Current thematic dossiers

Select a theme to view its dossier.

Cyber & operational resilience

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

Overview

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

  1. GlobalGlobalINTERPOLOther

    INTERPOL reports first MENA cybercrime operation led to 201 arrests and 53 servers seized

    INTERPOL reported the results of Operation Ramz, a coordinated cybercrime enforcement action across 13 Middle East and North Africa countries from October 2025 to 28 February 2026, targeting phishing, malware and cyber scams. The operation led to 201 arrests, 382 additional suspects identified, 3,867 victims identified, 53 servers seized and the exchange of nearly 8,000 pieces of data and intelligence, and was described as the first cyber operation of this scale that INTERPOL has coordinated in the region.

  2. EuropeUnited KingdomFinancial Conduct AuthorityOther

    United Kingdom's Financial Conduct Authority, Bank of England and HM Treasury reinforce cyber resilience steps for firms facing frontier AI threats

    The Financial Conduct Authority, Bank of England and HM Treasury issued a joint statement warning that frontier artificial intelligence models materially increase cyber risk for regulated firms and financial market infrastructures, reiterating that firms must address these risks under existing operational resilience requirements. The authorities highlight expectations around governance, vulnerability management, third-party risk, protection, and response and recovery, and direct firms to cyber resilience practices and guidance from the Cross Market Operational Resilience Group and the National Cyber Security Centre.

  3. AsiaJapanJapan Financial Services AgencyOrganizational affairs

    Japan Financial Services Agency convenes working group on AI related cyber threats in the financial sector

    The Japan Financial Services Agency has established a working group under its public private partnership conference to strengthen financial sector cybersecurity against artificial intelligence-related threats. The group brings together financial institutions, technology providers, industry associations and government bodies, including the Bank of Japan, to build a shared understanding of AI-driven cyber risks and consider countermeasures, with discussions confidential due to their cybersecurity sensitivity.

  4. EuropeGermanyBaFinEvents and speeches

    Germany's Federal Financial Supervisory Authority sets supervisory focus on cyber threats private debt and risky mortgages

    At its annual press conference, Germany's Federal Financial Supervisory Authority said consumer protection and financial stability are equal priorities and flagged cyber risk, private debt and risky residential mortgage lending as key supervisory concerns. BaFin is adding resources to cyber inspections, warned about liquidity and transparency risks in retail private-markets products such as ELTIFs, and said supervisory action on higher-risk new mortgages remains possible. It also pointed to tougher enforcement against unauthorized business, including more than 800 fraud warnings in 2025.

  5. EuropeAlbaniaMinistry of Finance (Albania)Events and speeches

    Albania's Ministry of Finance highlights near complete digitalisation of public finance processes and renewed anti-money laundering focus at cyber security summit

    Albania’s Finance Minister Petrit Malaj told the Albania-Israel Cyber Security Summit that protecting public financial systems is a strategic national priority and reaffirmed the government’s commitment to strengthening the legal and institutional framework against money laundering and terrorist financing. He cited progress in modernising public finance administration through digitalisation, interoperability and efficiency, and stressed international cooperation, including using Israel’s cyber security and data protection experience, to build more secure and transparent financial systems.

  6. EuropeAlbaniaBank of AlbaniaEvents and speeches

    Bank of Albania says first full banking system cybersecurity assessment under 93 controls is complete and DORA alignment is under way

    The Bank of Albania has completed its first full cybersecurity assessment cycle for the entire banking system using a U.S. Treasury-assisted methodology based on 93 controls and is conducting a horizontal reassessment. Governor Gent Sejko said cyber risk regulation and supervision have been a strategic priority, with efforts focused on supervisory capacity, cooperation with domestic authorities, adoption of international standards, and alignment with EU rules. Work is under way to harmonise the framework with the Digital Operational Resilience Act, with assessments to be repeated until consistent cybersecurity maturity is achieved across all banks.

  7. Middle EastMiddle EastMiddle East and North Africa Financial Action Task Force (MENAFATF)Strategy and priorities

    Middle East and North Africa Financial Action Task Force sets plenary priorities on faster financial crime response and five ongoing mutual evaluations

    The Middle East and North Africa Financial Action Task Force set strategic priorities under its current presidency to enhance faster, more flexible responses to organised crime, fraud and cyber threats, with a work programme focused on strengthening the presidency framework, advancing institutional development and overseeing the third round of mutual evaluations. Launched last year, this round now covers five countries at different stages, and MENAFATF has also created its first forum for research and training centres to integrate academia into regional efforts against financial crime.

