The Network Forum Annual Meeting in Madrid highlights the themes that emerged at that time, just as tensions flared up in the Middle East. Operational Resilience – unsurprisingly – featured extensively at the conference. Fraser Wikner, CEO at MYRIAD Group Technologies Ltd (MGTL), looks back on the discussions that took place over the three days.
Operational Resilience is on everyone’s minds.
As country risk only deepens, Network Managers are once again having to update their Operational Resilience toolkits.
Even before the dramatic turn of events in the Middle East in June, the International Securities Services Association (ISSA) – in its latest Risk Report – had identified the worsening global geopolitical situation as being something which the industry ought to be actively monitoring.
With all that is happening in the Middle East, Network Teams are looking to learn from some of their experiences in Ukraine following the Russian invasion. During one panel, a speaker told us that whilst relocating staff from Kyiv to Warsaw was fairly frictionless, extracting proprietary data and systems out of Ukraine was far more challenging, mainly due to local regulatory constraints.
I strongly feel that Network Managers should be asking their Agent and Correspondent Banks about whether there are any regulatory barriers across their markets preventing data transfers to third countries, and if so, how this is being factored into their Operational Resilience plans.
I also spoke to several Custodians at TNF who told me they have now banned all travel to the Middle East. However, having implemented virtual due diligences during Covid, Network Managers confidently assured me they are well-positioned to deal with this latest crisis.
Geopolitical risk may be top of mind for many Network Managers, but they also want to know that their Providers are insulated against outages, caused either by natural disasters, cyber-attacks, critical utility or infrastructure failures.
A Network Manager noted that in October 2024, the Bank of England conducted a massive stress test – SIMEX 24 – of the country’s Financial Services industry, examining its ability to respond to a major infrastructure failure, requiring a total shutdown and restart. Six months later, that simulation exercise became reality when the entire Iberian Peninsula was plunged into darkness following a power outage, yet again underscoring just how important it is for Banks and Financial Market Infrastructures (FMIs) to invest in their Operational Resilience.
The good news is that FMIs are indeed taking Operational Resilience seriously, with an expert at TNF noting that the country’s main Exchange – the BME – together with hospitals and airports, were the only three institutions whose lights stayed on for the duration of the crisis.
DORA is still a work in progress.
During TNF, I spoke on a panel about the EU’s Digital Operational Resilience Act (DORA).
Introduced in January 2025, DORA requires Financial Institutions, including Post-Trade Providers, to have measures in place to withstand, respond to and recover from ICT disruptions and threats.
Although DORA has been live for six months, it is still fairly fluid, as Regulators look to tighten up their oversight of Critical Third-Party Service Providers (CTPPs) to EU Financial Firms.
That CTPPs are facing heightened regulatory scrutiny is not surprising. I saw a study by Security ScoreCard, a Cyber Consultancy, which revealed that 41.8% of cyber breaches at top Fin-Tech Companies originated from incidents at their Third-Party Providers, while an additional 11.9% were because of issues at Fourth Parties.
One expert on my panel said the European Supervisory Authorities (ESA) will start identifying CTPPs over the next few months, a designation which will subject them to additional Risk Management and Operational Resilience requirements. CTPP classification will be based on several criteria, including whether an outage at a Third Party would have a material impact on the services provided by Financial Institutions, and the availability of alternative Providers. So-called Non-CTPPs, however, can voluntarily request to be categorised as Critical, which one or two Firms may do, especially if it becomes clear that CTPPs are enjoying a commercial advantage or are having an easier time when being onboarded as Approved Suppliers by Banks and FMIs.
While better supervision of CTPPs is critical, I noted the rules do create additional barriers to entry, particularly for Startup Companies, as CTPPs will be saddled with a EUR 50,000 minimum annual oversight fee. For some businesses, these costs risk being prohibitively expensive. As DORA’s scope continues to widen, Network Managers will need to keep a close eye on the rules, as they will almost certainly add to their existing Due Diligence remits.
Reverse KYCs and DDQs continue their evolution.
Operational Resilience was not the only issue on Network Managers’ minds at TNF.
Reverse Know-Your-Customer (KYC) by Agent Banks on their Global Custodian and Broker Dealer Clients was flagged by several Network Managers as being a problem. One Network Manager told me that while Agent Banks can obtain a lot of the rudimentary KYC information from publicly available sources, some Providers are demanding that the passport details of top Executives and Board Members at Custodians/Brokers be shared with them for KYC purposes.
This creates all sorts of problems. Firstly, it risks contravening the EU’s General Data Protection Regulation (GDPR), where the penalties for non-compliance are severe. Some Banks are also uneasy about turning over such sensitive information, especially in markets where data privacy/protection laws are less well-enshrined or even non-existent. A Network Manager highlighted that Custodians are increasingly pushing back against these requests from Agent Banks, while others are lobbying local Regulators to refine their KYC rules.
I also heard the Association for Financial Markets in Europe’s (AFME) Due Diligence Questionnaire (DDQ) is going through some changes, as it tries to future proof itself for a world where Digital Assets and Traditional Securities are traded in lockstep with each other. Under the proposals, an additional section covering Digital Assets and Digital Asset Custody will be incorporated into the DDQ. At previous TNFs, some experts had called for the creation of a standalone DDQ focused purely on Digital Assets to complement the existing AFME DDQ. However, the consensus in Madrid seems to be that institutional adoption of Digital Assets, such as Tokens and Crypto, etc. has not reached sufficient enough scale to warrant a Digital Asset-only DDQ.

