In response to ECB mandate SSM-2026-0301
The ECB AI cyber risk mandate just made AI-powered attacks a board-level emergency. Here's your playbook.
What EU zone financial institutions must deliver by October 31, 2026, and the 7 operational tracks that build real AI-powered attack readiness.
We spoke with CISOs and CIOs who are already preparing their AI cyber resilience plans, partners at Big-4 consulting firms advising regulated institutions, and our own teams who have worked alongside Fortune 50 organizations testing AI-powered attacks in production.
This briefing is our interpretation of the European Central Bank (ECB) supervisory mandate—a practical guide for building your plan or pressure testing your response. It translates the ECB’s requirements into 7 operational workstreams with clear ownership and actionable checklists you can use internally or share with your Joint Supervisory Team (JST), distinguishing between what the ECB expects and our recommendations for AI-powered attack readiness for financial services.
Part 1
What the ECB requires
The regulation itself, its timeline, and the specific focus areas from the letter. Everything in Part 1 is sourced from the ECB's published letter (SSM-2026-0301) and the ESRB warning.
Part 2
Our recommended approach
How to organize, staff, and execute the plan: stakeholders (RACI), war rooms, operational tracks, and Silverfort capability mappings. These are our recommendations, not regulatory requirements.
What we learned from frontier AI attacks in the field
Frontier AI models do not focus on finding new vulnerabilities or start with the most sophisticated exploit in their arsenal. They start with what is easiest and most likely to succeed: on-prem infrastructure and legacy systems.
Before any advanced exploitation takes place, the AI identifies and leverages under-protected identities and weak access controls to move laterally across systems and escalate privileges.
That finding, documented in detail in The Mythos Field Report and corroborated across every environment our teams tested, should shape where you invest your effort between now and October 31.
Discover our insights—and what actually stopped AI-powered attacks—in The Mythos Field Report
Part 1: The Mandate
What happened and what bank executives need to know
On July 7, 2026, the ECB’s Chair of the Supervisory Board, Claudia Buch, sent a formal letter to the CEOs of the roughly 110 significant institutions it supervises under the SSM (Single Supervisory Mechanism), requiring a comprehensive AI cyber threat action plan grounded in the Digital Operational Resilience Act (DORA)—due to the Joint Supervisory Team by October 31, 2026.
The ECB also postponed its annual IT Risk Questionnaire from September 2026 to February 2027.
The same day, the European Systemic Risk Board (ESRB) raised systemic cyber risk to “severe”, calling frontier AI a “paradigm shift”. The European Supervisory Authorities (EBA, EIOPA, ESMA) and the Five Eyes cyber security agencies issued parallel statements and a call to action to address the evolving landscape of AI-based threats.
Who must comply with the ECB-issued mandate
Directly
The ~110 ECB-supervised significant institutions, including Euro-area entities of global banking groups.
Indirectly
National regulators for every other EU country are expected to follow suit.
The timeline that matters
ESRB raises systemic cyber risk to "severe"
ECB letter; ESRB formal warning; ESA statement
Deadline
Action plan due to your JST
JST engagement; ECB horizontal analysis
Deferred IT Risk Questionnaire due
Why the ECB has issued their AI cyber risk mandate now
Three developments converged.
01
Mythos crossed the autonomous offensive threshold.
On April 7, 2026, Anthropic announced Project Glasswing and Claude Mythos Preview. It autonomously discovered and exploited zero-day vulnerabilities across every major OS and browser, producing 181 working exploits where the prior model produced 2. The UK AI Security Institute (AISI) confirmed it as the first model to complete a 32-step simulated network takeover (3/10 attempts, 20 hours for humans). Comparable open-weight capability is estimated 6-24 months out.
02
APTs are already using LLMs in live operations.
Russia’s APT28 deployed LAMEHUG malware (CERT-UA) that queries an LLM in real time to decide its next move. Google’s GTIG confirmed all four nation-state threat actors already operationalized LLMs in 2025.
03
The ECB assumes perimeter defenses will be breached.
The letter explicitly requires zero-trust principles, continuous verification, segmentation, and robust access controls with least privilege, MFA, and comprehensive logging. It names service accounts, APIs, and devices as subjects of continuous verification. They are mandating prevention, not faster detection.
AI changed the assumptions behind cybersecurity
For years, enterprise security relied on a familiar model: an attacker gets in, tools generate alerts, the SOC investigates, and incident response contains the breach. That model assumed defenders had time.
