10th Americas Deposit Insurance Forum: Enhancing Deposit Insurance Coverage and Reimbursement: Adapting to Digital Innovation, Emerging Risks, and Operational Challenges

You are here:

Deposit insurance and operational disruption in the digital era


Remarks by Eva Hupkes, Secretary General, International Association of Deposit Insurers 

Day 2 – San Jose, 10 September 2026


Good morning,

It is a great pleasure to address this Forum on its 10th anniversary, and I thank our hosts for bringing us together in San José.

Our Chair opened this Forum with reflections on what digital innovation asks of deposit insurers and how it is changing the deposit-taking business. I will pick up that thread from a different angle: how it is changing the operational risk environment in which deposit insurers, and the institutions we protect, operate.

Cyberattacks on the financial sector have become more frequent and more sophisticated than ever before. In most financial sectors, institutions depend on a small number of technology providers. A single operational failure can therefore disrupt many institutions at once. The next test of deposit insurance may not be the type of bank failure we have known in the past.

Where does the responsibility of the deposit insurer begin and end? And what, if any, role should it play in addressing cyber and operational disruptions, which may or may not result in institutional failure? These are the key questions I will pose to my panel later this afternoon. Allow me to use these remarks to provide some context for our discussion.

The Realities of Cyber Threats

This region has already experienced the kind of challenges I am describing.

Last year, attackers successfully breached C&M Software, a critical technology provider that connects banks and financial technology firms to Brazil’s central bank. They did not break the payment system’s cryptography. Instead, they purchased an employee’s login credentials and used valid institutional certificates to inject fraudulent instructions into the instant payment system. Within just a few hours, approximately 800 million reais, which is the equivalent to about 140 million USD, were drained from the reserve accounts of six institutions.

The central bank acted swiftly by suspending the provider’s connections. However, as a consequence, hundreds of institutions temporarily lost access to Pix, Brazil’s instant payment system. Fortunately, not a single customer deposit was affected.

This is not an isolated case. In 2023, Colombia experienced a ransomware attack on a single technology provider, which disrupted dozens of public entities and hundreds of companies all at once. In 2022, Costa Rica had to declare a national emergency after a cyberattack targeted government entities. The government refused to pay the ransom and instead collaborated with international partners to rebuild its cyber defenses.

You may also recall the CrowdStrike incident in July 2024. A faulty update to a widely used security product disabled millions of computers running Microsoft Windows across the globe in a single morning. While most institutions recovered within days, some required a week to resume normal operations. No institution failed, and no customer deposits were lost. This incident exposed a critical vulnerability: the concentration risk at the core of our digital financial system.

A recent study by two Federal Reserve economists, published in the Journal of Finance in December 2025, examined a real-world multi-day cyberattack that forced a technology service provider offline. The study relied on confidential supervisory and payment system data and did not name the provider. However, it revealed that the provider processed payments for a large number of banks. The effects rippled throughout the system. Banks that were never directly attacked were unable to send payments, while banks expecting those payments were left short. The smaller institutions among them were forced to borrow from the central bank to manage the situation.

These examples highlight a clear and growing reality. Our systems are deeply interconnected, and disruptions can cascade through the financial ecosystem in ways that are both immediate and far-reaching.

The response of the international community

These risks are set to intensify, and the international community is responding.

Just last month, the Chair of the Financial Stability Board, Andrew Bailey, issued a warning in his letter to the G20 finance ministers and central bank governors. He cautioned that the most advanced artificial intelligence systems are becoming increasingly autonomous and capable, with their most immediate implication for the financial system being cyber risk. He urged authorities and firms to prepare for severe scenarios in which many institutions, or a single shared provider, are disrupted simultaneously.

The General Manager of the Bank for International Settlements, speaking at the Jackson Hole symposium, emphasized the importance of high operational resilience and robust cybersecurity in building the future monetary and financial system. He also warned that “round-the-clock operability could quicken deposit outflows and might require additional backstops.”

Depositors, understandably, perceive an operational incident as a signal about the safety of their money. In a world where instant payments and social media dominate, the question “Is my money safe?” arises within minutes of hearing that a banking app is down.

The international regulatory community has also taken action. In December 2025, the Basel Committee issued its principles for the management of third-party risk in banking, providing a framework for mitigating vulnerabilities arising from external dependencies.

Our own standard is also evolving to address these challenges. The recently updated IADI Core Principles, specifically Principle 11, call on deposit insurers to maintain effective contingency planning and crisis management arrangements. This ensures that they are equipped to respond to both the potential and actual failure of an insured deposit-taking institution.

Building Preparedness: The Four Essential Pillars

What does this mean in practice? Preparedness rests on four essential building blocks, which have been the focus of this Forum yesterday and today. Each of these must be constructed in advance, in close collaboration with other financial safety-net participants and, increasingly, with the technology firms upon which the entire financial sector now depends.

The first building block is exercising. Joint simulations are critical and must reflect what the Basel Committee and the Financial Stability Board describe as severe but plausible scenarios. In today’s digital era, these scenarios include an outage at a provider serving multiple institutions, a fast-moving cyberattack affecting several entities simultaneously, an incident at the deposit insurer’s own payout platform, or even a false rumour about a solvent bank, amplified by fabricated material and spread rapidly.

