Current thematic dossiers

Select a theme to view its dossier.

Cyber & operational resilience

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

Overview

This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.

What's new

  1. AsiaIndiaSecurities & Exchange Board of IndiaCooperation

    Securities and Exchange Board of India signs MoU with India's Department of Telecommunications to share intelligence to combat securities market fraud

    The Securities and Exchange Board of India signed a Memorandum of Understanding with the Department of Telecommunications to enable regular data and information sharing to combat fraud in the securities market. The arrangement leverages the Department of Telecommunications’ Digital Intelligence Platform for secure, real-time intelligence sharing and coordination against misuse of telecom resources linked to cybercrime and financial fraud.

  2. AsiaIndiaSecurities & Exchange Board of IndiaProjects and initiatives

    Securities and Exchange Board of India launches three IT platforms to centralise regulatory communications, digitise adjudication and automate cyber audit supervision

    The Securities and Exchange Board of India launched three IT solutions to streamline external engagement, enable paperless quasi-judicial proceedings, and enhance cybersecurity supervision. The Single Universal Platform for Communications centralises official communications, the e-adjudication portal digitises adjudication processes and integrates with SEBI’s Case Management System, and the AI-enabled Cyber-Sec Audit Compliance platform analyses cyber audit reports to identify compliance gaps, generate risk scores, and support risk-based supervision.

  3. Latin AmericaPeruSuperintendencia de Banca, Seguros y AFP del PeruPolicy and regulation

    Peru's Superintendency of Banking, Insurance and Private Pension Funds updates its sanctions regime with new very serious cyber and market conduct breaches

    Peru's Superintendency of Banking, Insurance and Private Pension Funds has revised its Regulation of Infractions and Sanctions across the financial system, insurance, pensions, market conduct and risk management, emphasizing cybersecurity and information security failures. Issued through SBS Resolution No. 01029-2026, the update introduces new very serious infractions for inadequate information protection causing data loss, theft, alteration or customer fraud, and adjusts rules on insurance intermediation, nullity of Private Pension System affiliation and early loan repayments.

  4. North AmericaUnited StatesU.S. Department of the TreasuryProjects and initiatives

    U.S. Department of the Treasury launches OCCIP initiative to share actionable cybersecurity intelligence with eligible digital asset firms

    The U.S. Department of the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection launched a new initiative to provide eligible U.S. digital asset firms and industry organizations with the same timely, actionable cybersecurity information it shares with traditional financial institutions. The programme is intended to help firms identify, prevent, and respond to cyber threats and advances recommendations from the President’s Working Group on Digital Asset Markets and the GENIUS Act principles on cybersecurity and operational resilience.

  5. North AmericaCanadaCanadian Investment Regulatory OrganizationStrategy and priorities

    Canadian Investment Regulatory Organization releases fiscal 2027 annual priorities focusing on final rulebook harmonization, cyber resilience and complaint handling timelines

    The Canadian Investment Regulatory Organization published its Annual Priorities for fiscal 2027, the final year of its 2025–2027 Strategic Plan, focusing on investor protection, market integrity and completing integration. Key workstreams include issuing a harmonized rulebook, advancing registration and continuing education reforms, enhancing complaint handling and investor protection, modernizing regulation through technology and the InnovateSafe sandbox, strengthening cyber resilience, and reviewing Universal Market Integrity Rules to better support smaller dealers and junior issuers.

  6. Latin AmericaChileChile Financial Market CommissionPolicy and regulation

    Chile Financial Market Commission launches six-week consultation on updated service outsourcing rules and a new provider reporting file

    The Chile Financial Market Commission is consulting on amendments to Chapter 20-7 of the Updated Compilation of Banking Regulations to update requirements for the externalization of services and introduce an ongoing information requirement via a new regulatory file. The proposal would align the outsourcing framework for banks and other supervised entities with recent international guidance, strengthen third-party and outsourcing risk management, and establish periodic reporting on provider registries, activities, and incidents to support supervision.

