Cybersecurity is one of the challenges that the financial sector must face and incorporate into its business model from the moment of its design, it must be adequately reflected in the strategy and procedures of financial institutions, and technological risk management must be considered within the institutions' risk map and managed appropriately.
More information can be requested regarding all that related to this section of the website of the CNMV on email
ciberseguridad@cnmv.es Legislation, guides and other information of interest
- Code of Good Governance for Cybersecurity (13.07.2023) This code is included on the website for information purposes and the CNMV is not competent to supervise it.
Digital Operational Resilience Act - DORA
Regulation (EU) 2022/2554 (DORA - Digital Operational Resilience Act) was published on 27 December 2022 and applies from 17 January 2025. DORA is applied to financial institutions offering services in the European Union.
Given the great dependency of the financial sector on technology to perform its critical business functions and its increasing dependence on third-party technological services, the aim of DORA is to strengthen the resilience of the sector with regard to threats to its ICT assets. This Regulation harmonises the most relevant operational resilience requirements at European level for the entities to be capable, under the principle of proportionality, of detecting, responding to and recovering from possible incidents that affect their critical or relevant business functions.
DORA is based on five pillars:
- ICT risk management
- ICT-related incident management, classification and notification
- Digital operational resilience testing
- Third-party ICT risk management
- Information sharing
Level 2 and 3 Regulatory Developments by ESAs:
- Pillar I: ICT risk management
- Pillar II: ICT-related incident management
- Pillar III: Digital operational resilience testing
- Pillar IV: Third-party ICT risk management
- Pillar IV bis: Critical ICT third party service providers oversight framework
Cyber resilience in the face of frontier Artificial Intelligence models
The emergence of frontier artificial intelligence models marks a significant evolution in the technological capabilities available in the financial sector. These models not only enable the automation of complex tasks, the analysis of large volumes of data and the improvement of operational efficiency but also incorporate advanced capabilities that could significantly impact the field of cybersecurity. Among other things, they can facilitate the detection of and response to threats, but they also have the potential to increase the sophistication, speed and scale of certain attack vectors, thereby reinforcing the need for prudent management of the risks associated with their use.
From a supervisory standpoint, these technological developments do not alter the fundamental principles of risk management. Regulation (EU) 2022/2554 on digital operational resilience in the financial sector (DORA) is based on a technology-agnostic and risk-based approach. Its requirements regarding governance, ICT risk management, incident management, resilience testing and ICT service provider risk management therefore apply fully to the use of advanced artificial intelligence models, including those related to cybersecurity.
In this regard, it is important for entities to assess the potential impact of these technologies on their risk profile, review their ICT risk management framework and ensure it effectively addresses the risks associated with the use of frontier AI models. They should also plan any necessary measures proportionately. Entities should pay particular attention to issues such as attack surface management, vulnerability detection, prioritisation and patching timeframes, incident response times and the monitoring of ICT service providers.
To help understand these emerging challenges, this section compiles, for information purposes, relevant documentation relating to the cybersecurity risks associated with frontier AI models.
- Publications by cybersecurity agencies:
- Financial sector publications:
Post-quantum resilience: the transition to safe cryptography
The advance of quantum computing is one of the key strategic challenges to cybersecurity in the medium to long term. Although no quantum computer yet exists that could realistically compromise the cryptographic algorithms we currently use, the development of this technology poses major potential risks to the confidentiality, integrity and authenticity of digital information and communications. Certain public-key cryptographic algorithms in widespread use today could be put in jeopardy by the future capabilities of quantum computing, affecting critical infrastructure, systems and services in the financial sector. This technology thus presents a risk that could impact the entire financial system, as well as other sectors.
Post-quantum cryptography (PQC) refers to cryptographic algorithms that are designed to withstand attacks from both traditional and quantum computers. The transition to these new standards poses a major challenge to financial institutions, given the complexity of identifying, cataloguing and adapting systems, applications, devices and third-party dependencies that use potentially vulnerable cryptographic mechanisms. There is also the risk of “harvest now, decrypt later” scenarios, where information collected today could be decrypted in the future, once sufficiently advanced quantum capabilities exist.
The DORA regulation includes risk management obligations associated with the use of cryptography, as set out in Section 4 of Delegated Regulation (EU) 2024/1774, for example.
Given these developments, it is important that entities assess the potential exposure of their critical assets, processes and services to the risks posed by quantum computing, and factor this issue into their technological planning, cybersecurity risk management and operational resilience processes. Among other measures, entities should develop the capacity to identify relevant cryptographic dependencies, assess the timeframes over which they will remain exposed and plan their future migration towards quantum-resistant cryptographic standards in a proportionate manner, taking into account the recommendations issued by the competent national and international bodies.
To support ongoing monitoring of this topic, this section brings together relevant documentation, for information purposes, on quantum computing, post-quantum cryptography and their implications for cybersecurity and operational resilience in the financial sector.
- Publications by cybersecurity agencies:
- Financial sector publications:
TIBER-ES framework
TIBER-EU constitutes the first common European-scale framework for the execution of red teaming testing, recording the manner in which the authorities, the entities and the cybersecurity service providers are to work jointly to achieve the objective of these tests. These tests aim to foresee, as far as possible, the impact an entity would suffer in the case of confronting a real cyber attack. For this, a cyber attack is simulated in this type of advanced test, employing tactics, techniques and procedures such as those a sophisticated cyber attacker would use. Therefore, they constitute an extremely powerful instrument to improve the cyber resilience of financial institutions.
TIBER-ES subscribes to principles of TIBER-EU and has the aim of strengthening the cyber resilience of the Spanish financial sector, guaranteeing the acknowledgement of the authorities in other jurisdictions that have also adopted this framework locally. The CNMV will monitor the tests, via the TCT (TIBER Cyber Team), whenever the financial institutions carrying them out are within its supervisory scope. TIBER-EU, European framework for the execution of red teaming testing.
- TIBER-EU, European framework for the execution of red teaming testing.
- Guide for the implementation of the TIBER-ES operational framework. The purpose of this guide is to specify the conditions under which the red teaming testing is to be executed following the TIBER-ES requirements.
Public statements and events