What's new
Overview
This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.
What's new
Financial Supervisory Authority of Norway warns geopolitical tensions cyber threats and property vulnerabilities are increasing financial stability risks
The Financial Supervisory Authority of Norway said geopolitical tensions, cyber threats, high household debt and continued weakness in property development are increasing risks to financial stability. Banks and insurers remain profitable and solid, but the 2026 stress test shows banks' capital adequacy could weaken materially in a severe downturn. Credit risk has also risen in several corporate sectors, and cyber or operational incidents could have systemic effects.
Central Bank of the Republic of Azerbaijan’s FinCERT joins FIRST cybersecurity response network
The Central Bank of the Republic of Azerbaijan said its financial sector incident response center, FinCERT, has joined the Forum of Incident Response and Security Teams after meeting the membership requirements. The move is intended to strengthen international cooperation, information sharing and cyber incident response across Azerbaijan’s financial sector.
Central Bank of Estonia tests offline card payments at six shops and identifies need for technical improvements
The Central Bank of Estonia tested offline card payments by cutting communications to six shops for one hour. Major retailers were able to process limited purchases using physical bank cards and PIN codes, but the exercise exposed technical issues and showed that customers relying only on contactless devices or no cash remain vulnerable during outages.
Dutch Authority for the Financial Markets identifies shortcomings in trading platforms’ DORA ICT risk management
The Dutch Authority for the Financial Markets found that trading platforms still need to strengthen ICT risk management to comply fully with DORA, even though core frameworks are generally in place. The main gaps concern overly broad gap analyses, weaker controls in key risk areas, inconsistent policy documentation and incomplete adoption of DORA standards for intragroup ICT services. The AFM said it will assess both documented arrangements and their practical effectiveness, and will intervene where firms fall short.
South African Reserve Bank flags higher financial stability vulnerabilities from Middle East conflict and frontier AI while finding system resilient
The South African Reserve Bank’s first 2026 Financial Stability Review finds that residual vulnerability in South Africa’s financial system has increased since November 2025, driven mainly by the escalation of the Middle East conflict and rapid advances in frontier artificial intelligence. The review highlights heightened risks from volatile capital flows, fiscal stress, household distress and operational disruption, alongside persistent structural and climate-related vulnerabilities. Systemically important institutions remain well capitalised and liquid, and the Bank plans to provide deposit facilities to central counterparties by end-2026 and to finalise indicators for a positive cycle-neutral countercyclical capital buffer in 2027.
South Korea Financial Services Commission urges major financial groups to strengthen AI cyber defenses and signals strict liability for phishing losses
The South Korea Financial Services Commission met chief executives of five major financial holding companies to set priorities for addressing cybersecurity threats and deepfake voice phishing as AI use expands in finance. The Commission urged firms to strengthen AI-enabled defenses, join government AI cybersecurity tests, enhance data sharing with law enforcement and the Korea Financial Intelligence Unit, and consider insurance, while the government eases the network separation rule, expands its AI-based anti-phishing platform, and pursues strict liability to increase firm responsibility and victim remedies.
Dutch Authority for the Financial Markets warns advanced AI is shortening time to exploit vulnerabilities and urges stronger baseline security
The Dutch Authority for the Financial Markets warns that advanced artificial intelligence models are accelerating and sophisticating cyberattack chains, shortening the window for firms to detect and remediate vulnerabilities. It urges firms, particularly medium-sized and smaller entities with less mature security or older systems, to strengthen baseline security, patching, monitoring and incident response, including anomaly detection, logging of administrative actions and alerts for high-risk events. The authority also notes that firms can deploy artificial intelligence defensively to identify and fix vulnerabilities more quickly.
Australian Prudential Regulation Authority details intensified AI cyber and private credit supervision and action against five super trustees
The Australian Prudential Regulation Authority told a parliamentary committee the financial system remains resilient but faces a more volatile risk environment, and it is intensifying supervision of AI governance, cyber resilience, supplier concentration and private credit spillover risks. It cited higher capital overlays, licence conditions on several entities, a Financial Accountability Regime disqualification, and enforcement against five platform trustees for investment governance failings, while leaving macroprudential settings unchanged. APRA plans further remediation and possible prudential changes for platform trustees, is finalising a supervisory plan for AI risks, and will publish Phase 2 system stress test findings in mid-2026, followed by results of a joint bank stress test with the Reserve Bank of New Zealand.
Canada's Office of the Superintendent of Financial Institutions tells committee it is adapting supervision toward earlier risk detection and streamlined oversight
In committee remarks, the Office of the Superintendent of Financial Institutions said it is adapting supervision to address rising global risks through earlier risk identification, clearer accountability, operational resilience and more focused risk-based oversight. It also said it will simplify parts of its regulatory framework and apply a more proportionate approach where that can support growth, competition and new entrants without weakening resilience. OSFI added that access to financing for small- and medium-sized enterprises also depends on banks adjusting their risk appetite and business models.
