What's new
Overview
This deep dive takes stock of recent developments in cyber and operational resilience, including current supervisory risk watch points, the direction of policy and guidance as well as evolving supervisory practices.
What's new
Securities and Exchange Board of India signs MoU with India's Department of Telecommunications to share intelligence to combat securities market fraud
The Securities and Exchange Board of India signed a Memorandum of Understanding with the Department of Telecommunications to enable regular data and information sharing to combat fraud in the securities market. The arrangement leverages the Department of Telecommunications’ Digital Intelligence Platform for secure, real-time intelligence sharing and coordination against misuse of telecom resources linked to cybercrime and financial fraud.
Securities and Exchange Board of India launches three IT platforms to centralise regulatory communications, digitise adjudication and automate cyber audit supervision
The Securities and Exchange Board of India launched three IT solutions to streamline external engagement, enable paperless quasi-judicial proceedings, and enhance cybersecurity supervision. The Single Universal Platform for Communications centralises official communications, the e-adjudication portal digitises adjudication processes and integrates with SEBI’s Case Management System, and the AI-enabled Cyber-Sec Audit Compliance platform analyses cyber audit reports to identify compliance gaps, generate risk scores, and support risk-based supervision.
Peru's Superintendency of Banking, Insurance and Private Pension Funds updates its sanctions regime with new very serious cyber and market conduct breaches
Peru's Superintendency of Banking, Insurance and Private Pension Funds has revised its Regulation of Infractions and Sanctions across the financial system, insurance, pensions, market conduct and risk management, emphasizing cybersecurity and information security failures. Issued through SBS Resolution No. 01029-2026, the update introduces new very serious infractions for inadequate information protection causing data loss, theft, alteration or customer fraud, and adjusts rules on insurance intermediation, nullity of Private Pension System affiliation and early loan repayments.
U.S. Department of the Treasury launches OCCIP initiative to share actionable cybersecurity intelligence with eligible digital asset firms
The U.S. Department of the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection launched a new initiative to provide eligible U.S. digital asset firms and industry organizations with the same timely, actionable cybersecurity information it shares with traditional financial institutions. The programme is intended to help firms identify, prevent, and respond to cyber threats and advances recommendations from the President’s Working Group on Digital Asset Markets and the GENIUS Act principles on cybersecurity and operational resilience.
Canadian Investment Regulatory Organization releases fiscal 2027 annual priorities focusing on final rulebook harmonization, cyber resilience and complaint handling timelines
The Canadian Investment Regulatory Organization published its Annual Priorities for fiscal 2027, the final year of its 2025–2027 Strategic Plan, focusing on investor protection, market integrity and completing integration. Key workstreams include issuing a harmonized rulebook, advancing registration and continuing education reforms, enhancing complaint handling and investor protection, modernizing regulation through technology and the InnovateSafe sandbox, strengthening cyber resilience, and reviewing Universal Market Integrity Rules to better support smaller dealers and junior issuers.
Chile Financial Market Commission launches six-week consultation on updated service outsourcing rules and a new provider reporting file
The Chile Financial Market Commission is consulting on amendments to Chapter 20-7 of the Updated Compilation of Banking Regulations to update requirements for the externalization of services and introduce an ongoing information requirement via a new regulatory file. The proposal would align the outsourcing framework for banks and other supervised entities with recent international guidance, strengthen third-party and outsourcing risk management, and establish periodic reporting on provider registries, activities, and incidents to support supervision.
South Korea Financial Services Commission requires real-time ledger-to-wallet reconciliation and tighter controls at virtual asset exchanges after Bithumb payout error
The South Korea Financial Services Commission met with five major virtual asset exchanges and the Digital Asset Exchange Alliance to present inspection findings after Bithumb’s erroneous payout and to agree on stronger self-regulation and internal controls. Measures include near real-time ledger-to-wallet reconciliation, tighter controls and segregation for high-risk manual transactions, more frequent external verification, expanded disclosures, standardized internal control programs, semi-annual inspections and common risk governance standards. Separately, the Financial Supervisory Service found internal control deficiencies at Bithumb and plans sanctions procedures after legal review.
Central Bank of Kuwait launches first Advanced Cybersecurity Leaders Program under Kafa’a initiative
The Central Bank of Kuwait has launched the first Advanced Cybersecurity Leaders Program under the Kafa’a initiative, with Kuwaiti banks and the Kuwait Institute of Banking Studies, to build national cybersecurity capability for the banking sector, focusing on cloud security and technology risk resilience. Aimed at experienced Kuwaiti professionals, it offers advanced practical training, starting with an eight-week Cloud Environment Security track delivered with the SANS Institute, supports regulatory compliance, and prepares participants for GIAC certifications and senior leadership roles.