  8. EuropeSwedenFinansinspektionenProjects and initiatives

    Sweden's Financial Supervisory Authority opens registration for FTPOS 2026 financial sector crisis exercise

    Sweden’s Financial Supervisory Authority has invited public and private actors in the financial services preparedness sector to participate in FTPOS Sector Exercise 2026, a tabletop and functional exercise aimed at strengthening sector-wide coordination and crisis management through realistic scenarios. The exercise targets authorities, banks, insurance companies, securities firms, central infrastructure organisations and cash-handling actors, and is structured around situational awareness and reporting, sector focus areas, and communication and common messaging.

  9. PacificAustraliaAustralian Securities & Investments CommissionAlert and warning

    Australian Securities & Investments Commission warns licensees and market participants to urgently strengthen cyber resilience as frontier AI raises cyber risk

    The Australian Securities & Investments Commission has issued an open letter urging all licensees and market participants to strengthen cyber resilience as frontier AI increases the speed, scale and sophistication of cyber threats. ASIC reiterates that cyber resilience is a core licensing obligation requiring board and executive leadership, references its recent court outcome against FIIG Securities Limited, and sets expectations for effective, proportionate cyber risk controls and governance. The letter must be tabled at boards and risk governance committees and directs firms to Australian Government guidance as ASIC coordinates with other regulators to promote consistent expectations.

  10. EuropeNorwayNorwegian FinanstilsynetPolicy and regulation

    The Financial Supervisory Authority of Norway updates DORA incident reporting guidance and clarifies 72 hour status reporting and one month final report deadlines

    The Financial Supervisory Authority of Norway has updated its guidance on incident reporting under the Digital Operational Resilience Act, clarifying when firms must submit status and final reports following serious ICT-related incidents. It specifies timelines and triggers for initial and subsequent status reports, confirms that remedial actions need not be completed before the final report, and updates the Altinn incident reporting form to allow firms to enter future dates for handling root causes and expected resolution.

  11. GlobalGlobalInternational Monetary FundResearch

    International Monetary Fund analysis warns AI-enabled cyberattacks could trigger systemic financial stress

    The International Monetary Fund warns that advances in artificial intelligence are increasing the scale and speed of cyberattacks on the financial system and could turn extreme cyber incidents into macro-financial shocks. It urges supervisors to treat cybersecurity as a core financial stability issue by strengthening resilience standards, oversight of systemic transmission channels, and public-private coordination, while noting that AI can also enhance cyber defenses if supported by appropriate investment, governance, oversight and cooperation.

  12. AsiaIndiaSecurities & Exchange Board of IndiaPolicy and regulation

    Securities & Exchange Board of India issues advisory on AI led vulnerability detection risks and creates cyber-suraksha.ai task force

    The Securities & Exchange Board of India has warned securities market intermediaries about cyber risks from advanced AI tools and created a cyber-suraksha.ai task force for a coordinated response. The task force will assess AI-driven cybersecurity risks, develop a uniform mitigation strategy, facilitate threat intelligence sharing, and review third-party providers. SEBI’s advisory sets expectations for immediate and virtual patching, enhanced vulnerability assessments and SOC monitoring, stronger vendor and API controls, and longer-term plans for AI-based detection and mitigation.

  13. EuropeEuropeEuropean Central BankResearch

    European Central Bank working paper finds cyber stress test scrutiny drove about 80 percent higher cybersecurity investment at laggard banks

    The European Central Bank has published a working paper on its 2024 Cyber Resilience Stress Test, finding that supervisory scrutiny was associated with materially higher cybersecurity investment by euro area banks that had previously underinvested relative to their cyber risk profiles. Using confidential data for 109 Significant Institutions from 2019 to 2024, the authors estimate that the March 2023 announcement of the exercise was followed by an average 45 percent increase in cybersecurity investment across the sector and about 80 percent among laggard banks. The paper is presented as research and states that the views are those of the authors and do not necessarily reflect those of the European Central Bank.