U.S. Senate Committee on Banking, Housing and Urban Affairs Ranking Member Elizabeth Warren urges Treasury to strengthen financial sector cybersecurity over Mythos-class AI threats
Senator Elizabeth Warren, Ranking Member of the Senate Banking Committee, sent a letter urging Treasury Secretary Scott Bessent to strengthen financial sector cybersecurity and reverse what she called a deregulatory approach. She warned that emerging AI systems, including Anthropic’s Claude Mythos, could help attackers exploit vulnerabilities, and called for stronger rules on bank supervision, vendor oversight, and threat information sharing, citing rising data breaches and cuts to government cyber resources.
France's Financial Markets Authority urges regulated firms to strengthen cyber resilience against AI-driven threats
The France Autorité des marchés financiers has made cyber resilience a strategic priority in its 2026 action plan, warning that advances in artificial intelligence can accelerate exploitation of vulnerabilities and scale malicious campaigns. It will supervise compliance with the Digital Operational Resilience Act for portfolio management companies, crypto-asset and crowdfunding service providers and market infrastructures, and expects firms to strengthen cyber risk frameworks, governance and testing. The authority plans further awareness actions, surveys and inspections in 2026, and will publish a first review of major incidents after the European Supervisory Authorities issue their report.
European Insurance and Occupational Pensions Authority and other ESAs publish first DORA annual overview showing one third of major ICT incidents were cross border
The European Insurance and Occupational Pensions Authority, the European Banking Authority and the European Securities and Markets Authority published the first annual overview of major ICT incidents under the Digital Operational Resilience Act, based on 3,383 incidents (0.18 per entity) and highlighting increasingly borderless ICT risk. Around one third had cross-border impact, system failures and external events were the main drivers, and only 10% were cybersecurity-related, underscoring the need for stronger third-party risk management, closer oversight of outsourced services and enhanced cybersecurity.
European Central Bank warns frontier AI is reshaping cyber risk and will send banks a dear CEO letter
The European Central Bank’s Frank Elderson warned that frontier artificial intelligence models are reshaping cyber risk and urged banks to treat operational resilience as a firm-wide strategic priority, announcing a forthcoming dear CEO letter calling for proactive measures to keep systems robust and secure. He noted vulnerabilities revealed by the 2024 cyber resilience stress test despite existing response and recovery frameworks and said almost three-quarters of findings have been addressed. Elderson underscored the role of the Digital Operational Resilience Act and said the ECB will follow up with banks in a targeted way, using its system-wide view to identify areas of attention and good practices, particularly for smaller banks.
Hong Kong Securities and Futures Commission urges licensed firms to strengthen cybersecurity against frontier AI enabled threats
The Hong Kong Securities and Futures Commission has issued a circular urging licensed firms, especially internet brokers and virtual asset trading platforms, to strengthen cybersecurity in response to emerging threats from frontier AI models. Citing rising cyber incidents and increasingly sophisticated AI-enabled attacks, the SFC calls for enhanced patching and vulnerability management, detection and monitoring, and incident response and recovery. It reiterates that senior management is primarily responsible for cyber resilience and will increase supervisory engagement, thematic reviews and enforcement where necessary.
Basel Committee on Banking Supervision publishes ICT risk management practices report focused on non-malicious incidents
The Basel Committee on Banking Supervision has published a report on information and communication technology risk management for non-malicious ICT incidents at banks, positioning these within operational risk and resilience. The report compares bank, regulatory and supervisory practices across jurisdictions and complements the Committee’s earlier cyber resilience work. The Committee will continue to monitor digitalisation and financial technology developments, including artificial intelligence models and their implications for banks’ cyber security.
Financial Services Regulatory Authority of Ontario issues final corporate governance and operational risk and resilience guidance for Ontario insurers
The Financial Services Regulatory Authority of Ontario has issued final Corporate Governance Guidance and Operational Risk and Resilience Guidance for Ontario-incorporated insurance companies and reciprocal insurance exchanges. The principles-based guidance sets expectations for governance, operational risk management and resilience to strengthen oversight and improve insurers’ ability to manage operational risk and respond to disruptions, informed by a prior public consultation and consultation summary report.
Financial Supervisory Authority of Norway flags high operational risk and AML documentation gaps in DNB's UK operations
The Financial Supervisory Authority of Norway published a supervisory report on DNB’s UK operations, identifying high operational risk in the London branch and calling for stronger governance, non-financial risk documentation and a more holistic risk view. It highlights critically high risks in external fraud, data management and key-person risk in IT, as well as operational risks from outsourcing know-your-customer processes to DNB Riga and heightened geopolitical risks for clients in international trade. DNB will introduce quarterly credit risk reports to the Management Committee from the second quarter of 2026 and strengthen anti-money laundering and counter-terrorist financing considerations in decision memoranda and branch controls.
