## SPEECH
### Strengthening operational resilience for the age of Al
oftheEcBandVice-Chairof theSupervisoryBoardof theEcB,at theGoldmanSachsEuropeanFinancialsConference2026
Zurich,3June2026
Thank you for inviting me to speak today.
Europe is facing a set of unprecedented challenges.
on external providers for energy,technology,security andkeyfinancial infrastructures such as necessitytosafeguardtheEuropeanwayof life.
Ensuring that our future is not determined elsewhere demands investment on an unprecedented scale. Consider that the green, digital and defence transitions will require an additional 1.2 trillion of
spending per year between now and 2031.[11
No single actor, no single sector and no single country can meet these challenges alone.
As fiscal space tightens, much of Europe's investment needs will have to come from private investment,withcapital marketsplayingapivotal role.
In a bank-based financial system like Europe's, strong, competitive and resilient banks are even more indispensable than they are elsewhere. They sustain the flow of finance to businesses, households
has moved to the heart of the policy debate.2]
scaleorregulation.It alsohinges onwhetherbanks can continue toserve their clients andprovide critical services when disruption strikes. That is why today I will focus on operational resilience.
## Resilience goes far beyond capital
When some people hear supervisors speak about resilience, they immediately think of financial resilience.
However, in a world of more frequent, sophisticated and disruptive cyber incidents, technology failures stillunabletooperate.
A striking example of the importance of non-financial resilience is the ransomware attack that hit the NewYorkbranchof theIndustrial and Commercial Bankof China in2023-thelargest bankin the the US Treasury market, one of the most systemically important markets globally. The bank had to rely on manual workarounds - including reportedly dispatching a courier with a USB stick across downtownManhattan-tomeetitsobligations. crashed and displayed the"bluescreenofdeath".Thedisruptionaffected firms acrosssectors, including financial services. At thesame time,the threatenvironmentis evolvingrapidlywith the riseof Al.Onetelling example involvedcriminalsusingAl-generatedidentitiestocreatethousandsoffakecustomersinorderto obtainloans,causingmillionsinlossesforthebankconcerned. Wehave alsoseen an increase in thenumber of cyberattacksreported bybanksunder our supervision in recent years.3] All theseexamplesillustrate afundamentalpoint:abankcanhaveamplecapital and liquiditybutstil for operational shocks. Today, resilience is not only about absorbing losses, but also about maintaining critical services - even under severe operational stress.4]
### Operationalresiliencefirmlyontheagendaofbanksand supervisors
The good news is that banks and supervisors are not starting from scratch. Overthepastdecade,cyberattacksoncritical infrastructure-includingenergyand more sophisticated.5] Although cyberattacks are occurring everywhere, every day and at any time, and while notable disruption or threaten the viability of a major bank.l This is not a coincidence. The fact that financial services are among the sectors best prepared to deal with cyberattacks reflects yearsofcapacitybuildinginbanks:indefence,detectionandincidentresponseandreporting. particularly among banks' management bodies.] Importantly, banks' efforts have evolved in tandem with a stronger and sustained supervisory focus. years], during which we have worked closely with banks in both ongoing and on-site supervision. For example, in 2024 we conducted a cyber resilience stress test on 109 banks, 28 of which
underwent a more thorough assessment of their ability to respond to, and recover from, a severe but plausible cybersecurity incident. While the exercise confirmed that banks have frameworks in place to certainbanks.Since then,almost three-quarters ofourfindingsidentified bythestresstest havebeen addressed,withbanksnotablystrengtheningtheircyberresilience. TheDigital OperationalResilienceAct(DORA),whichentered intoforcelastyear,providesa service providers.9] respondtoandrecoverfromsophisticated attacksthatmirrorreal-worldthreats,therebyprovidinga more systemic and enforceable framework for resilience. 10 sectorsinstead. There is, however, no room for complacency. asymmetrybetweendefendersandadversaries. amid arapidlyevolving threat landscapeshapedbyfrontierAl models.
Al adoption is already widespread among Europe's significant banks. Our annual data collection on banks' use of innovative technologies shows that more than 85% of banks under European banking supervisionuseartificial intelligence. Used responsibly, Al can help banks strengthen their operations, improve risk management and enhanceITsecurity.ButAlalsovastlyimprovesthecapabilitiesavailabletomaliciousactors. Until very recently, launching a sophisticated cyberattack required deep technical expertise, extensive reconnaissanceandcoding,andoftenweeks-orevenmonths-oftrial anderror. Notanymore. malicious actors to carry out complex attacks with greater speed and precision. theyare a structural shift in theeconomics of cyber risk.Tools likeMythos appear tobe significantly vulnerabilities at a speed and scalefarbeyond what we have seenbefore.Second,they can combine seemingly minor vulnerabilities into serious attacks. And third, they can help reverse-engineer patches intoexploitablevulnerabilitiesand,again,dosoatunprecedentedspeed.
