The Committee on Payments and Market Infrastructures and the International Organization of Securities Commissions have published for public comment a voluntary, nonbinding cyber resilience toolkit for financial market infrastructures and a discussion paper on their growing reliance on third-party service providers. The publications address operational and systemic risks arising from cyber threats, interconnected financial ecosystems and the use of external providers for critical services. The toolkit supports implementation of the Principles for Financial Market Infrastructures and the 2016 cyber resilience guidance across four areas: governance, extreme but plausible scenario design, response and recovery planning, and testing. It covers recovery of critical operations within two hours, data integrity, safe disconnection and reconnection of ecosystem entities, red team testing and risks associated with artificial intelligence. The discussion paper identifies six third-party risk challenges: ecosystem complexity, provider concentration, opaque supply chains, difficult exit planning, unequal bargaining power and differences in regulatory expectations across jurisdictions. CPMI-IOSCO is seeking views on possible solutions and whether further policy work or other support is needed, and plans to finalize the toolkit after reviewing feedback.