Dutch Central Bank identifies cyber and operational risks from AI and geopolitics as major threats while banks remain resilient in war stress test
De Nederlandsche Bank’s semiannual Financial Stability Overview flags cyber and operational risks, driven by rapid advances in artificial intelligence and heightened geopolitical tensions, as a major threat to financial stability, with geo-economic fragmentation and prolonged higher energy prices remaining key risk drivers. Stress tests indicate Dutch banks can absorb losses from a Middle East conflict escalation within existing capital buffers, while the bank also highlights rising private credit exposures of large insurers and rapid global stablecoin market growth as emerging vulnerabilities.
Bank for International Settlements research finds ECB cyber stress test scrutiny raised cybersecurity investment by about 45% and by about 80% at laggard banks
The Bank for International Settlements published research showing that supervisory scrutiny alone can significantly increase banks’ cybersecurity spending, based on the European Central Bank’s 2024 cyber resilience stress test for 109 large euro area banks. The announcement of the qualitative test, which had no capital consequences and did not disclose bank-level results, was associated with a 45% rise in sector-wide cybersecurity investment, with prior underinvestors increasing spending by about 80% and adjusting outsourcing, staffing and cyber insurance in response to more intensive supervisory follow-up.
South Korea Financial Services Commission launches phased easing of network separation rules for AI cybersecurity at 49 large financial companies
South Korea’s Financial Services Commission announced measures to address cyber risks from advanced AI in finance, centred on phased easing of network separation rules so eligible firms can use AI and SaaS cybersecurity tools. It will grant one-year relief via no action letters to large institutions that pass expert screening, require vulnerability test reporting, and may fully lift network separation through the regulatory sandbox. The commission will also issue AI cybersecurity guidelines in June 2026.
State Bank of Vietnam governor urges banks to strengthen digital infrastructure data security and digital skills
The State Bank of Vietnam published remarks by Governor Pham Duc An outlining digitalisation priorities for the banking sector, including a stronger legal framework, expanded digital infrastructure and databases, enhanced cyber security and personal data protection, and improved workforce digital skills. He urged banks to centre citizens and businesses, treat data as foundational and technology as a driver, and advance digital payments, electronic authentication, biometric verification, data cleansing and anti-fraud measures linked to Project 06. The State Bank said contest proposals on process redesign, technology deployment, customer experience and system security will be further studied and implemented.
Australian Prudential Regulation Authority intensifies oversight as geopolitical shocks AI and private credit risks evolve
The Australian Prudential Regulation Authority’s latest System Risk Outlook finds Australia’s financial system remains resilient, with banks and insurers well capitalised and liquid, but notes intensified oversight and higher expectations for risk management amid geopolitical tensions, rapid artificial intelligence adoption and more complex global market linkages. APRA highlights AI governance and cyber resilience as central supervisory priorities, citing an April 2026 industry letter that set minimum expectations for board literacy, AI strategy, lifecycle accountability, supplier visibility, security testing and continuous monitoring. The report also notes that domestic private credit exposures remain contained at about AUD 200 billion, or 3 per cent of the banking system, but warns of growing offshore risks through international private market holdings and banks’ funds finance activities.
New York State Department of Financial Services issues cybersecurity guidance for heightened threat environments including frontier AI and geopolitical risks
The New York State Department of Financial Services issued non-binding guidance on cybersecurity measures DFS-regulated entities should consider when threats intensify, including during geopolitical events and following technological developments such as frontier AI models. Framed as actionable best practices rather than new legal requirements, the guidance groups measures into reducing the attack surface, improving threat detection and readiness, and strengthening resilience and response.
Financial Stability Board Regional Consultative Group for the Americas discusses 2026 priorities on operational resilience cross border payments and sovereign bond market risks
The Financial Stability Board’s Regional Consultative Group for the Americas met in Grand Cayman to review global and regional financial vulnerabilities and the FSB’s 2026 work priorities. Members discussed operational resilience, including cyber risks, cross-border payments action plans, regulatory and supervisory modernisation, and nonbank activity in sovereign bond markets and related data challenges.
Basel Committee on Banking Supervision agrees to publish ICT risk management report and advances cryptoasset and liquidity work
The Basel Committee on Banking Supervision will publish a report on observed ICT risk management practices for non-malicious incidents and advanced its review of the prudential standard for banks’ cryptoasset exposures. It will also assess whether to update its Principles for Sound Liquidity Risk Management and Supervision, finalise machine-readable Pillar 3 disclosures, consult on the treatment of cross-border exposures within the European banking union in the global systemically important bank framework, and deepen analytical work on banks’ management of physical risks from extreme weather events and the role of insurance.