MFSA brings ICT risk and cybersecurity resources under one hub

MFSA Office photo logo

The Malta Financial Services Authority has updated financial firms on the resources available through its dedicated Supervisory ICT Risk and Cybersecurity (SIRC) webpage, as regulators continue to put greater emphasis on how firms manage technology and cyber risks.

In a circular published on 1 October 2026, the MFSA said the webpage is intended to serve as a central reference point for firms looking for guidance on areas including digital operational resilience, cyber incident reporting, penetration testing and the management of third-party technology providers.

One place for DORA guidance

Much of the material relates to the Digital Operational Resilience Act (DORA), which has applied to in-scope financial entities since January 2025.

DORA introduced a common EU framework for managing technology-related risks across the financial sector. Its requirements cover ICT risk management, the reporting of major technology incidents, resilience testing, third-party ICT risk and arrangements through which firms can share information about cyber threats.

The MFSA’s SIRC webpage now brings together the different regulatory resources firms may need when dealing with these requirements, including circulars, FAQs, guidance documents, user guides and previous Dear CEO letters.

The Authority has particularly drawn attention to updated FAQs covering major ICT-related incidents, significant cyber-threat notifications and information-sharing arrangements.

Guidance on information-sharing arrangements is also available to firms wishing to exchange cyber-threat intelligence such as indicators of compromise, cybersecurity alerts and information on tactics or techniques being used by attackers. These arrangements are intended to allow information to be shared within trusted communities while respecting confidentiality, data protection and competition rules.

Third-party technology remains a key focus

The webpage also contains updated material on the Register of Information, one of DORA’s main requirements relating to ICT third-party providers.

Financial entities falling within the scope of DORA are required to maintain an up-to-date register of their contractual arrangements with external ICT service providers.

This has become increasingly important as financial institutions rely more heavily on cloud infrastructure, software providers and other external technology services.

At EU level, the Registers of Information have also been used by the European Supervisory Authorities to help identify ICT providers considered critical to the wider European financial system.

Cyber resilience moving beyond compliance

The latest circular forms part of a wider push by the MFSA to strengthen digital resilience across Malta’s financial sector.

Earlier supervisory work has highlighted that firms are increasingly aware of their responsibilities under DORA, although the Authority has also identified areas where organisations can strengthen areas such as governance, incident management, ICT risk controls and oversight of technology suppliers.

The MFSA has also placed greater attention on practical resilience measures during 2026. These have included guidance on ICT change management, where firms are expected to assess material technology changes, test systems before deployment and have appropriate rollback and recovery arrangements in place.

The SIRC webpage additionally covers Threat-Led Penetration Testing (TLPT), including Malta’s implementation of the European TIBER framework, which is designed to test how selected financial institutions would withstand sophisticated cyberattacks.

For compliance, risk and technology teams, the MFSA’s message is therefore increasingly clear: managing cyber and ICT risks is becoming an ongoing supervisory responsibility rather than a one-off DORA implementation exercise.

Financial entities have been encouraged to check the SIRC webpage regularly as guidance, FAQs and reporting requirements continue to develop.