<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>ITOL. — The Resilience Wire</title>
  <link>https://itol.app/news</link>
  <atom:link href="https://itol.app/rss.xml" rel="self" type="application/rss+xml"/>
  <description>Operational-resilience news for banking and financial services — regulators, standard setters, FMIs, and the recognized press, pressed into a fresh edition many times a day. Edition 2026–239–1640.</description>
  <language>en</language>
  <lastBuildDate>Thu, 27 Aug 2026 16:40:15 GMT</lastBuildDate>
  <ttl>60</ttl>
  <generator>ITOL. press run (script/fetch-news.mjs)</generator>
  <item>
    <title>​The EBA consults on draft technical standards on institutions’ operational risk management</title>
    <link>https://www.eba.europa.eu/publications-and-media/press-releases/eba-consults-draft-technical-standards-institutions-operational-risk-management</link>
    <guid isPermaLink="false">eba-47b9a51a</guid>
    <pubDate>Wed, 26 Aug 2026 08:37:24 GMT</pubDate>
    <source url="https://www.eba.europa.eu/publications-and-media">European Banking Authority</source>
    <category>policy</category>
    <description>​The European Banking Authority (EBA) today launched a public consultation on draft Regulatory Technical Standards (RTS) specifying the operational risk management framework that institutions must have in place as per Article 323 of the Capital Requirements…

AI précis: The draft RTS cover three components — governance, the operational risk management process, and the assessment system — with proportionality relief for institutions with a business indicator below EUR 750 million; ICT risk stays under DORA. Comments are due 31 December 2026, with a virtual public hearing on 29 September 2026.</description>
  </item>
  <item>
    <title>Cybersecurity Data Sharing Faces Liability Deadline</title>
    <link>https://gfmag.com/technology/cybersecurity-data-sharing-faces-liability-deadline/</link>
    <guid isPermaLink="false">gfmag-b5fafc63</guid>
    <pubDate>Fri, 21 Aug 2026 10:34:00 GMT</pubDate>
    <source url="https://gfmag.com/">Global Finance</source>
    <category>cyber</category>
    <description>With CISA protections expiring Sept. 30, businesses face new liability risks. CFOs must weigh alternatives for cybersecurity data sharing.

AI précis: CISA 2015's liability shield lapses September 30, 2026; the House has folded an extension into the 2027 NDAA, still awaiting the Senate. A DHS inspector-general report found AIS participation fell from 304 non-federal users to under 90, while the administration has launched an AI-powered alternative clearinghouse called &quot;Gold Eagle.&quot; Lawyers warn shared data could reach regulators, litigants, and insurers.</description>
  </item>
  <item>
    <title>Banks reveal key DORA resilience gaps</title>
    <link>https://qa-financial.com/banks-reveal-key-dora-resilience-gaps/</link>
    <guid isPermaLink="false">qaf-52060f3f</guid>
    <pubDate>Fri, 21 Aug 2026 07:08:18 GMT</pubDate>
    <source url="https://www.qa-financial.com/">QA Financial</source>
    <category>continuity</category>
    <description>AI précis: A Zanders study of 23 banks finds strong compliance with DORA's foundations but weak embedding: fewer than half had a board-approved ICT risk-appetite statement, only 12 addressed concentration and interconnectedness risks, advanced testing such as threat-led penetration testing remains limited, and only 16 said continuity plans cover all critical functions.</description>
  </item>
  <item>
    <title>The Blackout That Could Devastate America</title>
    <link>https://www.nytimes.com/2026/08/18/magazine/national-blackout-power-electricity-outage.html</link>
    <guid isPermaLink="false">pin-nyt-blackout-2026-08</guid>
    <pubDate>Tue, 18 Aug 2026 13:20:38 GMT</pubDate>
    <source url="https://www.nytimes.com/">The New York Times</source>
    <category>continuity</category>
    <category>third-party</category>
    <description>The power grid relies on thousands of aging, hand-built transformers. If enough fail, the blackout could last years.</description>
  </item>
  <item>
    <title>FDIC Considers Industry Standard-Setting Organization for Third-Party Service Providers</title>
    <link>https://www.consumerfinancemonitor.com/2026/08/17/fdic-considers-industry-standard-setting-organization-for-third-party-service-providers/</link>
    <guid isPermaLink="false">cfmon-de39fe84</guid>
    <pubDate>Mon, 17 Aug 2026 19:24:05 GMT</pubDate>
    <source url="https://consumerfinancemonitor.com/">Consumer Finance Monitor</source>
    <category>third-party</category>
    <description>AI précis: Per a Bloomberg Law report, the FDIC is circulating a term sheet for a Banking Industry Standards Development Organization (BISDO) that would set standards and certify third-party service providers to banks, with scope extending well beyond fintech partnerships. Compliance would not be a regulatory safe harbor, and governance, funding, and participation questions remain open.</description>
  </item>
  <item>
    <title>Outsourcing and competition in the banking sector: the rise of Cloud Service Providers</title>
    <link>https://www.bankofengland.co.uk/working-paper/2026/outsourcing-and-competition-in-the-banking-sector-the-rise-of-csps</link>
    <guid isPermaLink="false">boe-7100d5be</guid>
    <pubDate>Fri, 14 Aug 2026 13:00:00 GMT</pubDate>
    <source url="https://www.bankofengland.co.uk/news">Bank of England</source>
    <category>third-party</category>
    <description>Staff working papers set out research in progress by our staff, with the aim of encouraging comments and debate.