  14. EuropeNorwayNorwegian FinanstilsynetOther

    Norwegian Financial Supervisory Authority finds financial sector preparedness sound but flags high cyber threats and third party vulnerabilities

    The Norwegian Financial Supervisory Authority’s 2026 risk and vulnerability analysis finds Norway’s financial infrastructure remains robust, with satisfactory operational stability and payment service availability. However, it assesses the digital threat level as high, driven by organised criminal groups, state actors, wider use of artificial intelligence and heightened geopolitical tensions, and highlights supplier and value chain risk as a critical vulnerability. The authority notes new rules requiring firms to manage third-party risk, identify critical suppliers and maintain exit options.

  15. EuropeEuropeEuropean Insurance and Occupational Pensions AuthorityData and reporting

    European Insurance and Occupational Pensions Authority says European insurance sector risks remain stable at medium level in April 2026 dashboard

    The European Insurance and Occupational Pensions Authority has published its April 2026 Insurance Risk Dashboard, assessing overall risks in the European insurance sector as stable at a medium level. Market risk has increased amid higher bond and equity volatility, while other key risks remain at medium levels, supported by strong capital positions, premium growth and stable underwriting, though geopolitical, inflation, marine/aviation/trade-related and cyber risks continue to weigh on the outlook. The assessment is based on fourth quarter 2025 and end-2024 Solvency II data from 94 insurance groups and 2,092 solo undertakings.

  16. PacificAustraliaAustralian Prudential Regulation AuthorityPolicy and regulation

    Australian Prudential Regulation Authority finalises CPS 230 amendments granting limited contractual exemptions for certain non-traditional service providers

    The Australian Prudential Regulation Authority has finalised targeted amendments to Prudential Standard CPS 230 Operational Risk Management, Prudential Practice Guide CPG 230 and the Material Service Provider Register template. The changes introduce limited exemptions from certain contractual requirements for material arrangements with specified non-traditional service providers, including central banks and clearing and settlement facilities, and clarify expectations for managing these arrangements and reporting on exempt providers.

  17. Latin AmericaBrazilCentral Bank of BrazilProjects and initiatives

    Central Bank of Brazil convenes cyber resilience forum for critical providers and says cybersecurity rulemaking will continue

    The Central Bank of Brazil convened the BC Cyber Resilience Forum 2026 Critical Providers to discuss cybersecurity and operational resilience in the National Financial System, stating that cyber risk has become a structural risk for financial stability and that its cybersecurity regulatory agenda will continue. Officials emphasized coordinated action across critical technology providers, robust third-party risk management and secure arrangements for services such as Pix and the Reserve Transfer System. The central bank reported a sharp increase in critical incident reports and incidents involving diversion of financial institutions’ funds between 2020 and 2025 and signalled it will continue to assess potential regulatory enhancements.

  18. EuropePortugalPortuguese Insurance Regulator (ASF)Policy and regulation

    Portugal's Insurance and Pension Funds Supervisory Authority sets DORA reporting rules for insurers pension managers and certain insurance intermediaries

    Portugal’s Insurance and Pension Funds Supervisory Authority has amended its reporting framework to implement the EU Digital Operational Resilience Act for insurers, reinsurers, pension fund managers and larger insurance intermediaries. Covered entities must report registers of third-party ICT service contracts, planned ICT arrangements supporting critical or important functions, severe ICT-related incidents and, voluntarily, significant cyber threats, and maintain ICT risk management review reports and cost and loss estimates for ASF review. The amendments repeal prior ASF rules on ICT security, cloud outsourcing and ICT incident reporting to eliminate overlaps.

  19. AsiaJapanJapan Financial Services AgencyProjects and initiatives

    Japan Financial Services Agency establishes finance sector cybersecurity working group to address AI driven threats

    The Japan Financial Services Agency has established a public-private working group on financial sector cybersecurity, described as a Japanese version of “Project Glasswing”, to coordinate responses to AI-driven cyber risks. The initiative aims to accelerate information sharing on vulnerabilities, shorten the time from identification to patch application, and strengthen preparedness for incidents in the highly interconnected, real-time financial system, with potential expansion to include IT firms, online finance participants, and engagement with international counterparts through G7 and G20 forums.

