2026-03-05

Added · Updated

Exercising Caution in Times of Heightened Cyber Threat

The Malta Financial Services Authority requires Authorised Persons to maintain an elevated cyber posture by enforcing multi-factor authentication, least privilege access, and continuous monitoring of logs and alerts. Boards of Directors must ensure ICT and cybersecurity risks are adequately discussed and managed, while Authorised Persons must centralize logs for critical systems and deploy advanced threat detection technologies. Authorised Persons are required to re-validate incident response playbooks to ensure immediate notification of confirmed intrusions and confirm that all critical functions fall within the scope of their ICT business continuity policies. Additionally, entities must report major ICT-related incidents within stipulated time frames as per Commission Delegated Regulations (EU) 2024/1772 and 2025/301.

Malta Financial Services Authority logo

Malta

Malta Financial Services Authority

Click to view full text

More like this from MFSA

MFSA published 5 documents in the last 30 days. We email you each new one the day it's published.

Share