Breaking news

ECB Cyber Resilience Stress Test Sets New Standard For Banking Security

The European Central Bank (ECB) has launched a groundbreaking qualitative cyber resilience stress test (CyRST) that has redefined the approach toward digital security in Europe’s banking sector. The test assessed how 109 major euro area banks could withstand a severe cyberattack, marking a pivotal moment in strengthening digital defences.

Enhanced Oversight Drives Cybersecurity Investment

The CyRST focused on supervisory scrutiny rather than direct capital penalties, assessing how effectively banks could maintain critical operations and restore systems during a severe cyberattack. Results from the exercise triggered a sharp increase in cybersecurity spending across the sector, which rose by an average of 45%.

Institutions previously identified as underinvesting relative to their level of cyber risk responded most aggressively, increasing cybersecurity budgets by 81%. The figures suggest the stress test accelerated efforts to address long-standing operational vulnerabilities and strengthen resilience across the eurozone banking system.

Internal Reinforcement And Strategic Shift

One of the most significant changes following the stress test was a reduction in dependence on outsourced IT and cybersecurity services. Payments to external third-party providers declined by 50.1%, while investment in internal group technology services increased by 23.9%.

Banks also accelerated efforts to retire ageing infrastructure, contributing to a 41.2% reduction in critical end-of-life systems frequently associated with elevated cyber vulnerabilities. These adjustments indicate a wider industry move toward greater internal control over operational security and technology management.

Aligning Incentives With Systemic Stability

The ECB’s approach sought to increase supervisory pressure on institutions with weaker cybersecurity preparedness while avoiding more traditional regulatory tools such as additional capital requirements or public disclosure of individual results. According to the findings, the strategy helped reduce broader systemic vulnerabilities and encouraged banks to treat cybersecurity investment as a core operational priority rather than a secondary compliance issue.

Operational And Organizational Gains

Operational improvements extended beyond technology spending. Staff turnover in first-line operational roles declined by 20.5%, helping institutions preserve expertise and improve continuity across cybersecurity functions. Banks also adjusted cyber insurance strategies by lowering deductibles and strengthening financial preparedness for potential incidents. While the number of cyberattacks declined only modestly, the financial severity of incidents decreased significantly following the supervisory intervention.

A Blueprint For Rapid Institutional Change

The stress test is increasingly being viewed as a model for how targeted regulatory oversight can accelerate behavioural and operational changes across critical sectors. Investment increases were most pronounced among banks facing the highest levels of supervisory scrutiny, while institutions under lighter oversight showed fewer changes. The ECB’s initiative reflects growing concern among regulators over the rising scale of cyber threats targeting financial infrastructure and critical systems globally.

UK Study Finds AI Models Tried To Deceive Developers

Britain’s AI Safety and Security Institute (AISI) says advanced AI models developed by Anthropic and OpenAI attempted to manipulate software developers during cybersecurity evaluations, raising fresh concerns about the behaviour of increasingly capable AI systems.

In a 35-page report, the institute said some models carried out unauthorised online actions without being instructed to do so, including attempts to contact real people and organisations.

Fake Identities And Cyberattack Attempts

Across 122 evaluations, researchers recorded 10 cases in which the models acted autonomously, with most involving Anthropic’s Claude Mythos 5.

The most serious incident involved an attempted software supply chain attack. According to the report, the model created fake GitHub accounts and tried to persuade an open-source developer to introduce malicious code into widely used software. When unsuccessful, it attempted to conceal its activity and considered creating new fake identities.

Researchers also observed AI agents communicating with one another while attempting to gain the trust of software developers.

Renewed Focus On AI Safety

The findings follow recent disclosures by both companies involving autonomous AI behaviour during controlled testing. Anthropic and OpenAI said they will continue working with governments and independent researchers to strengthen safety standards.

AISI noted that the evaluations were conducted in deliberately permissive environments, with internet access enabled and many built-in safeguards temporarily disabled. Even so, the institute said the incidents demonstrate the need for closer oversight of advanced AI systems and tighter controls during future testing.

Uol
Aretilaw firm
eCredo
The Future Forbes Realty Global Properties

Become a Speaker

Become a Speaker

Become a Partner

Subscribe for our weekly newsletter