In response to ECB mandate SSM-2026-0301

The ECB AI cyber risk mandate just made AI-powered attacks a board-level emergency. Here's your playbook.

What EU zone financial institutions must deliver by October 31, 2026, and the 7 operational tracks that build real AI-powered attack readiness.

We spoke with CISOs and CIOs who are already preparing their AI cyber resilience plans, partners at Big-4 consulting firms advising regulated institutions, and our own teams who have worked alongside Fortune 50 organizations testing AI-powered attacks in production.

This briefing is our interpretation of the European Central Bank (ECB) supervisory mandate—a practical guide for building your plan or pressure testing your response. It translates the ECB’s requirements into 7 operational workstreams with clear ownership and actionable checklists you can use internally or share with your Joint Supervisory Team (JST), distinguishing between what the ECB expects and our recommendations for AI-powered attack readiness for financial services.

What we learned from frontier AI attacks in the field

Frontier AI models do not focus on finding new vulnerabilities or start with the most sophisticated exploit in their arsenal. They start with what is easiest and most likely to succeed: on-prem infrastructure and legacy systems.

Before any advanced exploitation takes place, the AI identifies and leverages under-protected identities and weak access controls to move laterally across systems and escalate privileges.

That finding, documented in detail in The Mythos Field Report and corroborated across every environment our teams tested, should shape where you invest your effort between now and October 31.

Discover our insights—and what actually stopped AI-powered attacks—in The Mythos Field Report

Part 1: The Mandate

What happened and what bank executives need to know

On July 7, 2026, the ECB’s Chair of the Supervisory Board, Claudia Buch, sent a formal letter to the CEOs of the roughly 110 significant institutions it supervises under the SSM (Single Supervisory Mechanism), requiring a comprehensive AI cyber threat action plan grounded in the Digital Operational Resilience Act (DORA)—due to the Joint Supervisory Team by October 31, 2026.

The ECB also postponed its annual IT Risk Questionnaire from September 2026 to February 2027. 

The same day, the European Systemic Risk Board (ESRB) raised systemic cyber risk to “severe”, calling frontier AI a “paradigm shift”. The European Supervisory Authorities (EBA, EIOPA, ESMA) and the Five Eyes cyber security agencies issued parallel statements and a call to action to address the evolving landscape of AI-based threats.

Who must comply with the ECB-issued mandate

Directly

The ~110 ECB-supervised significant institutions, including Euro-area entities of global banking groups.

Indirectly

National regulators for every other EU country are expected to follow suit.

The timeline that matters

June 25 2026

ESRB raises systemic cyber risk to "severe"

July 7 2026

ECB letter; ESRB formal warning; ESA statement

October 31 2026

Deadline

Action plan due to your JST

After submission

JST engagement; ECB horizontal analysis

February 2027

Deferred IT Risk Questionnaire due

Why the ECB has issued their AI cyber risk mandate now

Three developments converged.

01

Mythos crossed the autonomous offensive threshold.

On April 7, 2026, Anthropic announced Project Glasswing and Claude Mythos Preview. It autonomously discovered and exploited zero-day vulnerabilities across every major OS and browser, producing 181 working exploits where the prior model produced 2. The UK AI Security Institute (AISI) confirmed it as the first model to complete a 32-step simulated network takeover (3/10 attempts, 20 hours for humans). Comparable open-weight capability is estimated 6-24 months out.

02

APTs are already using LLMs in live operations.

Russia’s APT28 deployed LAMEHUG malware (CERT-UA) that queries an LLM in real time to decide its next move. Google’s GTIG confirmed all four nation-state threat actors already operationalized LLMs in 2025.

03

The ECB assumes perimeter defenses will be breached.

The letter explicitly requires zero-trust principles, continuous verification, segmentation, and robust access controls with least privilege, MFA, and comprehensive logging. It names service accounts, APIs, and devices as subjects of continuous verification. They are mandating prevention, not faster detection.

AI changed the assumptions behind cybersecurity

For years, enterprise security relied on a familiar model: an attacker gets in, tools generate alerts, the SOC investigates, and incident response contains the breach. That model assumed defenders had time.

AI changes that equation. Instead of requiring days of manual effort, AI can autonomously discover attack paths, adapt when blocked, chain legitimate identities, and escalate privileges at machine speed. The question is no longer whether security teams can detect attacks quickly enough. It is whether they can stop attackers before they move.


