top of page
fnlogo.png

CySEC Alerts Cyprus Financial Sector to Rising AI-Powered Cyber Risks and Calls for Stronger Digital Defences

  • Jun 19
  • 3 min read

The Cyprus Securities and Exchange Commission (CySEC) has issued a warning to regulated financial entities in Cyprus regarding the increasing cybersecurity risks linked to advanced artificial intelligence systems.


 

The regulator has urged firms to reinforce their digital operational resilience and align their protections with the requirements of European regulatory frameworks.

 

In a circular distributed to industry stakeholders, CySEC highlighted that so-called frontier AI models are becoming increasingly capable of detecting and exploiting software vulnerabilities at a speed and scale not previously seen. According to the regulator, these capabilities raise serious concerns for the financial sector’s cybersecurity posture.

 

The warning was directed at a broad range of supervised entities, including Cyprus Investment Firms (CIFs), central securities depositories, trading venues, crypto-asset service providers, alternative investment fund managers, and UCITS management companies.

 

CySEC noted that recent progress in advanced AI technologies presents a dual reality for cybersecurity: while such systems can be used to enhance defensive security measures, they also introduce significant risks when used maliciously. The regulator stated that these developments may substantially accelerate the cycle of vulnerability discovery and exploitation.

 

As a result, CySEC warned that the frequency, complexity, and scale of cyberattacks targeting financial institutions and their ICT third-party service providers could increase significantly.

 

The commission reminded all entities falling under the Digital Operational Resilience Act (DORA), formally Regulation (EU) 2022/2554, that they are legally required to maintain strong ICT risk management frameworks capable of adapting to evolving threats, including those driven by emerging AI technologies.

 

CySEC further stated that it expects regulated firms, in a manner proportionate to their size, nature, scale, and complexity, to evaluate whether their current ICT risk management systems remain sufficient under the changing threat environment. Where gaps are identified, firms are expected to strengthen controls, procedures, and protective mechanisms accordingly.

 

The regulator specifically called for enhanced identification and assessment of ICT vulnerabilities, encouraging the use of improved threat intelligence capabilities and more effective vulnerability monitoring systems. It also stressed the importance of reviewing how quickly vulnerabilities are addressed, particularly in relation to patch management processes affecting critical infrastructure and legacy systems.

 

CySEC additionally emphasized that ICT systems should be designed with security and resilience built into their architecture from the outset. Firms were also advised to reassess identity and access management controls, as well as the resilience of essential ICT assets.


 

The circular highlighted the need for special attention to ICT third-party service providers and broader supply chain dependencies, urging firms to evaluate their preparedness and resilience in these areas.

 

In addition, CySEC encouraged financial institutions to strengthen their monitoring and detection systems in order to respond more effectively to increasingly sophisticated cyber threats. It suggested that firms consider greater automation and the use of enhanced security orchestration tools to improve incident response times and handling capacity.

 

The regulator also underlined the importance of ensuring that backup, restoration, and disaster recovery systems remain effective even under severe cyber-attack scenarios. It specified that backup systems should be properly segregated and regularly tested under realistic conditions to ensure operational reliability.

 

CySEC further stated that AI-related cyber risks must be incorporated into ICT risk assessments, governance frameworks, and operational resilience planning processes. It added that firms should maintain mechanisms that allow them to learn from past incidents, testing exercises, and emerging threat intelligence.

 

Reiterating obligations under DORA, CySEC noted that financial entities are required to protect their ICT systems and assets from unauthorized access and malicious activity and must also be capable of detecting unusual or anomalous behavior and ICT incidents.

 

Furthermore, institutions are required to maintain robust business continuity plans and ensure effective backup and recovery capabilities. They must also carry out appropriate ICT testing and vulnerability assessments, while effectively managing risks arising from third-party ICT providers.

 

CySEC stated that it will continue monitoring developments in frontier AI technologies and their impact on cybersecurity and operational resilience across the financial sector. The regulator also indicated that it may engage directly with regulated entities regarding their preparedness, governance structures, and implementation of ICT risk mitigation measures where necessary.

 

Finally, CySEC urged financial institutions to remain alert and to take proactive steps to ensure their digital operational resilience frameworks continue to evolve in response to the rapidly changing cyber threat landscape.

By fLEXI tEAM

Comments


bottom of page