Together, these characteristics suggest that the"price of admission"will fall. The marginal cost of Cyberattacks that previously required significant expertise, time and resources may in future be Thedirectionof travel is unmistakable:thespeed,scale and accessibilityof advanced cyber capabilities are increasing, and the time available to defenders is shrinking. Banks therefore need to prepare more quickly, more effectively and more consistently across the
topresto
#### The pivotal role of management bodies in addressing this strategic challenge
safetyandsoundness.It isthereforeessential thatbanks'managementbodiestakeclearownershipof
Moreover, the critical infrastructure on which banks depend -including cloud providers, become targets. As a result, scenarios that were once considered tail risks may become more likely, such as vulnerabilities in a single, widely used infrastructure quickly escalating into disruption across an entire sector, with knock-on effects on banks' ability to operate. This makes it all the more important to both strengthen the oversight and monitoring of third-party dependencies and enhance information sharing across thefinancial system.Given that manyof these threats aresimilarinnature,thetimely collectiveresilience. Considering that some banks' preparedness is still weak this is also where we, as supervisors, have a sophisticated IT environments11. a so-called"dear CEOletter"to all banks inwhichwe aim to askbanks to takeproactive measures to Our aim is straightforward:to ensure that banks take the necessary steps now, before these technologies are more widely used by threat actors.
#### Strengthening operational resilience requires investment
Operational resilience is not a stand-alone issue that is separate from the current debate on banking If banks are unable to maintain their customers'trust by providing a reliable service,their ability to theyears ahead. Strengthening operational resilience requires multi-year investment in people, systems and ongoing improvement. Banks should thereforegivecareful considerationtobolstering operational resilience in their investing. At the same time, the banking sector's defensive capabilities are not evenly distributed, leaving parts forsmallandmedium-sizedbanks. This is, however, no reason for inaction. In a diverse banking system, where banks of different sizes and business models thrive and support the real economy, all banks must be able to ensure a There are undoubtedly areas where a more proportionate approach is worth pursuing.12] Such
### Conclusion
Let me conclude. Todoso,weneed strong and competitivebanks.Butbanks can onlyplay theirroleif they areresilient, includingtooperationalthreats. increasing the speed of exploitation and exposing weaknesses that were too often tolerated for too long. Because we cannot afford to be complacent. Our message as supervisors is simple: act early, invest decisivelynow,anddonotwaitforthenextincidenttorevealwhereyourvulnerabilitieslie. supportingtherealeconomythroughthedigital,greenanddefencetransitions.
1. digital and defence transitions", The ECB Blog, ECB, 25 July. 2. Commission's consultationonbanking sector competitiveness; seeECB(2026),Eurosystemresponse For more details on the importance of overcoming fragmentation to boost competitiveness, see Elderson, F. (2026), "Boosting\_prosperity through deeper integration", keynote speech at the 3. The number of cyber incidents reported by banks to the ECB rose sharply up to the end of 2024. The DORA, the ECB now receives ICT (non-cyber but operational) incident reports as well as ICT cyber incident reports.However, the latter are smaller in number than before because the reporting thresholdsdifferfromthoseunder theECB'sformercyberincidentreportingframework. 4. Inpractice,this meansbeing able toprevent,withstand,respond to,recoverand learnfrom follows: "the ability of a bank to deliver critical operations through disruption. This ability enables a banktoidentify andprotectitselffromthreats andpotentialfailures,respond and adaptto,aswell as operations through disruption. In considering its operational resilience, a bank should assume that disruptions will occur, and take into account its overall risk appetite and tolerance for disruption." See paragraph11oftheBaselCommittee'sprinciplesforoperationalresilience. 5. See Tuominen, A. (2025), "lmproving banks' resilience to hybrid threats", speech at the conference "The Current Hybrid Threat Environment and Financial Stability",jointlyorganised by Commerzbank B.and Wendelborn, J. (2025),"Cyber threats to financial stability in a complex geopolitical jointly with the educational services industry, and below the public administration, healthcare and technology industries; see the University of Maryland's CISSM Cyber Events Database. In the financesector,February. 6. Some incidents have disrupted payment channels, delayed customer services and, in a few cases, caused notablefinancial losses.But nonehasthreatened theviabilityof amajorbankorproduced a systemicshock. 7. whereasonly62%citecreditrisk.InstituteofInternationalFinance(2026),AnnualEY/llFGlobalBank RiskManagementSurvey-Shifting\_priorities:CROagendasinatimeofuncertainty\_andinnovation, lIF,24February. 8. a systemic crisis,possibly when the ECB's and the NCAs own ICT systems are also affected. This and identifying areas where cooperation should be improved. 9. This is essential because banks increasingly rely on external providers for some critical functions that in the supply chain, even if they themselves have not been directly targeted. 10. 11. Good practicesdonot describe or establishnewregulatoryrequirements and havenolegallybinding implementing any of the good practices pointed by the ECB, provided that it follows other practices that are more appropriate to its particular risk profile, business model and circumstances. 12.
Even if proportionality is already embedded in the European regulatory and supervisory approach, we see room to embrace it further. The small and non-complex institutions (SNCls)regime, is the natural startingpoint,whilemaintaining theSingleRulebook,whichensures therisk-based nature of the of eligible small banks through an increase of the E5 billion threshold of the SNCl regime as well as accompanied by a credible, flexible and efficient crisis management framework for these institutions: EurosystemresponsetotheEuCommission'stargetedconsultationonthecompetitivenessoftheEu banking\_sector,April.
#### CONTACT
### European Central Bank DirectorateGeneralCommunications
- Sonnemannstrasse20 >
- 60314FrankfurtamMain,Germany >
- +496913447455 >
- media@ecb.europa.eu
Reproduction is permitted provided that the source is acknowledged.
Media contacts Copyright 2026, European Central Bank