  7. AsiaSouth KoreaSouth Korea Financial Services CommissionSupervision

    South Korea Financial Services Commission requires real-time ledger-to-wallet reconciliation and tighter controls at virtual asset exchanges after Bithumb payout error

    The South Korea Financial Services Commission met with five major virtual asset exchanges and the Digital Asset Exchange Alliance to present inspection findings after Bithumb’s erroneous payout and to agree on stronger self-regulation and internal controls. Measures include near real-time ledger-to-wallet reconciliation, tighter controls and segregation for high-risk manual transactions, more frequent external verification, expanded disclosures, standardized internal control programs, semi-annual inspections and common risk governance standards. Separately, the Financial Supervisory Service found internal control deficiencies at Bithumb and plans sanctions procedures after legal review.

  8. Middle EastKuwaitCentral Bank of KuwaitProjects and initiatives

    Central Bank of Kuwait launches first Advanced Cybersecurity Leaders Program under Kafa’a initiative

    The Central Bank of Kuwait has launched the first Advanced Cybersecurity Leaders Program under the Kafa’a initiative, with Kuwaiti banks and the Kuwait Institute of Banking Studies, to build national cybersecurity capability for the banking sector, focusing on cloud security and technology risk resilience. Aimed at experienced Kuwaiti professionals, it offers advanced practical training, starting with an eight-week Cloud Environment Security track delivered with the SANS Institute, supports regulatory compliance, and prepares participants for GIAC certifications and senior leadership roles.

  9. AsiaPhilippinesCentral Bank of the PhilippinesPolicy and regulation

    Central Bank of the Philippines amends Peso RTGS incident management with one-hour participant reporting and two-hour fallback settlement triggers

    The Central Bank of the Philippines’ Peso Real-Time Gross Settlement Management Committee amended Section 1401.15 of the Manual of Regulations for Payment Systems to update incident management requirements for connectivity and system-availability issues affecting Peso RTGS operations. The rules clarify coordination with the Bangko Sentral to identify incident origin, impose stricter timelines and reporting obligations on participants, and set conditions for using alternative settlement mechanisms. The memorandum details available alternatives, including bilateral and multilateral netting, paying-agent arrangements, and business continuity procedures, while allowing the Bangko Sentral to refuse or defer processing of suspicious or non-compliant files.

  10. Latin AmericaChileChile Financial Market CommissionPolicy and regulation

    Chile Financial Market Commission consults on permitting limited continued use of coordinates cards for transaction authentication

    The Chile Financial Market Commission has launched a public consultation on amendments to General Rule No. 538 on minimum security and authentication standards for electronic transactions, to facilitate the transition to Reinforced Client Authentication by allowing certain clients to continue using coordinates cards. Issuers would be permitted to define specific client groups, based on objective criteria and reported to the Commission, that may retain coordinates cards, though such transactions would not qualify as Reinforced Client Authentication.

  11. North AmericaUnited StatesFinancial Industry Regulatory AuthorityProjects and initiatives

    Financial Industry Regulatory Authority launches Financial Intelligence Fusion Center portal for cybersecurity and fraud threat intelligence sharing

    The Financial Industry Regulatory Authority has launched the Financial Intelligence Fusion Center, a secure portal for FINRA and member firms to share timely cybersecurity and fraud threat intelligence and coordinate responses. The platform collects, analyzes and disseminates threat information, incorporates input from government and private sector partners, and expands FINRA’s existing cybersecurity and fraud-related resources for member firms.

  12. EuropeNetherlandsDutch Authority for the Financial MarketsOther

    Dutch Authority for the Financial Markets urges audit firms to adopt robust information security frameworks and shares supervisory strengthening points

    The Dutch Authority for the Financial Markets has issued guidance urging audit firms to strengthen information security and IT risk management in light of data leaks. Drawing on practices at public interest entity audit firms and De Nederlandsche Bank’s Good Practice on Information Security, the guidance highlights improvements in ICT risk processes, continuity and configuration management, supplier oversight, and incident learning. The authority says IT risk control will remain a supervisory priority and that it will continue engaging with the sector.