Identity has become the critical control plane

One of the biggest misconceptions about AI-powered attacks is that they depend on revolutionary new exploits. In practice, they rely on legitimate identities. As detailed in The Mythos Field Report, the AI repeatedly abused:

Once inside, it moved laterally using legitimate credentials until it reached higher-value systems.

This changes how banks should think about resilience. Patching and detection remain essential, but neither stops an attacker from abusing trusted identities once authentication succeeds. Identity has become the control plane for AI-powered attacks.

This matters even more in hybrid banking environments that still depend on Active Directory and legacy systems. In these environments, the speed of AI-powered attacks becomes the multiplier of existing risk.

The practical implication: If identity is where AI-powered attacks move, identity is where control must be enforced.

case study

Learn how a Fortune 50 company stopped Mythos

What actually stopped it

Why inline, runtime Identity Security matters

We have established two facts: AI-powered attacks move through identities, and machine-speed attacks leave little to no time for detection and response. So, what can actually stop them?

The challenge is that most Identity Security controls were never designed for this reality. They operate before or after authentication, not during it, when the access decision is made.

IGA reviews access periodically rather than evaluating risk in real time. PAM protects only a fraction of privileged identities, leaving significant gaps across modern environments. Detection and response activate only after authentication succeeds—far too late when AI-powered attackers can chain identities, move laterally, and escalate privileges in minutes.

None were designed for machine-speed attacks across hybrid environments. Individually and together, they leave a critical gap that AI-powered attackers exploit to move laterally and escalate privileges at machine speed.

AI powered attacks against traditional identity controls – Silverfort

What actually stopped it

The only controls proven to stop these attacks were the ones enforced inline, at the moment of authentication. Inline identity controls interrupted attack chains before attackers could move laterally or escalate privileges.

Quote-gradient

“What remains standing after Mythos compresses the full attack chain into minutes is runtime control. Evaluate identity, understand context, assess risk, and enforce the access decision inline, before authentication completes. A service account that has authenticated to two servers for three years suddenly requests a domain controller at 3am: denied in milliseconds. That is runtime Identity Security.”

Roy-Akerman-Headshot-2.jpg

Roy Akerman

VP of Identity Security Strategy at Silverfort

Learn more about Mythos and the collapse of identity attack timelines: Why runtime is the only answer

What the ECB is asking banks to do

The ECB’s expectations are grounded in the Digital Operational Resilience Act (DORA) (Regulation (EU) 2022/2554) and implementing its supervisory guidance. They are split into 6 focus areas which are practical, risk-based, and divided into immediate and longer-term actions.

The table below summarizes these expectations. Throughout the table, each recommendation is labeled either (ECB), indicating an expectation reflected in the ECB’s communication, or (Recommended), indicating a complementary best practice that strengthens resilience against AI-powered cyber threats.

ECB

ECB expectation

Silverfort

Recommended best practice

Short-term (Areas 1-4): Concrete measures by October 31

Area 1

Attack surface

Prioritise the protection of potential attack surfaces.

Area 2

Patch management

Accelerate vulnerability and patch management at scale.

Area 3

Monitoring & detection

Enhance monitoring, detection and AI-enabled defensive capabilities.

Area 4

Governance & supply chain

Strengthen governance, funding, awareness training and supply chain assurance.

Long-term (Areas 5-6): Credible roadmap with milestones

Area 5

Defense-in-depth & zero trust

Reinforce defence-in-depth and cyber hygiene; modernise infrastructure.

Area 6

Operational resilience

Improve response and recovery, crisis management, and information-sharing.

Cross-cutting requirements

Part 2: Our recommended implementation approach

The opportunity inside the ECB AI cyber risk mandate

Below are our recommendations for how to organize and execute the plan the ECB requires. The stakeholders mapping, operational tracks, and war rooms are not regulatory requirements. They are our interpretation of what works, informed by the global organizations we have helped prepare.

Compliance is not security, but this mandate gives you three things that are usually hard to get:

A funding case

The ECB explicitly asks boards to assess whether ICT budgets are sufficient.

Cover for org redesign

Put IAM under the CISO and connect the SOC to identity.

Board accountability

Responsibility placed "primarily" with the management body. Move before October.

Mapping ECB areas to 7 working tracks

The ECB has 6 focus areas. We recommend running them as 7 operational tracks, splitting Identity Security out of Area 5 as its own workstream because it has its own dedicated team, tooling, and budget line.

