On 7 July 2026, ECB Banking Supervision issued a direct letter to the CEOs of significant institutions. A rare, pointed intervention that reframes AI not merely as a business opportunity, but as a structural shift in the cyber threat landscape.
The message from Claudia Buch, Chair of the Supervisory Board, is unambiguous and worthy of attention for all entities across the sector: emerging AI models can now identify software vulnerabilities and generate working exploits at unprecedented speed. The window between a weakness being discovered and being weaponised is collapsing. The ECB is explicit that this is a long-term change in the threat environment, not a passing trend tied to any single tool, or limited to a particular geography or region.
Crucially, the letter stresses that these developments do not create entirely new categories of risk. Instead, they dramatically amplify the speed and scale at which familiar risks materialise, and indeed previously assessed risks require reassessment. That distinction matters: institutions cannot treat this as someone else's problem or a future one. The controls already expected under DORA remain valid, they simply have to work faster, and under far greater pressure.


A deadline, not a discussion paper
This is not guidance to file. The ECB is calling on significant institutions to assess the impact of the evolving threat landscape without delay, and to develop a comprehensive action plan setting out concrete measures, resources, ownership and timelines. That plan must reach the relevant Joint Supervisory Team by 31 October 2026. The ECB will then run a horizontal analysis across submissions to identify sector-wide trends and gaps. This is DORA in action, it is the recognition and embodiment of the act that there is a growing concentration risk.
In return, supervisors are offering some breathing room to focus effort where it counts: the annual IT Risk Questionnaire deadline moves from September 2026 to February 2027, with other supervisory activities reviewed case by case.
"As part of the short-term effort, prioritising protection of perimeter technologies and internet-facing and externally exposed ICT assets, including third-party software and open-source components, is key to preparing for the rise in AI-enabled cybersecurity threats."
ECB Banking Supervision, Letter to CEOs, 7 July 2026
The emphasis on the perimeter is deliberate. AI-enabled adversaries are already probing internet-facing systems, this is their first act, and the modern attack surface extends well beyond a bank's own code into third-party software and open-source dependencies buried deep in the supply chain. Knowing what you expose, and to whom, is the precondition for defending it.
The short-term priorities
Under the immediate, short-term effort, the ECB asks institutions to concentrate on four fronts:
Protect the attack surface
Minimise and continuously monitor every internet-facing and externally exposed asset, including cloud and third-party connections. This assumes an understanding where the perimeter sits.
Patch at scale
Accelerate vulnerability scanning and patch management to cope with the rising speed and volume of disclosure. This includes revisiting previously risk accepted vulnerabilities, the ability of models to chain vulnerabilities in attacks requires a re-examination.
Detect with AI
Enhance monitoring, detection and AI-enabled defensive capabilities across applications, logs and network traffic. This is naturally going to lag behind the offensive
Assure the supply chain
Verify that third-party risk management is fit for purpose given the role of ICT providers in critical supply chains. In many cases, this extends into fourth and even fifth party providers.
Beyond the sprint: structural resilience
Short-term fixes buy time; they do not build durability. The ECB is equally clear that operational and cyber resilience must be advanced through deeper, structural measures:
Reinforce defence-in-depth and modernise
Strengthen cyber hygiene and defence-in-depth, and modernise infrastructure by replacing or updating legacy, unsupported or end-of-life technologies before they become the softest target.
Improve response, recovery and sharing
Advance operational resilience through tested response and recovery mechanisms, including crisis management, and through secure information-sharing arrangements across the sector.
Read together, these two horizons form a single message: assume the perimeter will be breached, and design to withstand it. A prudent posture no longer treats a breach as a failure state to be avoided at all costs, but as a scenario to be survived, through segmentation, zero-trust principles, resilient recovery, and the muscle memory that only regular exercises build.
What this means for board members and executives
The ECB places responsibility squarely with management bodies. Strategic ICT decisions, investment, resourcing and risk-tolerance frameworks, may need to be revisited, and governance strengthened where necessary. Open supervisory findings from previous inspections and the 2024 cyber-resilience stress test should be closed without delay; in an accelerating threat landscape, unresolved weaknesses only grow more material.
For institutions, the practical question between now and 31 October is not whether to act, but whether their action plan will withstand scrutiny. That demands an honest view of the attack surface, a realistic assessment of patch and recovery capacity, and clear ownership from the top.

Is your action plan ready for the JST?
Thomas Murray helps institutions map their attack surface, benchmark ICT resilience and build supervisory-ready action plans ahead of the October deadline. We also offer confidential cybersecurity advisory services to executives acting as a trusted independent advisor helping executives and board members to prepare, focus on key issues and ask the questions that matter.
Insights

The ECB Sounds the Alarm on AI-Enabled Cyber Threats
Stay ahead of the curve with Cyber Series, your essential update on the evolving threat landscape.

Global Cyber Threat Briefing: June 2026 Attack Statistics and Trends
Stay ahead of the curve with Cyber Series, your essential update on the evolving threat landscape.

The DENIC Disruption and NIS2: Critical Infrastructure Under New Rules
Stay ahead of the curve with Cyber Series, your essential update on the evolving threat landscape.

US is Most Attacked Nation, Driven by Ransomware and Data Exfiltration
Stay ahead of the curve with Cyber Series, your essential update on the evolving threat landscape.