Central Bank of the Philippines amends Peso RTGS incident management with one-hour participant reporting and two-hour fallback settlement triggers
The Central Bank of the Philippines’ Peso Real-Time Gross Settlement Management Committee amended Section 1401.15 of the Manual of Regulations for Payment Systems to update incident management requirements for connectivity and system-availability issues affecting Peso RTGS operations. The rules clarify coordination with the Bangko Sentral to identify incident origin, impose stricter timelines and reporting obligations on participants, and set conditions for using alternative settlement mechanisms. The memorandum details available alternatives, including bilateral and multilateral netting, paying-agent arrangements, and business continuity procedures, while allowing the Bangko Sentral to refuse or defer processing of suspicious or non-compliant files.
Chile Financial Market Commission consults on permitting limited continued use of coordinates cards for transaction authentication
The Chile Financial Market Commission has launched a public consultation on amendments to General Rule No. 538 on minimum security and authentication standards for electronic transactions, to facilitate the transition to Reinforced Client Authentication by allowing certain clients to continue using coordinates cards. Issuers would be permitted to define specific client groups, based on objective criteria and reported to the Commission, that may retain coordinates cards, though such transactions would not qualify as Reinforced Client Authentication.
Financial Industry Regulatory Authority launches Financial Intelligence Fusion Center portal for cybersecurity and fraud threat intelligence sharing
The Financial Industry Regulatory Authority has launched the Financial Intelligence Fusion Center, a secure portal for FINRA and member firms to share timely cybersecurity and fraud threat intelligence and coordinate responses. The platform collects, analyzes and disseminates threat information, incorporates input from government and private sector partners, and expands FINRA’s existing cybersecurity and fraud-related resources for member firms.
Dutch Authority for the Financial Markets urges audit firms to adopt robust information security frameworks and shares supervisory strengthening points
The Dutch Authority for the Financial Markets has issued guidance urging audit firms to strengthen information security and IT risk management in light of data leaks. Drawing on practices at public interest entity audit firms and De Nederlandsche Bank’s Good Practice on Information Security, the guidance highlights improvements in ICT risk processes, continuity and configuration management, supplier oversight, and incident learning. The authority says IT risk control will remain a supervisory priority and that it will continue engaging with the sector.
Office of the Superintendent of Financial Institutions sets out June 2026 streamlined approvals and proposed 75% risk weight for some SME loans
The Office of the Superintendent of Financial Institutions outlined supervisory priorities, emphasizing heightened geopolitical, cyber, integrity and security risks, increased focus on non-bank financial intermediaries, and measured capital recalibration, including proposed lower risk weights for some SME loans and continued use of the 0–4% Domestic Stability Buffer. Work on non-bank intermediaries covers exposures, risk rating and governance, supported by a Credit Risk Management Guideline consultation, while synthetic risk transfer will be assessed on a substance-over-form basis. OSFI will also launch a modernized, streamlined approvals framework in June 2026 to provide a clearer, faster and more predictable path to a federal licence for eligible applicants such as credit unions and fintechs.
Danish Financial Supervisory Authority survey finds geopolitics now matches cyber threats as the top stability risk for Danish financial firms
The Danish Financial Supervisory Authority's 2026 survey of Danish financial firms highlights cyber threats and geopolitical conditions as the most significant risks to financial stability, with both rated equally for the first time. Firms noted increased vulnerability due to reliance on foreign IT suppliers and linked rising cyber risk to geopolitical tensions. Despite these concerns, firms expressed high confidence in the stability of the Danish financial system over the next three years.
Dubai Financial Services Authority launches consultation on operational resilience
The Dubai Financial Services Authority issued Consultation Paper No. 170 on operational resilience for consultation. The paper sets out proposed requirements to enhance firms’ ability to withstand, adapt to and recover from operational disruptions.
Bank of Italy and Guardia di Finanza sign cybersecurity cooperation and information-sharing agreement
The Bank of Italy and the Guardia di Finanza have signed a cooperation and information-sharing agreement to enhance cybersecurity measures. The agreement aims to improve prevention and protection against cyberattacks by utilizing the expertise of both institutions.
France's Financial Markets Authority revises guidance for portfolio management companies including mandatory DORA resilience information and streamlined authorisation withdrawals
France's Financial Markets Authority (AMF) has updated its supervisory doctrine for portfolio management companies, aligning it with regulatory developments and clarifying compliance with the EU Digital Operational Resilience Act (DORA). The update includes guidance on staffing, authorisation withdrawals, life-insurance arbitration mandates, own funds calculations, and ancillary loan mandates. Firms must update their activity programmes within six months to comply with the new DORA documentation requirements.