AI changes that equation. Instead of requiring days of manual effort, AI can autonomously discover attack paths, adapt when blocked, chain legitimate identities, and escalate privileges at machine speed.
The question is no longer whether security teams can detect attacks quickly enough. It is whether they can stop attackers before they move.
Identity has become the critical control plane
One of the biggest misconceptions about AI-powered attacks is that they depend on revolutionary new exploits. In practice, they rely on legitimate identities. As detailed in The Mythos Field Report, the AI repeatedly abused:
- AD trust relationships
- Service accounts
- Privileged identities
- Legacy protocols
- Misconfigured permissions
Once inside, it moved laterally using legitimate credentials until it reached higher-value systems.
This changes how banks should think about resilience. Patching and detection remain essential, but neither stops an attacker from abusing trusted identities once authentication succeeds. Identity has become the control plane for AI-powered attacks.
This matters even more in hybrid banking environments that still depend on Active Directory and legacy systems. In these environments, the speed of AI-powered attacks becomes the multiplier of existing risk.
The practical implication: If identity is where AI-powered attacks move, identity is where control must be enforced.
case study
Learn how a Fortune 50 company stopped Mythos
What actually stopped it
Why inline, runtime Identity Security matters
We have established two facts: AI-powered attacks move through identities, and machine-speed attacks leave little to no time for detection and response. So, what can actually stop them?
The challenge is that most Identity Security controls were never designed for this reality. They operate before or after authentication, not during it, when the access decision is made.
IGA reviews access periodically rather than evaluating risk in real time. PAM protects only a fraction of privileged identities, leaving significant gaps across modern environments. Detection and response activate only after authentication succeeds—far too late when AI-powered attackers can chain identities, move laterally, and escalate privileges in minutes.
None were designed for machine-speed attacks across hybrid environments. Individually and together, they leave a critical gap that AI-powered attackers exploit to move laterally and escalate privileges at machine speed.

What actually stopped it
The only controls proven to stop these attacks were the ones enforced inline, at the moment of authentication. Inline identity controls interrupted attack chains before attackers could move laterally or escalate privileges.
“What remains standing after Mythos compresses the full attack chain into minutes is runtime control. Evaluate identity, understand context, assess risk, and enforce the access decision inline, before authentication completes. A service account that has authenticated to two servers for three years suddenly requests a domain controller at 3am: denied in milliseconds. That is runtime Identity Security.”

Roy Akerman
VP of Identity Security Strategy at Silverfort
Learn more about Mythos and the collapse of identity attack timelines: Why runtime is the only answer
What the ECB is asking banks to do
The ECB’s expectations are grounded in the Digital Operational Resilience Act (DORA) (Regulation (EU) 2022/2554) and implementing its supervisory guidance. They are split into 6 focus areas which are practical, risk-based, and divided into immediate and longer-term actions.
The table below summarizes these expectations. Throughout the table, each recommendation is labeled either (ECB), indicating an expectation reflected in the ECB’s communication, or (Recommended), indicating a complementary best practice that strengthens resilience against AI-powered cyber threats.
ECB
ECB expectation
Silverfort
Recommended best practice
Short-term (Areas 1-4): Concrete measures by October 31
Area 1
Attack surface
Prioritise the protection of potential attack surfaces.
Area 2
Patch management
Accelerate vulnerability and patch management at scale.
Area 3
Monitoring & detection
Enhance monitoring, detection and AI-enabled defensive capabilities.
Area 4
Governance & supply chain
Strengthen governance, funding, awareness training and supply chain assurance.
Long-term (Areas 5-6): Credible roadmap with milestones
Area 5
Defense-in-depth & zero trust
Reinforce defence-in-depth and cyber hygiene; modernise infrastructure.
Area 6
Operational resilience
Improve response and recovery, crisis management, and information-sharing.
Cross-cutting requirements
Part 2: Our recommended implementation approach
The opportunity inside the ECB AI cyber risk mandate
Below are our recommendations for how to organize and execute the plan the ECB requires. The stakeholders mapping, operational tracks, and war rooms are not regulatory requirements. They are our interpretation of what works, informed by the global organizations we have helped prepare.
Compliance is not security, but this mandate gives you three things that are usually hard to get:
A funding case
The ECB explicitly asks boards to assess whether ICT budgets are sufficient.
Cover for org redesign
Put IAM under the CISO and connect the SOC to identity.
