information and communication technology (ict) has dramatically shaped financial services in the last decade or two, connecting one of the oldest industries globally to the digital world. in light of this, the european banking authority (eba) identified the need to address security risks arising from electronic payments and, subsequently, released a set of guidelines in 2017 that also support the objectives of the payment services directive (psd2). to bridge this gap, the eba established new requirements in 2019 that also apply to credit institutions and investment firms and, thus, ensure a consistent and robust approach in the financial sector across the european single market.

in december 2020, the mfsa issued new guidelines to harmonise the management of ict and security risks within the financial services industry, in line with the direction established by european supervisory authorities. these recommendations are applicable to a wide range of financial services entities, namely: ict and security risk management is all about identifying and preparing for adverse situations that usually result from inadequate internal processes, external events such as cyber attacks, or even natural threats such as the covid-19 pandemic proved to be. the general data protection regulation (gdpr) came into force on 25 may 2018. the objective behind this european regulation was to modernise laws due to rapid…