AI précis: Using proprietary bank-provider contract data, BoE researchers find cloud spending is associated with lower operating costs and higher deposits, with demand-side benefits largest for small and medium banks. A counterfactual restricting cloud outsourcing implies higher market concentration and lower depositor welfare; lower capital requirements would cut cloud investment, offsetting about 32% of their welfare gain.</description>
  </item>
  <item>
    <title>Critical Infrastructure Needs a Unified Cyber Defense</title>
    <link>https://www.govinfosecurity.com/critical-infrastructure-needs-unified-cyber-defense-a-32545</link>
    <guid isPermaLink="false">gvis-b389b824</guid>
    <pubDate>Thu, 13 Aug 2026 17:00:00 GMT</pubDate>
    <source url="https://govinfosecurity.com/">GovInfoSecurity</source>
    <category>cyber</category>
    <description>Critical infrastructure cyberattacks increasingly cross sector boundaries, exposing weaknesses created by siloed defenses. Alliance for Critical Infrastructure's ...</description>
  </item>
  <item>
    <title>AI Is Making Business Resilience More Complicated</title>
    <link>https://telecomreseller.com/2026/08/13/ai-complicates-resilience/</link>
    <guid isPermaLink="false">pin-tcr-ai-resilience-2026-08</guid>
    <pubDate>Thu, 13 Aug 2026 12:00:00 GMT</pubDate>
    <source url="https://telecomreseller.com/">Telecom Reseller / Technology Reseller News</source>
    <category>third-party</category>
    <category>continuity</category>
    <description>AI adds another layer of dependencies to an already complicated business environment. If an AI-dependent system behind critical customer service goes offline, the consequences turn serious. The piece's answer: map the dependency chain, hold multiple contingencies, and actually test them.</description>
  </item>
  <item>
    <title>Why Jamie Dimon is calling CEOs across corporate America about AI</title>
    <link>https://www.moneycontrol.com/news/business/why-jamie-dimon-is-calling-ceos-across-corporate-america-about-ai-13995858.html</link>
    <guid isPermaLink="false">moneycontr-3792f35b</guid>
    <pubDate>Wed, 05 Aug 2026 18:37:00 GMT</pubDate>
    <source url="https://moneycontrol.com/">Moneycontrol</source>
    <category>policy</category>
    <description>The JPMorgan CEO has approached banks, technology firms and critical-infrastructure operators as the ACI seeks to develop safeguards with the Trump administration.

AI précis: Dimon's outreach began in July and spans more than 40 companies; he is expanding the Alliance for Critical Infrastructure, a group JPMorgan helped found, with calls planned for August to discuss collaboration, according to two sources cited by Reuters.</description>
  </item>
  <item>
    <title>JPMorgan CEO Dimon leads new cross-industry effort to tackle AI risks</title>
    <link>https://www.reuters.com/world/jpmorgan-ceo-dimon-leads-new-cross-industry-effort-tackle-ai-risks-2026-08-05/</link>
    <guid isPermaLink="false">pin-aci-reuters-2026-08</guid>
    <pubDate>Wed, 05 Aug 2026 10:03:00 GMT</pubDate>
    <source url="https://www.reuters.com/">Reuters</source>
    <category>cyber</category>
    <category>third-party</category>
    <description>Reuters exclusive: Dimon is urging corporate leaders to join a US-focused group on AI risk — an expansion of the Alliance for Critical Infrastructure, which JPMorgan helped found, spanning more than 40 firms across critical-infrastructure industries.</description>
  </item>
  <item>
    <title>Dynamic Scenario Library Volume 2.0</title>
    <link>https://www.cmorg.org.uk/artefact/dynamic-scenario-library-volume-20</link>
    <guid isPermaLink="false">pin-cmorg-dsl2-2026-08</guid>
    <pubDate>Tue, 04 Aug 2026 12:00:00 GMT</pubDate>
    <source url="https://www.cmorg.org.uk/">Cross Market Operational Resilience Group</source>
    <category>continuity</category>
    <category>cyber</category>
    <description>The DSL is designed to be a shared resource which contains a catalogue of categorised and individually described scenarios, constructed using a common design methodology. This is version 2.0 of the DSL, published July 2026, reflecting a series of interim updates to the original document.</description>
  </item>
  <item>
    <title>EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector</title>
    <link>https://www.eba.europa.eu/publications-and-media/press-releases/eba-eiopa-and-esma-call-enhanced-governance-and-consistent-supervision-mitigate-ict-risks-frontier</link>
    <guid isPermaLink="false">eba-56493de3</guid>
    <pubDate>Fri, 31 Jul 2026 12:30:00 GMT</pubDate>
    <source url="https://www.eba.europa.eu/publications-and-media">European Banking Authority</source>
    <category>policy</category>
    <description>The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today published a statement calling for a cross-sectoral, risk-based and consistent supervisory approach to mitigate the ICT risks stemming from frontier AI models.