ECB AreaYour Working TrackRecommendation
Area 1: Attack surfacesTrack 1: Asset visibilityKeep as is—direct 1:1
Area 2: Patch managementTrack 2: Patch at scaleKeep as is—direct 1:1
Area 3: Monitoring & detectionTrack 3: Monitoring & detectionKeep as is—direct 1:1
Area 4: Governance & supply chainTrack 4: Governance & supply chainKeep as is—direct 1:1
Area 5: Defense-in-depthTrack 5: Identity, access & zero trustSplit: identity controls get their own track
Area 5 (continued)Track 6: Legacy modernization & infraSplit: infrastructure stays here
Area 6: Operational resilienceTrack 7: Operational resilienceKeep as is—direct 1:1

When you submit to the JST, map your track-level work back to the ECB's 6-area structure. Internally, run identity as its own track.

RACI model: Who owns what

The RACI model maps the involved stakeholders’ responsibility assignment to a matrix to define who does what: Responsible, Accountable, Consulted, and Informed. Identity teams appear as Responsible (R) across four tracks, not just Track 5. If your identity function is staffed for only one, this RACI shows you the gap.

TrackAccountableResponsibleIdentity team role
1. Asset visibilityCIOHead of InfraConsulted: identity trust paths
2. Patch at scaleCIOHead of InfraInformed
3. Monitoring & detectionCISOSOC Lead + Head of IAMResponsible: credential-based detection, behavioral baselines
4. Governance & fundingBoard Risk CtteeCIO + CISO + Head of IAMResponsible: access certification, identity risk metrics
5. Identity & zero trustCISOHead of IAMResponsible: full track ownership
6. Legacy & infraCIOHead of Infra + Head of IAMResponsible: least privilege, MFA, compensating controls
7. Operational resilienceCIOHead of BCM (Business Continuity Management)Consulted: identity containment

War rooms for AI-powered attacks

While not explicitly required by the ECB, we recommend establishing a structured war room cadence to accelerate execution, remove blockers, and ensure board-level visibility ahead of the October 31 deadline.

Tactical

Weekly

IAM, SOC, patch, infra engineers.

Output: Live tracker across 7 tracks, blockers escalated in 48 hours.

Operational

Bi-weekly

CISO, Head of IAM, SOC Lead, Head of Infra, Vendor Risk, GRC.

Output: Program status, budget calls, draft plan sections.

Board

Monthly

CEO, CIO, CISO, Board Risk Committee.

Output: Metrics update, risk-tolerance decisions, sign-off.

Identity Security action items across all ECB AI cyber risk mandate areas

Identity security is not confined to a single area. The ECB's expectations embed identity requirements across all of them. Below is a consolidated view for your IAM team.

01

Attack surface

Action items

Discover all human and machine identities, including service accounts and legacy authentication protocols. Map Active Directory trust relationships as part of the attack surface.

How Silverfort helps

Silverfort continuously discovers and inventories every identity and its relationships, providing complete visibility and context. It automatically identifies and prioritizes risky identities, including shadow admins, dormant service accounts, and other unmanaged privileged identities.

02

Patch management

Action items

For systems with unpatched vulnerabilities, enforce stronger identity controls on authentication paths leading to those systems.

How Silverfort helps

Silverfort enforces adaptive MFA or blocks access to specific systems on demand, buying your patching teams valuable remediation time. MFA can also be extended to Active Directory, legacy applications, and homegrown systems that cannot natively support modern authentication.

03

Monitoring

Action items

  • Strengthen monitoring of authentication events.
  • Deploy behavioral baselining for identity activity.
  • Feed identity anomaly signals into the SOC.

How Silverfort helps

Silverfort continuously baselines authentication behavior, detects credential-based anomalies in real time, and feeds identity risk signals directly into your SIEM and SOAR platforms.

04

Governance

Action items

  • Include identity risk metrics within the organization’s risk appetite framework.
  • Assess whether IAM staffing and capabilities are sufficient for the expanded scope.

How Silverfort helps

Silverfort provides continuous visibility into identity risk, including privileged account coverage, control gaps, orphaned service accounts, and other high-risk identities. Risks are prioritized by severity, with actionable remediation guidance.

05

Defense-in-depth

Action items

  • Implement continuous verification, Least Privilege, MFA (including for legacy systems), and identity-based segmentation.
  • Extend privileged access protection beyond traditional PAM vault coverage.

How Silverfort helps

Silverfort Runtime Access Protection (RAP) evaluates every authentication in real time and enforces security inline with the authentication flow — allowing, blocking, or stepping up authentication before access is granted. It protects hybrid environments without application changes, infrastructure modifications, or complex refactoring projects.