The second is data. Deposit insurers must have access to depositor records at all times, in a format they prescribe, and these records must be tested before a failure occurs. This is especially important for accounts that are pooled or intermediated, where it is critical to identify who actually owns the money.

The third building block is payment capability. Paying depositors quickly through the instant payment systems that this region has developed requires pre-established arrangements with the operators of those systems, as well as with the central bank and the supervisor. Technology can play a transformative role here. Automation can streamline processes, and artificial intelligence can help validate data and screen for fraud. However, it is essential that every automated decision is recorded and that a person remains accountable for handling exceptions.

The fourth and final building block is the fund itself. The fund’s strength depends on its robustness, its diversification, its management of currency risk -particularly where guarantees cover foreign currency deposits – and its ability to call for contributions quickly when it needs to be replenished. Later today, we will delve deeper into this topic during the panel discussion on investment strategies.

One overarching requirement ties all four building blocks together: the operational resilience of the deposit insurer itself. The updated IADI Core Principles treat this as a standalone requirement. Specifically, the new Core Principle 4 on business continuity expects deposit insurers to have a framework in place to withstand, adapt to, and recover from severe operational disruptions.

The boundary question

Deposit insurer mandates are traditionally triggered by failure. Deposit insurance was designed for scenarios where funds are at risk. But what happens when access to funds is lost, even though the money itself remains safe? The public will still demand reassurance. When access fails, silence invites speculation, and someone must step in to provide clarity first.

That someone, however, is not necessarily the deposit insurer. Communication during an operational crisis is a shared responsibility of the financial safety net as a whole. Yet we must be realistic about one important fact: among all safety-net participants, the deposit insurer is often the most visible and the most trusted by depositors. Naturally, depositors may turn to the deposit insurer first  whether or not it is formally in charge of the situation.

This is precisely why roles and responsibilities must be clearly defined in advance. The supervisor, the central bank, the finance ministry, and the deposit insurer must coordinate to agree on who communicates what, ensuring the public receives clear and consistent information about what has happened and what is being done to address it.

The more challenging question arises when the loss of access is prolonged. Should the deposit insurer step in and advance funds to depositors, even though no institution has failed? I will pose this question to the panel, and I will be equally candid about the complexities it entails. Advancing funds without a failure would fundamentally change the purpose of the deposit insurance fund. It could dilute the incentives for institutions and their technology providers to strengthen their own resilience. Moreover, it would extend beyond the mandate that most deposit insurers currently operate under.

There is undoubtedly a role for the financial safety net in such situations, but it is not necessarily the deposit insurer’s role, nor should its fund necessarily be the one to act. What is essential is that each jurisdiction defines the deposit insurer’s role including its role in communication  in advance and in close collaboration with all other safety-net participants.

This coordination lies at the heart of the 2025 revision of the IADI Core Principles. It is vital that the boundaries of the deposit insurer’s role are explained clearly to the public well before those boundaries are tested in practice.

The revised Core Principles – a standard crafted for a fast-evolving environment

The revised Core Principles, issued last September, provide us with a robust framework. They establish common expectations for crisis preparedness, operational resilience, and safety-net coordination, while allowing flexibility for differences in legal mandates, institutional arrangements, and market structures. These principles are deliberately high-level and that is by design. A standard crafted for a fast-evolving environment must remain adaptable, capable of accommodating change without requiring constant revision.

Next week in Washington, we will review the accompanying Assessment Handbook. This tool will support our members in applying the Core Principles, whether through self-assessments, peer support, or financial sector assessments conducted by the IMF or the World Bank.

Trust in the financial system is now tested in new and unprecedented ways our systems never anticipated. But the foundation of trust remains unchanged. It is built over years of preparation. Deposit insurers play a vital role in that work.For the past ten years, the deposit insurers of the Americas have come together at this Forum to engage with one another and to learn from each other’s experiences. Depositors may never see the years of preparation that go into safeguarding their confidence. What they will see, however, is whether the promise held when it mattered most.

I look forward to another day of meaningful and lively engagement. Thank you for listening, thank you for being here — and, once again, my heartfelt thanks to our gracious hosts.

References

  • Bailey, A (2026): Letter from the FSB Chair to G20 Finance Ministers and Central Bank Governors, 28 August.
  • Banco Central do Brasil statements and press reporting (2025): June 2025 incident at C&M Software
  • Basel Committee on Banking Supervision (2025): Principles for the sound management of third-party risk in the banking sector, 10 December;
  • Hernández de Cos, P (2026): “Pushing the monetary frontier: stablecoins and tokenised deposits”, remarks at the Jackson Hole Economic Symposium, 28 August.
  • Duke University, Digi Americas Alliance, Latam CISO Network (2024) Cyber Readiness in Latin American Public Sectors: Lessons from the Frontline 
  • International Monetary Fund (2026): “Financial Stability Risks Mount as Artificial Intelligence Fuels Cyberattacks”, IMF Blog, 7 May;
  • Kotidis, A and S L Schreft (2025): “The Propagation of Cyberattacks through the Financial System: Evidence from an Actual Event”, Journal of Finance, December.

 

Share this post
LinkedIn
Email this