AI précis: The statement stresses prevention, detection and management of cyber risks tied to frontier AI, says financial entities need robust governance and risk-management frameworks, and updates on DORA oversight activities for critical ICT third-party providers. The ESAs encourage firms and supervisors to use it as a basis for supervisory dialogue.</description>
  </item>
  <item>
    <title>Letter from the Governor to the Daily Mail</title>
    <link>https://www.bankofengland.co.uk/letter/2026/letter-from-the-governor-to-the-daily-mail</link>
    <guid isPermaLink="false">boe-d0a7e708</guid>
    <pubDate>Thu, 23 Jul 2026 16:00:00 GMT</pubDate>
    <source url="https://www.bankofengland.co.uk/news">Bank of England</source>
    <category>cyber</category>
    <description>Letter from Governor Andrew Bailey to the Daily Mail on the subject of AI and cyber-attacks

AI précis: Bank of England Governor Andrew Bailey wrote to the Daily Mail rejecting a claim that the Bank's cyber defences are unsophisticated. He says the real concern is frontier AI making cyber-attacks, outages and scams worse, and points to stress tests, penetration testing and international coordination on testing frontier AI models.</description>
  </item>
  <item>
    <title>Agencies Issue Joint Statement on Handling of Highly Sensitive Information During Bank Examinations</title>
    <link>https://content.govdelivery.com/accounts/USFDIC/bulletins/420cf8d</link>
    <guid isPermaLink="false">fdic-79517541</guid>
    <pubDate>Thu, 16 Jul 2026 18:20:46 GMT</pubDate>
    <source url="https://www.fdic.gov/news/press-releases/">Federal Deposit Insurance Corporation</source>
    <category>policy</category>
    <description>PRESS RELEASE | JULY 16, 2026 Agencies Issue Joint Statement on Handling of Highly Sensitive Information During Bank Examinations WASHINGTON — The federal bank regulatory agencies today issued a joint statement describing enhanced security procedures for…

AI précis: Federal bank regulators issued a joint statement on enhanced security procedures for handling highly sensitive information during examinations, such as reviewing materials on-site rather than transferring them to agency systems. The agencies commit to notifying affected banks of any material breach of confidential supervisory information within 72 hours of discovery, absent legal restrictions.</description>
  </item>
  <item>
    <title>Exploring cross-sectoral interconnections in resolution planning</title>
    <link>https://www.fsb.org/2026/07/exploring-cross-sectoral-interconnections-in-resolution-planning/</link>
    <guid isPermaLink="false">fsb-ca005049</guid>
    <pubDate>Thu, 09 Jul 2026 08:04:47 GMT</pubDate>
    <source url="https://www.fsb.org/press/">Financial Stability Board</source>
    <category>continuity</category>
    <description>In this speech, FSB Secretary General, John Schindler highlights the importance of resolve in resolution planning, emphasising collaboration, preparedness, in maintaining financial system resilience.