  13. North AmericaCanadaOffice of the Superintendent of Financial InstitutionsOther

    Office of the Superintendent of Financial Institutions sets out June 2026 streamlined approvals and proposed 75% risk weight for some SME loans

    The Office of the Superintendent of Financial Institutions outlined supervisory priorities, emphasizing heightened geopolitical, cyber, integrity and security risks, increased focus on non-bank financial intermediaries, and measured capital recalibration, including proposed lower risk weights for some SME loans and continued use of the 0–4% Domestic Stability Buffer. Work on non-bank intermediaries covers exposures, risk rating and governance, supported by a Credit Risk Management Guideline consultation, while synthetic risk transfer will be assessed on a substance-over-form basis. OSFI will also launch a modernized, streamlined approvals framework in June 2026 to provide a clearer, faster and more predictable path to a federal licence for eligible applicants such as credit unions and fintechs.

  14. EuropeDenmarkDanish FinanstilsynetOther

    Danish Financial Supervisory Authority survey finds geopolitics now matches cyber threats as the top stability risk for Danish financial firms

    The Danish Financial Supervisory Authority's 2026 survey of Danish financial firms highlights cyber threats and geopolitical conditions as the most significant risks to financial stability, with both rated equally for the first time. Firms noted increased vulnerability due to reliance on foreign IT suppliers and linked rising cyber risk to geopolitical tensions. Despite these concerns, firms expressed high confidence in the stability of the Danish financial system over the next three years.

  15. Middle EastUnited Arab EmiratesDubai Financial Services AuthorityPolicy and regulation

    Dubai Financial Services Authority launches consultation on operational resilience

    The Dubai Financial Services Authority issued Consultation Paper No. 170 on operational resilience for consultation. The paper sets out proposed requirements to enhance firms’ ability to withstand, adapt to and recover from operational disruptions.

  16. EuropeFranceFrance Autorite des marches financiersPolicy and regulation

    France's Financial Markets Authority revises guidance for portfolio management companies including mandatory DORA resilience information and streamlined authorisation withdrawals

    France's Financial Markets Authority (AMF) has updated its supervisory doctrine for portfolio management companies, aligning it with regulatory developments and clarifying compliance with the EU Digital Operational Resilience Act (DORA). The update includes guidance on staffing, authorisation withdrawals, life-insurance arbitration mandates, own funds calculations, and ancillary loan mandates. Firms must update their activity programmes within six months to comply with the new DORA documentation requirements.

  17. AfricaGhanaBank of GhanaProjects and initiatives

    Bank of Ghana launches revised Cyber and Information Security Directive 2026 tightening AI governance cloud security and board accountability

    The Bank of Ghana has launched the revised Cyber and Information Security Directive 2026, updating standards for banks and digital financial participants. Key elements include AI and machine learning governance, cloud computing security with data sovereignty, and a proportionality framework for scaling requirements. The directive mandates board-level cyber risk expertise and expands the Financial Industry Command Security Operations Centre's coverage to include more financial institutions.

  18. EuropeUnited KingdomFinancial Conduct AuthoritySupervision

    Financial Conduct Authority publishes post-transition findings from operational resilience self-assessments and highlights areas for firms to improve

    The Financial Conduct Authority has published supervisory observations from firms’ annual operational resilience self-assessments to reinforce compliance with its framework, highlighting stronger practices and areas needing improvement in impact tolerances, mapping, scenario testing, vulnerability management, communications and governance. In related joint material with the Bank of England and the Prudential Regulation Authority, the authorities set out effective practices for responding to and recovering from high-severity cyber disruption and signal they will continue requesting periodic self-assessments as firms reassess their ability to remain within impact tolerances.

