On Jul. 7, ECB wrote to banks on AI-enabled security threats.
ECB published a letter sent to CEOs of significant euro area banks on the subject of addressing artificial intelligence (AI)-enabled cybersecurity threats.
Rapid advancements in AI systems represent pivotal changes to the cybersecurity landscape, speed up identifying vulnerabilities and attacking at unprecedented speed.
Has potentially profound implications for the confidentiality, integrity and resilience of banks' information and communication technology (ICT) systems.
ECB considers it a long-term shift in threat landscape, not a temporary phenomenon.
Overview
Responsibility for responding to evolving cyber risk enviroment primarily lies with banks' management bodies, strategic ICT related decisions may need revisiting.
In particular, governance and control systems are expected to be strengthened.
ECB emphasizes importance of addressing, without delay, open supervisory findings and measures related to ICT and security risks identified in supervisory activities.
Requirements of Digital Operational Resilience Act (DORA) remain highly relevant.
ECB calls on significant institutions to assess the impact of the evolving threat landscape without delay, and to develop a comprehensive action plan outlining concrete measures to strengthen relevant controls, allocating necessary resources.
Assigning clear roles and responsibilities, and defining implementation timelines.
Action Plan
Should build on bank's existing cyber risk strategy and address both immediate priorities and longer-term strategic aspects.
In short term should focus on: accelerating vulnerability and patch management at scale; enhance monitoring, detection and AI-enabled defensive capabilities.
Verify that 3rd party risk management is fit for purpose in current situation.
As part of short-term effort, prioritizing protection of perimeter technologies and internet-facing and externally exposed ICT assets, including 3rd party software and open-source components, is key to preparing for rise in AI-enabled threats.
In addition to these short-term actions, operational and cyber resilience should be advanced through structural measures including: reinforcing defense-in-depth and cyber hygiene, and modernizing infrastructure by replacing or updating legacy, unsupported or end-of-life technologies.
And improving operational resilience through response and recovery mechanisms, including crisis management, as well as information sharing arrangements.
Next Steps
Bank's action plan should be submitted to ECB supervisory team by Oct. 31, 2026.
Team will further engage with bank to discuss action plan and will monitor progress.
ECB will conduct a horizontal analysis of the submitted action plans to identify trend, challenges and areas for improvement, and will share conclusions with banks.
In an effort to enabling institutions to prioritize their efforts and focus resources on relevant key areas, ECB will extend deadline for annual collection of the IT Risk Questionnaire from September 2026 to February 2027.
Adjustments to other supervisory activities will be considered on case-by-case basis.
ECB also highlights that other emerging technologies, e.g. progress towards practical quantum computing, will have significant impact on the cybersecurity landscape.
It will address emerging risk to traditional encryption methods posed by advances in quantum computing in a separate letter in due course.