AI précis: FSB Secretary General John Schindler, speaking at the FSB's ReSolve event, urged a cross-sectoral approach to resolution planning, bringing together working groups covering banks, financial market infrastructures, and insurers. He noted the FSB has launched a strategic review of its crisis preparedness activities, with cross-sectoral interconnections central to that review.</description>
  </item>
  <item>
    <title>Telstra outage in Australia disrupts trains and payments; no evidence of 'malicious' activity</title>
    <link>https://www.reuters.com/business/media-telecom/telstra-outage-disrupts-australian-train-services-taxi-payments-2026-07-07/</link>
    <guid isPermaLink="false">reu-52f6cfa9</guid>
    <pubDate>Wed, 08 Jul 2026 07:00:00 GMT</pubDate>
    <source url="https://www.reuters.com/">Reuters</source>
    <category>continuity</category>
    <category>payments</category>
  </item>
  <item>
    <title>Financial Policy Committee Record – July 2026</title>
    <link>https://www.bankofengland.co.uk/financial-policy-committee-record/2026/july-2026</link>
    <guid isPermaLink="false">boe-81096b87</guid>
    <pubDate>Tue, 07 Jul 2026 09:30:00 GMT</pubDate>
    <source url="https://www.bankofengland.co.uk/news">Bank of England</source>
    <category>continuity</category>
    <category>policy</category>
    <description>Our Financial Policy Committee (FPC) meets to identify risks to financial stability and agree policy actions aimed at safeguarding the resilience of the UK financial system.

AI précis: The Bank of England published the record of its Financial Policy Committee's 26 June 2026 meeting. The FPC judged that vulnerabilities in risky asset valuations, sovereign debt, and private credit remain and some have grown, noting increased equity-market leverage, market effects from the Middle East conflict, and rising cyber and operational-resilience risks from advances in frontier AI.</description>
  </item>
  <item>
    <title>Top banking watchdogs issue stark warning over AI-driven cyber attacks</title>
    <link>https://www.ft.com/content/304cdbb9-c161-4e40-af4d-6df1d2ff5363?syn-25a6b1a6</link>
    <guid isPermaLink="false">ft-e702c18f</guid>
    <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
    <source url="https://ft.com/">Financial Times</source>
    <category>cyber</category>
  </item>
  <item>
    <title>ECB tells Europe's biggest banks to prepare for AI-powered cyber threats</title>
    <link>https://www.euronews.com/business/2026/07/07/ecb-tells-europes-biggest-banks-to-prepare-for-ai-powered-cyber-threats</link>
    <guid isPermaLink="false">euronews-a8cabaec</guid>
    <pubDate>Tue, 07 Jul 2026 07:00:00 GMT</pubDate>
    <source url="https://euronews.com/">Euronews</source>
    <category>cyber</category>
  </item>
  <item>
    <title>ECB payment system suffers second outage in a week</title>
    <link>https://www.reuters.com/business/finance/ecbs-t2-payment-system-back-up-after-brief-incident-impacting-payments-2026-07-06/</link>
    <guid isPermaLink="false">reu-2f2209a5</guid>
    <pubDate>Mon, 06 Jul 2026 07:00:00 GMT</pubDate>
    <source url="https://www.reuters.com/">Reuters</source>
    <category>continuity</category>
    <category>payments</category>
  </item>
  <item>
    <title>Financial Entities Must Move Beyond Third-Party Oversight to Meet EU’s Digital Operational Resilience Act (DORA) Requirements</title>
    <link>https://www.crowdfundinsider.com/2026/07/289670-financial-entities-must-move-beyond-third-party-oversight-to-meet-eus-digital-operational-resilience-act-dora-requirements/</link>
    <guid isPermaLink="false">crowdfundi-f74fcdad</guid>
    <pubDate>Sun, 05 Jul 2026 04:12:00 GMT</pubDate>
    <source url="https://crowdfundinsider.com/">Crowdfund Insider</source>
    <category>third-party</category>
    <category>continuity</category>
    <description>UK Finance has shared a blog post authored by Craig Oliver, Third-Party Risk Management and Supplier Assurance Lead, PA Consulting and Karan Chao, Third Party Risk &amp; Digital Trust Expert, PA ...

AI précis: The authors argue DORA's direct ESA supervision of critical ICT providers makes resilience a shared responsibility, not an arm's-length contractual one, and firms stay fully accountable. They urge four steps: explain impact tolerances to key suppliers, align contracts and governance with the oversight regime, run joint multi-party resilience exercises, and help suppliers mature their own compliance.</description>
  </item>
  <item>
    <title>DORA’s first incident banking data gives regulators fresh testing playbook</title>
    <link>https://qa-financial.com/doras-first-incident-banking-data-gives-regulators-fresh-testing-playbook/</link>
    <guid isPermaLink="false">qaf-78e81d48</guid>
    <pubDate>Thu, 02 Jul 2026 07:00:00 GMT</pubDate>
    <source url="https://www.qa-financial.com/">QA Financial</source>
    <category>policy</category>
    <description>AI précis: The European Supervisory Authorities published the first annual overview of major DORA incident reports on June 3, calling ICT risks 'increasingly borderless and interconnected.' Consultants say 2025 was a transition year and 2026 marks DORA's first real enforcement test, with the ECB embedding its TIBER-EU framework as the model for mandatory threat-led penetration testing.</description>
  </item>
</channel>
</rss>