  19. EuropeEuropeEuropean Central Bank - Banking SupervisionProjects and initiatives

    European Central Bank Banking Supervision sets Digital Operational Resilience Act priorities on ICT change risk, third-party dependencies and threat-led penetration testing

    The European Central Bank Banking Supervision is using the EU Digital Operational Resilience Act to intensify oversight of banks’ digital and operational resilience, focusing on ICT change management, third-party risk and cyber testing. Expanded incident reporting shows 38% of major incidents in 2025 stemmed from IT change, while rising cloud reliance and delays in contract renegotiations and business continuity planning have heightened scrutiny of third-party risk management. An EU-level framework now oversees 19 critical ICT providers. The ECB will conduct an on-site campaign on ICT third-party risk management and launch a three-year threat-led penetration testing cycle, with over 80 banking groups already notified.

  20. Latin AmericaBrazilCentral Bank of BrazilProjects and initiatives

    Central Bank of Brazil strengthens Conta PI security with minimum balance thresholds automatic blocking and an alternative statement channel

    The Central Bank of Brazil has introduced measures to enhance operational security and management of the Instant Payments Account (Conta PI) within the Instant Payments System (SPI). These measures include setting a minimum operational balance, automatic blocking options, and an alternative channel for accessing Conta PI statements during network outages. These enhancements are part of the central bank's Agenda BC and the second phase of a toolset to strengthen the payments ecosystem.

  21. PacificAustraliaCouncil of Financial RegulatorsStrategy and priorities

    Council of Financial Regulators flags elevated geopolitical and cyber risks and agrees 2026 crisis preparedness workplan

    The Council of Financial Regulators said global financial stability risks have increased, while direct Australian exposures to the Middle East remain limited. It urged banks to maintain strong capital and liquidity, called for prudent lending standards, and agreed a workplan to strengthen crisis preparedness for capital and liquidity stress scenarios. The Council also advanced joint work on cyber resilience and said it will publish actions to streamline regulatory data collection and sharing in the first half of 2026.

  22. EuropePolandPolish Financial Supervision Commission (KNF)Data and reporting

    Polish Financial Supervision Commission publishes CSIRT KNF Annual Cybersecurity Report 2025 highlighting supply chain threats and DORA incident reporting volumes

    The Polish Financial Supervision Commission's CSIRT published its Annual Report on Cybersecurity 2025, highlighting a complex cyberthreat landscape with increased attacks on technology and IT service providers, raising supply chain risks. The report details 41,751 dangerous domains, 9,751 blocked fraudulent ads, and 787 DDoS attacks, alongside 274 ICT incident reports under DORA. CSIRT KNF issued 625 threat warnings and 70 recommendations, noting heightened ransomware activity and proactive monitoring of data-leak publications.

  23. AsiaTaiwanTaiwan Financial Services CommissionSupervision

    Taiwan Financial Supervisory Commission publishes 2025 H2 examination findings and corrective actions across 12 sectors

    The Taiwan Financial Supervisory Commission published financial examination findings for the second half of 2025 across 12 sectors, highlighting systemic deficiencies in AML/CFT/CPF, customer protection, cyber security, and real estate lending. Issues include weak onboarding and monitoring of high-risk customers, incomplete insurance and ETF disclosures, inadequate controls over personal data and privileged accounts, and insufficient scrutiny of lending to speculators and vacant-land projects. The authority will continue publishing findings and corrective actions to signal priorities and support stronger controls.

  24. EuropeUnited KingdomBank of EnglandPolicy and regulation

    Bank of England finalises IOREP operational incident and third-party reporting rules for FMIs effective 18 March 2027 and consults on revoking duplicate CCP incident reporting rule

    The Bank of England has finalized its IOREP rules for financial market infrastructures, standardizing the reporting of significant operational incidents and third-party arrangements to boost resilience. Applicable to UK central counterparties, securities depositories, payment operators, and service providers, reporting via Financial Conduct Authority platforms starts 18 March 2027. The Bank is consulting on revoking duplicative reporting for central counterparties, aligning with IOREP.