, patching and outsourced provider oversight. Boards and senior management are expected to ensure technology risk is monitored continuously and that remediation can be accelerated without weakening controls.
European Securities and Markets Authority launches supervisory review of crypto custody providers digital operational resilience
The European Securities and Markets Authority has launched a Common Supervisory Action on the digital operational resilience of crypto-asset service providers, centred on custody services. National Competent Authorities will review a risk-based sample of authorised firms from the second half of 2026 to the first half of 2027, focusing on distributed ledger technology risks such as key management, transaction controls, incident response, smart contracts and third-party dependencies. ESMA will compile the findings into a final report for its Board of Supervisors in the second half of 2027.
European Central Bank Banking Supervision directs significant institutions to submit AI cyber-risk action plans by October 31
European Central Bank Banking Supervision has directed significant institutions to assess AI-enabled cyber threats and submit action plans by October 31, 2026. Plans must address accelerated patching, exposed assets, monitoring, third-party risk and longer-term operational resilience. The ECB has extended the annual IT Risk Questionnaire deadline to February 2027 to support this work.
Dutch Authority for the Financial Markets publishes Financial Stability Committee warning on AI driven cyber risk and private credit transparency
The Dutch Authority for the Financial Markets published a Financial Stability Committee update warning that advanced AI models are increasing the urgency of stronger cyber resilience in finance. The committee called for faster vulnerability management and better coordination and information sharing across sectors. It also said private credit's rapid growth requires better data on exposures, credit quality and links to the wider financial system.
De Nederlandsche Bank reports Financial Stability Committee urges stronger cyber coordination and better private credit data
De Nederlandsche Bank said the Dutch Financial Stability Committee has warned that advanced AI models are changing cyber risk and that financial institutions need to adapt their risk management and resilience. The committee also said financial stability risks remain high and called for stronger cross-sector cyber coordination and information sharing. It separately flagged rapid private credit growth and said better data are needed on exposures, credit quality and interconnectedness.
Dutch Authority for the Financial Markets publishes Financial Stability Committee warning that advanced AI models raise cyber resilience urgency
The Dutch Authority for the Financial Markets published a Financial Stability Committee update warning that advanced AI models are intensifying cyber risks and require financial institutions to strengthen cyber resilience and adapt risk management. The committee also said broader financial stability risks remain elevated and called for better data on the fast-growing private credit market. Improved coordination and information sharing across authorities, firms and critical sectors were identified as a priority.
European Systemic Risk Board warns frontier AI models could intensify systemic cyber risks in EU finance
The European Systemic Risk Board has warned that frontier AI models could raise systemic cyber risks for the EU financial system by helping threat actors find vulnerabilities and conduct attacks faster and at greater scale. It also flagged strategic dependency risks from the concentration of leading AI providers outside the EU. The ESRB will review the issue in its quarterly risk assessments and may take further action if needed.
European Banking Authority backs ESRB warning on frontier AI cyber risks and urges stronger financial sector defences
The European Banking Authority, alongside the other European Supervisory Authorities, backed the ESRB warning that frontier AI models are increasing systemic cyber risks for the financial sector. It urged financial entities to strengthen cybersecurity capabilities and called on supervisors to reflect the risks in their oversight. The authorities will continue monitoring the issue and clarify supervisory expectations under DORA.
Central Bank of the Philippines issues frontier AI cyber risk recommendations including hardware-backed MFA for privileged access
The Central Bank of the Philippines issued guidance for supervised institutions on managing cybersecurity risks from frontier AI systems that could automate vulnerability discovery and multi-stage attacks. It recommends stronger attack-surface visibility, zero trust and patching controls, hardware-backed MFA for privileged access with passwords and SMS or push methods discontinued for that purpose, AI-enabled defensive tools, business continuity reviews and institution-specific AI governance frameworks.
National Bank of Belgium flags rising payment fraud and broader operational risks in 2026 oversight report
The National Bank of Belgium’s 2026 oversight report identifies rising payment fraud, cyber threats, third-party technology dependence and physical security risks as key resilience concerns for financial market infrastructures and payment service providers. It calls for stronger controls, real-time fraud monitoring and regular crisis testing. New Belgian legislation also expands the bank’s oversight powers over financial messaging providers such as Swift.
South Africa Financial Sector Conduct Authority publishes 2026-2029 regulation plan focused on COFI Bill transition and JIBAR to ZARONIA reform
The South Africa Financial Sector Conduct Authority has issued its 2026-2029 regulation plan, with the Conduct of Financial Institutions Bill as the central driver of future market conduct reform. Priorities include themed consultations for the new framework, benchmark reform and the JIBAR to ZARONIA transition by 31 December 2026, plus joint standards on governance, outsourcing, operational resilience and beneficial ownership transparency. The authority also says it will limit new projects where possible and phase reforms to manage industry impact.
Bank of France, French National Agency for the Security of Information Systems and Prudential Supervision and Resolution Authority sign cyber cooperation agreement under DORA and NIS 2
The Bank of France, the French National Agency for the Security of Information Systems and the Prudential Supervision and Resolution Authority signed an agreement to deepen cyber cooperation in the financial sector. It supports their roles under DORA and NIS 2 and covers incident and threat information sharing, supervisory coordination, cyber crisis management and threat-led penetration testing.
Ukraine National Commission on Securities and Stock Market launches DORA-based overhaul of IT system controls for capital markets firms
The Ukraine National Commission on Securities and Stock Market has proposed new DORA-based rules to tighten oversight of the IT systems used by professional capital markets participants. Firms would face broader reporting on software, cloud and server arrangements, security measures and automated bots, plus immediate notification duties for cyberattacks, software failures and prohibited sanctioned software. Comments are open until July 27, 2026, after which the measure will be sent for registration with the Ministry of Justice.