  20. AsiaPhilippinesCentral Bank of the PhilippinesPolicy and regulation

    Central Bank of the Philippines introduces a Cybersecurity Maturity Framework and mandates Cybersecurity Control Self-Assessment reporting

    The Central Bank of the Philippines has amended IT risk management rules for banks and non-bank financial institutions, replacing the IT Rating System with the Supervisory Assessment Framework and introducing a Cybersecurity Maturity Framework supported by a mandatory Cybersecurity Control Self-Assessment. The framework defines four maturity tiers aligned to institutions’ IT profile classifications and requires annual IT Profile and Cybersecurity Control Self-Assessment submissions via the Advanced SupTech Engine for Risk-based Compliance platform.

  21. EuropeFranceBank of FranceOther

    Bank of France and ACPR urge financial institutions to start preparing for post-quantum cryptography migration

    The Bank of France and the French Prudential Supervision and Resolution Authority warned that advances in cryptographically relevant quantum computers could, over the medium term, break current cryptographic protections used across the financial sector and urged institutions to plan migration to post-quantum cryptography. The note emphasises “harvest now, decrypt later” risks, identifies governance, asset inventory, data sensitivity and crypto-agility as core elements of a long-term migration programme, and aligns with G7 and European post-quantum roadmaps targeting dominant adoption by 2030. The ACPR has launched a 2026 interview cycle with financial sector participants and encourages proactive internal roadmaps, resilience testing and participation in standard-setting.

  22. CaribbeanDominican RepublicCentral Bank of the Dominican RepublicPolicy and regulation

    Central Bank of the Dominican Republic publishes comprehensive amendments to the operational risk regulation extending scope to exchange and remittance agents

    The Central Bank of the Dominican Republic announced that the Monetary Board has approved a comprehensive revision of the Regulation on Operational Risk, updating governance, risk management, control and capitalisation standards for financial and foreign exchange intermediation entities. The reform expands the regulatory perimeter to include exchange agents and remittance and exchange agents, which must maintain proportionate frameworks to prevent, detect and mitigate incidents affecting operational continuity and information integrity.

  23. AsiaIndiaIndia International Financial Services Centres AuthorityPolicy and regulation

    India International Financial Services Centres Authority issues cyber security and resilience guidelines for GIFT IFSC market infrastructure institutions with 6-hour incident reporting and ISO 27001 certification

    The India International Financial Services Centres Authority has issued Guidelines on Cyber Security and Cyber Resilience for Market Infrastructure Institutions in IFSC, establishing a prescriptive framework for stock exchanges, clearing corporations, depositories and the bullion exchange in GIFT IFSC. The rules require Board-approved cyber policies, a Chief Information Security Officer reporting to the MD/CEO, 24x7 Security Operations Centres, rapid incident reporting to the authority and CERT-In, post-quantum cryptography roadmaps, third-party risk controls and ISO 27001 certification. The Guidelines took effect on 1 April 2026, with Market Infrastructure Institutions required to achieve full compliance within specified timelines.

  24. AsiaJapanJapan Financial Services AgencySupervision

    Japan Financial Services Agency updates supervisory guidance to promote phishing-resistant multi-factor authentication and issues joint anti-phishing awareness materials

    The Japan Financial Services Agency has outlined a public-private, cross-industry initiative on phishing-resistant multi-factor authentication and phishing awareness, and is revising its supervisory and administrative guidelines to incorporate phishing-resistant MFA in response to rising phishing-related illegal remittances and transactions. The initiative includes jointly developed awareness materials by financial institutions, the Japan Financial Services Agency and the National Police Agency, comprising promotional flyers and videos explaining phishing-resistant MFA and warning about phishing emails.

  25. GlobalGlobalBank for International Settlements - Financial Stability InstituteProjects and initiatives

    Bank for International Settlements' Financial Stability Institute reviews emerging practices for cyber risk stress testing of banks

    The Bank for International Settlements’ Financial Stability Institute published a brief on how authorities use cyber stress tests to assess banks’ resilience to severe cyber disruptions and potential financial stability impacts. Drawing on exercises by the Bank of England, the Danish Financial Supervisory Authority and ECB Banking Supervision, it distinguishes firm- and system-focused models, notes that tests are typically qualitative tabletop exercises with limited disclosure, and calls for repeated exercises, greater methodological transparency, broader participation and better planning for authorities’ crisis coordination.