Bank of Ghana launches revised Cyber and Information Security Directive 2026 tightening AI governance cloud security and board accountability
The Bank of Ghana has launched the revised Cyber and Information Security Directive 2026, updating standards for banks and digital financial participants. Key elements include AI and machine learning governance, cloud computing security with data sovereignty, and a proportionality framework for scaling requirements. The directive mandates board-level cyber risk expertise and expands the Financial Industry Command Security Operations Centre's coverage to include more financial institutions.
Financial Conduct Authority publishes post-transition findings from operational resilience self-assessments and highlights areas for firms to improve
The Financial Conduct Authority has published supervisory observations from firms’ annual operational resilience self-assessments to reinforce compliance with its framework, highlighting stronger practices and areas needing improvement in impact tolerances, mapping, scenario testing, vulnerability management, communications and governance. In related joint material with the Bank of England and the Prudential Regulation Authority, the authorities set out effective practices for responding to and recovering from high-severity cyber disruption and signal they will continue requesting periodic self-assessments as firms reassess their ability to remain within impact tolerances.
European Central Bank Banking Supervision sets Digital Operational Resilience Act priorities on ICT change risk, third-party dependencies and threat-led penetration testing
The European Central Bank Banking Supervision is using the EU Digital Operational Resilience Act to intensify oversight of banks’ digital and operational resilience, focusing on ICT change management, third-party risk and cyber testing. Expanded incident reporting shows 38% of major incidents in 2025 stemmed from IT change, while rising cloud reliance and delays in contract renegotiations and business continuity planning have heightened scrutiny of third-party risk management. An EU-level framework now oversees 19 critical ICT providers. The ECB will conduct an on-site campaign on ICT third-party risk management and launch a three-year threat-led penetration testing cycle, with over 80 banking groups already notified.
Central Bank of Brazil strengthens Conta PI security with minimum balance thresholds automatic blocking and an alternative statement channel
The Central Bank of Brazil has introduced measures to enhance operational security and management of the Instant Payments Account (Conta PI) within the Instant Payments System (SPI). These measures include setting a minimum operational balance, automatic blocking options, and an alternative channel for accessing Conta PI statements during network outages. These enhancements are part of the central bank's Agenda BC and the second phase of a toolset to strengthen the payments ecosystem.
Council of Financial Regulators flags elevated geopolitical and cyber risks and agrees 2026 crisis preparedness workplan
The Council of Financial Regulators said global financial stability risks have increased, while direct Australian exposures to the Middle East remain limited. It urged banks to maintain strong capital and liquidity, called for prudent lending standards, and agreed a workplan to strengthen crisis preparedness for capital and liquidity stress scenarios. The Council also advanced joint work on cyber resilience and said it will publish actions to streamline regulatory data collection and sharing in the first half of 2026.
Polish Financial Supervision Commission publishes CSIRT KNF Annual Cybersecurity Report 2025 highlighting supply chain threats and DORA incident reporting volumes
The Polish Financial Supervision Commission's CSIRT published its Annual Report on Cybersecurity 2025, highlighting a complex cyberthreat landscape with increased attacks on technology and IT service providers, raising supply chain risks. The report details 41,751 dangerous domains, 9,751 blocked fraudulent ads, and 787 DDoS attacks, alongside 274 ICT incident reports under DORA. CSIRT KNF issued 625 threat warnings and 70 recommendations, noting heightened ransomware activity and proactive monitoring of data-leak publications.
Taiwan Financial Supervisory Commission publishes 2025 H2 examination findings and corrective actions across 12 sectors
The Taiwan Financial Supervisory Commission published financial examination findings for the second half of 2025 across 12 sectors, highlighting systemic deficiencies in AML/CFT/CPF, customer protection, cyber security, and real estate lending. Issues include weak onboarding and monitoring of high-risk customers, incomplete insurance and ETF disclosures, inadequate controls over personal data and privileged accounts, and insufficient scrutiny of lending to speculators and vacant-land projects. The authority will continue publishing findings and corrective actions to signal priorities and support stronger controls.
Bank of England finalises IOREP operational incident and third-party reporting rules for FMIs effective 18 March 2027 and consults on revoking duplicate CCP incident reporting rule
The Bank of England has finalized its IOREP rules for financial market infrastructures, standardizing the reporting of significant operational incidents and third-party arrangements to boost resilience. Applicable to UK central counterparties, securities depositories, payment operators, and service providers, reporting via Financial Conduct Authority platforms starts 18 March 2027. The Bank is consulting on revoking duplicative reporting for central counterparties, aligning with IOREP.