What's new
Overview
This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.
What's new
National Bank of Denmark and Danish Financial Supervisory Authority launch three sector preparedness initiatives after joint cyber resilience stress test
The National Bank of Denmark reported that a joint stress test with the Danish Financial Supervisory Authority and key market participants has led to three new sector-wide preparedness initiatives. The exercise tested an extreme but plausible securities data manipulation scenario and highlighted the need for coordinated recovery, communication and contingency planning across the financial sector.
Spanish Securities Commission updates internal regulations for MiCA DLT Pilot DORA and employee cryptoasset trading
The Spanish Securities Commission has revised its internal regulations to reflect new EU rules including MiCA, the DLT Pilot Regime and DORA. The changes also rename and expand two departments, add data governance responsibilities and extend staff trading rules to cover cryptoassets.
Dominican Republic Superintendency of Banks holds strategic dialogue on digital resilience and highlights new technology supervision directorate
The Dominican Republic Superintendency of Banks held five sessions with supervised financial institutions and industry groups on cybersecurity, technology supervision and operational continuity. It said its internal strengthening in cybersecurity and risk management has supported the creation of a new Directorate of Technology and Information Security Supervision. The discussions also included a consumer protection perspective on complaints and the applicable regulatory framework.
Bank of Albania approves digital operational resilience rules for licensed entities and joins IMF regional capacity center
The Bank of Albania approved a new regulation on digital operational resilience and amended its existing ICT rulebook for entities it licenses. The changes are aimed at strengthening management of technology and cyber risks as banking and financial services become more digital, while also supporting alignment with European Union requirements. It also approved participation in the IMF's Regional Capacity Development Center for Southeast Europe.
World Federation of Exchanges publishes Mythos AI paper and urges stronger existing cyber resilience frameworks
The World Federation of Exchanges has issued a position paper on the Mythos AI model, saying it reinforces existing cybersecurity trends rather than creating a wholly new threat. For exchanges and clearinghouses, the paper points to stronger vulnerability management, patching, access controls and incident response, alongside continued industry coordination and information-sharing.
International Monetary Fund identifies systemic AI cyber risks and sets out seven resilience actions
The International Monetary Fund warns that AI could turn vulnerabilities in shared financial technologies and critical service providers into rapid, correlated disruptions. It recommends seven resilience actions covering surveillance, third-party oversight, cross-sector exercises, incident reporting, international coordination and frontier AI monitoring. Financial institutions should prioritize containment, recovery and machine-speed defenses.
Germany's Federal Financial Supervisory Authority launches consultation on amendments to investment audit reporting rules
Germany's Federal Financial Supervisory Authority is consulting on amendments to investment audit reporting rules for capital management companies and managed funds. The draft reflects new fund lending requirements and adds or updates audit obligations tied to DORA, SFTR, the Benchmark Regulation, SFDR and anti-money laundering reporting. Comments are due by 31 July 2026.
French Financial Markets Authority publishes 2026 market and risk mapping highlighting geopolitical cyber and frontier AI risks
The French Financial Markets Authority has issued its 2026 market and risk mapping, highlighting geopolitical instability, cyber risk, market resilience and the rise of advanced frontier AI models. It also points to changes in household financial savings amid innovation and increasing risks.
U.S. Senate Committee on Banking, Housing and Urban Affairs leaders introduce bill to codify Commerce Department ICTS authority and restrict covered foreign adversary technology transactions
Senate Banking Committee leaders introduced a bill to codify and strengthen the Commerce Department’s ICTS supply chain security powers. The measure would let Commerce prohibit or mitigate covered transactions tied to technology from specified foreign adversary countries, while adding enforcement tools, congressional oversight and protections for free speech and open-source software. It would also formalize the ICTS office within the Bureau of Industry and Security and create a Senate-confirmed assistant secretary role.
Swedish Financial Supervisory Authority becomes part of new operational crisis management function from July 1 2026
The Swedish Financial Supervisory Authority said it will be part of a new operational crisis management function that takes effect on July 1, 2026 to help prevent and manage serious operational disruptions in Sweden’s financial system. Led by the Riksbank, the function will bring together public authorities and selected private firms to improve coordination, responsibility allocation and information-sharing.
Portuguese Insurance Regulator updates RiskOutlook reporting form for cyber risk and DORA implementation
The Portuguese Insurance Regulator has revised the RiskOutlook reporting form to reflect cyber risk and DORA-related digital operational resilience requirements. The changes add a dedicated cyber and digitalization risk class, include new resilience questions, remove certain ad hoc components, and apply to reporting due from July 1, 2026.
Central Bank of Uruguay advances cybersecurity supervision rollout for the payment system with periodic reporting by e-money issuers
The Central Bank of Uruguay is implementing a new cybersecurity supervision framework for the National Payment System based on the Uruguay Cybersecurity Framework. From July 1, Electronic Money Issuers must periodically report their cybersecurity capabilities to support more consistent and proactive supervision. The framework is set to be extended gradually to other financial system participants.
European Central Bank Banking Supervision flags AI-driven cyber and concentration risks as a 2026-28 supervisory priority
In a letter to an MEP, European Central Bank Banking Supervision said AI-related cyber and operational risks are a supervisory priority for 2026-28 and warned that advanced AI could increase the likelihood of systemic cyber incidents. It is reviewing banks' AI use and controls, following up on weaknesses through supervision, and urging banks to test AI-driven cyber scenarios. The ECB also said it is monitoring wider financial stability risks from concentrated reliance on common AI tools and technology providers.
