Malta’s Financial Sector at a Digital Crossroads: Insights from the MFSA’s 2024 Dear CEO Letter

In September 2025, the Malta Financial Services Authority (“MFSA”) issued its Dear CEO Letter on Supervisory Engagements and Digital Operational Resilience 2024. This letter deserves careful attention as it captures not only the MFSA’s supervisory experience over the past year but also its growing expectations as Malta’s financial sector braces for the full application of the Digital Operational Resilience Act (“DORA”).

From the regulator’s perspective, digital resilience has become a matter of governance, accountability and strategic foresight and is no longer a technical concept reserved for IT teams. The letter is a timely reminder that operational resilience is a legal obligation, not a best-practice aspiration.

The MFSA’s Supervisory ICT Risk and Cybersecurity (“SIRC”) function led the 2024 supervisory agenda with a comprehensive Supervisory Engagement Plan that combined several supervisory tools to assess licence holders’ preparedness in digital operational resilience. The SIRC adopted both the risk-based approach and outcomes-based supervision, in line with the MFSA’s 2024 Supervision Priorities. This dual framework ensured that engagements were not only proportionate to each entity’s risk profile but also measured the real-word effectiveness of controls over time.

A Shift Towards Outcomes-Based Supervision

Perhaps the most striking development highlighted by the MFSA is its increasing reliance on Outcomes-Based Supervision. This model introduces a three-year supervisory cycle during which the same set of controls is evaluated and re-evaluated to measure sustained compliance over time. Following the initial engagement, firms are granted a 12-month window to implement remediation measures before the MFSA revisits to assess progress.

Although only 13% of supervisory engagements in 2024 were conducted under this new framework, the results were telling. Firms subject to outcomes-based reviews showed stronger overall control effectiveness than those assessed under traditional methods. The message is clear: the MFSA is moving away from episodic inspections towards continuous accountability. For licence-holders, this requires a shift in mindset as compliance is not a one-off exercise but an enduring state of readiness. From a legal standpoint, this demands thorough documentation, demonstrable board oversight, and consistent implementation of approved controls throughout the supervision cycle.

The MFSA’s findings paint a picture of cautious optimism. Across all assessed entities, approximately 61% of controls were fully met, 28% were partially achieved, and 9% were not met. These figures suggest that Malta’s regulated sector is moving in the right direction, yet significant gaps remain.

For many firms, the challenge lies not in awareness but in execution. Policies exist, frameworks are drafted, and committees are established, yet practical implementation often lags behind. This gap between “paper compliance” and real-world resilience is precisely where legal, risk, and compliance teams must now focus their efforts.

The DORA Lens: Key Areas of Weakness

Under the chapter on ICT Risk Management, the Authority observed that many licence holders still lack an integrated approach to identifying and managing ICT risks. These are too often treated as isolated technical concerns rather than core elements of enterprise risk management. Change management processes are inconsistently applied, and third-party risk registers are incomplete or outdated.

For legal advisors, this area poses one of the most tangible risks. DORA imposes clear obligations on financial entities to ensure robust governance, board oversight, and contractual safeguards in their ICT arrangements. Firms must ensure that their policies are not only comprehensive but actively embedded in operations. Contracts with service providers should contain mandatory audit rights, sub-outsourcing restrictions, and continuity clauses, terms that are still missing from too many agreements across the industry.

Incident management and reporting represent another area of concern. The MFSA noted weaknesses in how firms classify, escalate, and report operational disruptions. Some entities lack formal playbooks or clear escalation hierarchies, leading to delays in notifying internal stakeholders and external authorities. Under DORA, such shortcomings can have serious regulatory consequences. Legal teams should take a leading role in defining what constitutes a “major incident,” setting notification timelines, and ensuring that contractual arrangements with third-party ICT providers include explicit cooperation and notification obligations.

The chapter on digital operational resilience testing revealed that many licence-holders remain in the early stages of developing structured testing programmes. Few have implemented advanced testing such as threat-led penetration tests, and even fewer maintain detailed documentation of their results. The MFSA also observed that internal audit functions often lack the technical expertise to assess ICT resilience effectively. From a governance perspective, this underlines the need to invest in both technical capacity and cross-functional collaboration thus bringing together IT, compliance, and legal teams to validate testing frameworks and follow through on remediation measures.

Finally, the Authority highlighted ongoing deficiencies in third-party risk management. Although most firms have begun compiling outsourcing registers and aligning their contracts with DORA requirements, the level of completeness and quality varies significantly. Many contracts still lack clauses covering exit strategies, audit rights, or sub-outsourcing controls, leaving entities exposed if a service provider fails or withdraws. Given that licence-holders remain fully accountable for outsourced activities, this area arguably represents the highest legal exposure under DORA.

From Compliance Burden to Strategic Opportunity

What emerges from the MFSA’s letter is a clear regulatory philosophy: resilience must be built into the fabric of every financial entity. DORA compliance cannot be delegated to IT or compliance teams alone; it requires engagement at board level and across all control functions.

For lawyers and corporate service providers advising regulated entities, the practical roadmap is becoming clearer. Start by embedding outcomes-based supervision readiness, maintain comprehensive documentation, ensure continuous effectiveness of controls, and treat remediation as an ongoing obligation. Strengthen ICT risk governance by aligning it with enterprise-wide risk management and ensuring that boards are directly accountable for ICT oversight. Develop robust incident response frameworks with legally sound escalation and reporting mechanisms. Implement structured resilience testing programmes supported by detailed documentation and contractual clarity with testing providers. And finally, revisit every outsourcing agreement to ensure DORA-compliant clauses are in place and enforceable.

 A Forward-Looking Perspective

The MFSA’s 2024 Dear CEO Letter marks a pivotal moment in Malta’s regulatory journey. The Authority is not merely measuring compliance, but it is steering the sector towards a culture of continuous operational resilience. The good news is that most firms are moving in the right direction. The less comfortable truth is that many still have much to do before achieving true digital maturity.

For the financial sector, digital resilience is fast becoming as critical as capital adequacy or solvency. For lawyers, this presents both a challenge and an opportunity to guide clients through the intersection of law, technology, and governance with precision and foresight. Those who treat DORA not as another regulatory burden but as a framework for long-term strength will emerge as the sector’s most trusted and future-ready institutions.