ICT risk

  • ESRB Frontier AI Warning: DORA Cyber Risk Reporting Under Scrutiny

    On 7 July 2026 the European Systemic Risk Board published a formal warning that frontier artificial intelligence models are now a source of systemic cyber risk with direct implications for DORA cyber risk reporting across the EU financial system, and the three European Supervisory Authorities backed it the same day. On the same date, ECB…

  • DORA ICT-Risk Reporting: Reading KNF’s 2026 Cyber-Threat Report

    On 9 July 2026, CSIRT KNF, the cyber-incident response team inside Poland’s Financial Supervision Authority, refreshed its report on the cyber threats facing the Polish financial sector for 2026. The document reads like a briefing pack rather than a rulebook: the priority attack scenarios, the techniques criminals are stacking into single campaigns, and the risks…

  • CASP Digital Operational Resilience: ESMA’s Custody CSA

    On 8 July 2026 the European Securities and Markets Authority launched a Common Supervisory Action on crypto-asset service providers, aimed squarely at one activity: custody. The exercise assesses the maturity of CASP digital operational resilience frameworks for custody services, and national competent authorities will run it on a risk-based sample of authorised CASPs from the…

  • DORA Compliance Checklist for Luxembourg Fund Administrators

    Last updated: April 2026 DORA (Regulation (EU) 2022/2554) has been live since 17 January 2025. For Luxembourg fund administrators, UCITS management companies, and AIFMs, the question is no longer whether it applies to you. It does. The question is whether your implementation actually covers what the CSSF expects, or whether you have gaps disguised as…