2026-03-05
Added · Updated
The Malta Financial Services Authority requires Authorised Persons to maintain an elevated cyber posture by enforcing multi-factor authentication, least privilege access, and continuous monitoring of logs and alerts. Boards of Directors must ensure ICT and cybersecurity risks are adequately discussed and managed, while Authorised Persons must centralize logs for critical systems and deploy advanced threat detection technologies. Authorised Persons are required to re-validate incident response playbooks to ensure immediate notification of confirmed intrusions and confirm that all critical functions fall within the scope of their ICT business continuity policies. Additionally, entities must report major ICT-related incidents within stipulated time frames as per Commission Delegated Regulations (EU) 2024/1772 and 2025/301.
More like this from MFSA
MFSA published 5 documents in the last 30 days. We email you each new one the day it's published.