Norwegian Financial Supervisory Authority sets new mandate for financial infrastructure contingency committee on severe ICT incidents and crises
The Norwegian Financial Supervisory Authority has adopted a new mandate for the Preparedness Committee for Financial Infrastructure, clarifying its role in severe ICT incidents and crises. The mandate strengthens sector coordination and assigns the committee responsibilities including crisis coordination, information sharing, planning and annual exercises.
Danish Financial Supervisory Authority publishes half-yearly risk outlook and sets H2 2026 focus on housing cyber and AI risks
The Danish Financial Supervisory Authority's half-yearly risk outlook highlights geopolitical shocks, stretched housing prices, cyber threats and growing AI use as the main risks for the financial sector. Its H2 2026 supervisory focus will center on lending and housing developments, prioritetslån, cyber resilience and AI-related risk management. The authority will also step up work on pensions, alternative funds, crypto-asset firms and trade-based money laundering.
Central Bank of the Philippines requires stronger authentication for high risk digital transactions by banks and large e wallet operators by 25 June 2026
The Central Bank of the Philippines said banks and e-wallet operators with more than P75 million in monthly online transactions must replace SMS- and email-based OTPs with stronger authentication for high-risk digital transactions by 25 June 2026. Covered firms must also strengthen fraud monitoring to detect suspicious activity, while lower-risk transactions may still use less stringent methods.
Bank of Italy hosts G7 Cyber Expert Group meeting on cyberattack coordination and emerging technology risks
The Bank of Italy hosted a G7 Cyber Expert Group meeting in Palermo focused on cybersecurity and operational resilience in finance. Discussions covered lessons from a recent cross-border cyberattack coordination exercise and the risks associated with artificial intelligence and quantum computing. The meeting underscored the need for international coordination to manage operational interdependencies and emerging vulnerabilities.
Turks and Caicos Financial Services Commission announces 2026 Annual Industry Meeting on AI cyber resilience and business continuity
The Turks and Caicos Financial Services Commission has announced its 2026 Annual Industry Meeting for June 30, focused on supervisory modernization, cyber resilience and business continuity. A central theme is the use of artificial intelligence in AML/CFT, fraud detection and market surveillance, together with related privacy and cross-border data issues. The invite-only event will also be livestreamed on government social media channels.
INTERPOL co-led operation identifies 34 suspicious trafficking cases and 27 potential victims on subscription content platforms
INTERPOL reported that Operation CyberProtect III uncovered 34 suspicious cases, 18 suspect profiles and 27 potential victims linked to trafficking and sexual exploitation on subscription content platforms. The co-organized operation with the Organization for Security and Co-operation in Europe found traffickers using encrypted messaging, paywalled sites, crypto-linked payments and fake AI profiles to recruit and control victims.
International Association of Insurance Supervisors and Financial Stability Institute find cyber insurance covers only 1% of global economic losses as accumulation risk grows
The International Association of Insurance Supervisors and the Financial Stability Institute find that cyber insurance covers only about 1% of global economic cyber losses, with small businesses and emerging markets most exposed. They identify correlated accumulation risk as the market’s most pressing underwriting concern and call for risk-based pricing, clearer coverage and stronger stress testing. Public-private backstops may be needed for systemic or uninsurable events.
Bank for International Settlements Financial Stability Institute examines cyber insurance and highlights that only 1 percent of global cyber losses are insured
The Bank for International Settlements' Financial Stability Institute has published an FSI Insights paper on cyber insurance, finding that only about 1 percent of global economic cyber losses are insured. It says the market is constrained by coverage ambiguity, pricing difficulties and accumulation risk from shared digital dependencies. The paper also highlights a large protection gap, especially for SMEs, and points to risk-based underwriting, clearer wording and possible public-private backstops for uninsurable risks.
Dutch Authority for the Financial Markets flags weak execution and ICT risk controls in SREP Market View 2025
The Dutch Authority for the Financial Markets says in its SREP Market View 2025 that many firms have adequate policies and processes but weaker execution in practice. It highlights gaps in internal controls, ICT risk management and the clarity of roles and responsibilities. Firms are expected to use the findings to review their organizations and strengthen weaknesses.
Central Bank of Russia publishes first AI information security recommendations for financial institutions
The Central Bank of Russia has issued its first recommendations on information security for financial institutions using AI. The guidance maps AI-related risks and cyberattack tactics and recommends human confirmation where AI is used in high-risk critical processes such as payment transactions. It also calls for internal AI threat models and security policies and highlights vendor security practices, including bug bounty participation.
Belgium Financial Services and Markets Authority warns frontier AI heightens cyber risk and tells DORA firms to strengthen controls
The Belgium Financial Services and Markets Authority has warned that frontier AI systems are making cyberattacks easier, faster and more scalable, requiring regulated firms to reassess ICT risk even if they were previously seen as lower-risk targets. It says DORA provides the core response framework and expects in-scope firms to strengthen asset inventories, patching, detection and incident response, and oversight of ICT service providers. The guidance is also recommended for firms outside DORA's scope.
Bank of Japan requests short term cyber measures for financial institutions to address frontier AI driven vulnerability risks
The Bank of Japan has asked financial institutions to urgently strengthen short-term cybersecurity measures to address the risk that frontier AI will accelerate vulnerability discovery and exploitation. Firms are expected to treat the issue as a management priority, focus patching and defenses on critical systems, and ensure vendors, contracts and contingency plans can support rapid response. The measures are framed as immediate actions, with about one month as a general guideline and ongoing review as threats evolve.