About Us
Our Work
News & Insights
Publications
Events
Membership
Accounting

Menu

Ensuring appropriate and workable Cyber and Operational Resilience requirement

AFME advocates for cyber and operational resilience frameworks that are effective, proportionate, and workable for financial institutions.

 

As new financial-services-specific operational resilience regimes are introduced across the EU and UK, it is essential that regulatory requirements strengthen resilience without creating unnecessary complexity, duplication, or operational burden. AFME will continue to make and advocate proposals for improvements to both EU (Digital Operational Resilience Act, or DORA)) and UK operational resilience regimes.

 

It is key that regulatory and supervisory approaches to cyber and operational resilience remain up-to-date and fit-for-purpose as new technologies such as AI reshape the appropriate approaches to ensuring resilient capital markets.

 

Moreover, in order to contribute to competitiveness of European capital markets, ensuring greater alignment and streamlining of requirements is key. This applies to new and proposes financial services frameworks, such as incident reporting requirements under EU DORA and UK frameworks. Increasingly, however, streamlining is required between financial and cross-sectoral cyber regulations, such as the EU Cyber Resilience Act (CRA) and emerging UK measures relating to ransomware payments. Where strong sector-specific requirements already exist, appropriate exemptions or alignment mechanisms should be applied so that financial institutions can operate under a single, consistent framework that supports both resilience objectives and effective risk management.

Join our mailing list

Get the Latest Financial Market Updates

Stay ahead in Europe's financial markets—sign up for AFME’s newsletter today for exclusive insights, industry updates, and event invitations!