These are the controls that consistently stopped Mythos:

  • Adaptive, In-Flow MFA — Extends MFA to Active Directory, legacy applications, RDP, file shares, command-line tools, and other systems that cannot natively support modern authentication.
  • Just-in-Time (JIT) Access & Dynamic Policies — Protect high-risk and privileged access by enforcing JIT access and risk-based policies, eliminating standing privileges without adding unnecessary user friction.
  • Virtual Fencing — Prevents service account abuse by restricting where and how service accounts can authenticate, without rotating credentials or disrupting critical business processes.
  • Identity Segmentation — Stops lateral movement by restricting where compromised identities can authenticate and which resources they can access.

06

Resilience

Action items

  • Include identity containment in cyber crisis playbooks.
  • Ensure compromised identities can be isolated during active incidents.

How Silverfort helps

Silverfort enables emergency enforcement of deny or step-up authentication policies on compromised identities within seconds, containing the blast radius while the SOC investigates and remediates the incident.

How Silverfort maps to the ECB's requirements.

Our teams stopped Mythos in production. The inline identity controls blocked the attacks at the authentication boundary. Here is the summary—and you can read more about it in The Mythos Field Report.

ECB AreaThreat from frontier AISilverfort capability
Area 1: Attack surfaceAI rapidly discovers unmanaged identities, trust relationships, service accounts, and legacy authentication paths to build attack chains.Complete visibility and context: Continuously discovers every identity, maps relationships, and prioritizes risky identities such as shadow admins and dormant service accounts.
Area 2: Patch managementAI exploits known vulnerabilities before organizations can patch them.Adaptive access controls: Enforce step-up MFA or block access to vulnerable systems, reducing exposure while remediation is underway.
Area 3: MonitoringCredential-based attacks span dozens of authentication paths simultaneously, overwhelming traditional monitoring.Identity Threat Detection and Response (ITDR): Behavioral baselining, real-time identity anomaly detection, and identity risk signals integrated with SIEM/SOAR platforms.
Area 4: GovernanceAI expands the identity attack surface faster than organizations can inventory, assess, and govern it, leaving boards without accurate visibility into identity risk.Identity Security Posture Management: Continuously measures identity risk, providing visibility into privileged accounts, orphaned service accounts, control gaps, and high-risk exposures, with prioritized remediation guidance.
Area 5: Defense-in-depth & zero trustAI chains legitimate identities, service accounts, and trust relationships at machine speed.Runtime Access Protection (RAP): Evaluates every authentication and enforces security controls inline with the authentication flow - allowing, blocking, or stepping up authentication before access is granted: Adaptive MFA, Just-in-Time (JIT) access, and risk-based policies, service account virtual fencing, Identity Segmentation
Area 6: ResilienceAI-powered attacks complete lateral movement and privilege escalation before responders can react.Inline Incident Containment: Instantly isolate compromised identities, enforce emergency access policies, and contain attack paths within seconds.

The next step

Discover how to stop AI-powered attacks

Get the complete readiness guide for identity and security teams.

Mythos-eBook_600px

FAQs

What does the ECB require European banks to do on AI cyber threats?
The ECB asked the significant euro-area banks it directly supervises to submit a comprehensive AI cyber-threat action plan by October 31, 2026, covering both immediate and longer-term resilience measures.

Emerging frontier AI models can discover vulnerabilities and generate working exploits at unprecedented speed. But they don’t necessarily rely on novel techniques – they identify and chain together existing weaknesses and risks, exploit legitimate identities, misconfigurations, excessive permissions, and trust relationships to move laterally across the environment and escalate privileges till they achieve their goal. As AI compresses the time between initial access and business impact, the window for detection and response becomes too small, making traditional reactive defenses increasingly ineffective.

Learn more about frontier AI readiness.

The ECB explicitly stated that responsibility for responding to the evolving cyber-risk environment, and specifically AI-powered attacks, primarily lies with banks’ management bodies, making this an executive governance and resilience issue, not only a technical security matter.

Identity is the control plane for AI-powered attacks. Rather than relying on new exploits, AI attackers chain together legitimate identities, excessive privileges, and trust relationships to move laterally at machine speed. Runtime identity controls enforced inline, before authentication completes, can stop credential abuse before access is granted, preventing attacks from spreading and reducing business impact. Learn more in The Mythos Field Report.