Board accountability
Responsibility placed "primarily" with the management body. Move before October.
Mapping ECB areas to 7 working tracks
The ECB has 6 focus areas. We recommend running them as 7 operational tracks, splitting Identity Security out of Area 5 as its own workstream because it has its own dedicated team, tooling, and budget line.
| ECB Area | Your Working Track | Recommendation |
|---|---|---|
| Area 1: Attack surfaces | Track 1: Asset visibility | Keep as is—direct 1:1 |
| Area 2: Patch management | Track 2: Patch at scale | Keep as is—direct 1:1 |
| Area 3: Monitoring & detection | Track 3: Monitoring & detection | Keep as is—direct 1:1 |
| Area 4: Governance & supply chain | Track 4: Governance & supply chain | Keep as is—direct 1:1 |
| Area 5: Defense-in-depth | Track 5: Identity, access & zero trust | Split: identity controls get their own track |
| Area 5 (continued) | Track 6: Legacy modernization & infra | Split: infrastructure stays here |
| Area 6: Operational resilience | Track 7: Operational resilience | Keep as is—direct 1:1 |
When you submit to the JST, map your track-level work back to the ECB's 6-area structure. Internally, run identity as its own track.
RACI model: Who owns what
The RACI model maps the involved stakeholders’ responsibility assignment to a matrix to define who does what: Responsible, Accountable, Consulted, and Informed. Identity teams appear as Responsible (R) across four tracks, not just Track 5. If your identity function is staffed for only one, this RACI shows you the gap.
| Track | Accountable | Responsible | Identity team role |
|---|---|---|---|
| 1. Asset visibility | CIO | Head of Infra | Consulted: identity trust paths |
| 2. Patch at scale | CIO | Head of Infra | Informed |
| 3. Monitoring & detection | CISO | SOC Lead + Head of IAM | Responsible: credential-based detection, behavioral baselines |
| 4. Governance & funding | Board Risk Cttee | CIO + CISO + Head of IAM | Responsible: access certification, identity risk metrics |
| 5. Identity & zero trust | CISO | Head of IAM | Responsible: full track ownership |
| 6. Legacy & infra | CIO | Head of Infra + Head of IAM | Responsible: least privilege, MFA, compensating controls |
| 7. Operational resilience | CIO | Head of BCM (Business Continuity Management) | Consulted: identity containment |
War rooms for AI-powered attacks
While not explicitly required by the ECB, we recommend establishing a structured war room cadence to accelerate execution, remove blockers, and ensure board-level visibility ahead of the October 31 deadline.
Tactical
Weekly
IAM, SOC, patch, infra engineers.
Output: Live tracker across 7 tracks, blockers escalated in 48 hours.
Operational
Bi-weekly
CISO, Head of IAM, SOC Lead, Head of Infra, Vendor Risk, GRC.
Output: Program status, budget calls, draft plan sections.
Board
Monthly
CEO, CIO, CISO, Board Risk Committee.
Output: Metrics update, risk-tolerance decisions, sign-off.
Identity Security action items across all ECB AI cyber risk mandate areas
Identity security is not confined to a single area. The ECB's expectations embed identity requirements across all of them. Below is a consolidated view for your IAM team.
01
Attack surface
Action items
Discover all human and machine identities, including service accounts and legacy authentication protocols. Map Active Directory trust relationships as part of the attack surface.
How Silverfort helps
Silverfort continuously discovers and inventories every identity and its relationships, providing complete visibility and context. It automatically identifies and prioritizes risky identities, including shadow admins, dormant service accounts, and other unmanaged privileged identities.
02
Patch management
Action items
For systems with unpatched vulnerabilities, enforce stronger identity controls on authentication paths leading to those systems.
How Silverfort helps
Silverfort enforces adaptive MFA or blocks access to specific systems on demand, buying your patching teams valuable remediation time. MFA can also be extended to Active Directory, legacy applications, and homegrown systems that cannot natively support modern authentication.
03
Monitoring
Action items
- Strengthen monitoring of authentication events.
- Deploy behavioral baselining for identity activity.
- Feed identity anomaly signals into the SOC.
How Silverfort helps
04
Governance
Action items
- Include identity risk metrics within the organization’s risk appetite framework.
- Assess whether IAM staffing and capabilities are sufficient for the expanded scope.
How Silverfort helps
05
Defense-in-depth
Action items
- Implement continuous verification, Least Privilege, MFA (including for legacy systems), and identity-based segmentation.
- Extend privileged access protection beyond traditional PAM vault coverage.
How Silverfort helps
Silverfort Runtime Access Protection (RAP) evaluates every authentication in real time and enforces security inline with the authentication flow — allowing, blocking, or stepping up authentication before access is granted. It protects hybrid environments without application changes, infrastructure modifications, or complex refactoring projects.
These are the controls that consistently stopped Mythos:
- Adaptive, In-Flow MFA — Extends MFA to Active Directory, legacy applications, RDP, file shares, command-line tools, and other systems that cannot natively support modern authentication.
- Just-in-Time (JIT) Access & Dynamic Policies — Protect high-risk and privileged access by enforcing JIT access and risk-based policies, eliminating standing privileges without adding unnecessary user friction.
- Virtual Fencing — Prevents service account abuse by restricting where and how service accounts can authenticate, without rotating credentials or disrupting critical business processes.
- Identity Segmentation — Stops lateral movement by restricting where compromised identities can authenticate and which resources they can access.
06
Resilience
Action items
- Include identity containment in cyber crisis playbooks.
- Ensure compromised identities can be isolated during active incidents.
How Silverfort helps
Silverfort enables emergency enforcement of deny or step-up authentication policies on compromised identities within seconds, containing the blast radius while the SOC investigates and remediates the incident.
How Silverfort maps to the ECB's requirements.
Our teams stopped Mythos in production. The inline identity controls blocked the attacks at the authentication boundary. Here is the summary—and you can read more about it in The Mythos Field Report.
| ECB Area | Threat from frontier AI | Silverfort capability |
|---|---|---|
| Area 1: Attack surface | AI rapidly discovers unmanaged identities, trust relationships, service accounts, and legacy authentication paths to build attack chains. | Complete visibility and context: Continuously discovers every identity, maps relationships, and prioritizes risky identities such as shadow admins and dormant service accounts. |
| Area 2: Patch management | AI exploits known vulnerabilities before organizations can patch them. | Adaptive access controls: Enforce step-up MFA or block access to vulnerable systems, reducing exposure while remediation is underway. |
| Area 3: Monitoring | Credential-based attacks span dozens of authentication paths simultaneously, overwhelming traditional monitoring. | Identity Threat Detection and Response (ITDR): Behavioral baselining, real-time identity anomaly detection, and identity risk signals integrated with SIEM/SOAR platforms. |
| Area 4: Governance | AI expands the identity attack surface faster than organizations can inventory, assess, and govern it, leaving boards without accurate visibility into identity risk. | Identity Security Posture Management: Continuously measures identity risk, providing visibility into privileged accounts, orphaned service accounts, control gaps, and high-risk exposures, with prioritized remediation guidance. |
| Area 5: Defense-in-depth & zero trust | AI chains legitimate identities, service accounts, and trust relationships at machine speed. | Runtime Access Protection (RAP): Evaluates every authentication and enforces security controls inline with the authentication flow - allowing, blocking, or stepping up authentication before access is granted: Adaptive MFA, Just-in-Time (JIT) access, and risk-based policies, service account virtual fencing, Identity Segmentation |
| Area 6: Resilience | AI-powered attacks complete lateral movement and privilege escalation before responders can react. | Inline Incident Containment: Instantly isolate compromised identities, enforce emergency access policies, and contain attack paths within seconds. |
The next step
Discover how to stop AI-powered attacks
Get the complete readiness guide for identity and security teams.

FAQs
What does the ECB require European banks to do on AI cyber threats?
Why is the ECB concerned about AI-powered attacks?
Emerging frontier AI models can discover vulnerabilities and generate working exploits at unprecedented speed. But they don’t necessarily rely on novel techniques – they identify and chain together existing weaknesses and risks, exploit legitimate identities, misconfigurations, excessive permissions, and trust relationships to move laterally across the environment and escalate privileges till they achieve their goal. As AI compresses the time between initial access and business impact, the window for detection and response becomes too small, making traditional reactive defenses increasingly ineffective.
Why is this a board-level issue for financial institutions?
Where does identity security fit into an AI cyber action plan?
Identity is the control plane for AI-powered attacks. Rather than relying on new exploits, AI attackers chain together legitimate identities, excessive privileges, and trust relationships to move laterally at machine speed. Runtime identity controls enforced inline, before authentication completes, can stop credential abuse before access is granted, preventing attacks from spreading and reducing business impact. Learn more in The Mythos Field Report.