Cyprus financial regulator CySEC published an operational guide Tuesday detailing how employees at supervised firms can report suspected violations of EU financial law directly to the watchdog. The manual follows Cyprus’s March 2026 legislation that criminalized suppressing whistleblower reports with penalties reaching three years imprisonment or thirty thousand euros. Current and former employees, board members, shareholders and trainees can now report twenty-two categories of misconduct including insider dealing, naked short selling, conflicts of interest and MiFID II suitability failures through phone, email, post or face-to-face meetings, anonymously or otherwise.
CySEC commits to acknowledging reports within seven days and providing updates within three months. However, the regulator explicitly states it cannot compensate or remedy any damage whistleblowers suffer from retaliation, which ranges from dismissal and blacklisting to social media attacks and forced psychiatric evaluations. While protection extends to relatives and colleagues, CySEC operates solely as a reporting channel without enforcement powers over workplace consequences.
FXnCO Insight
Cyprus-based brokers face heightened compliance scrutiny as employees gain direct regulatory access, but continued retaliation risks may limit reporting effectiveness despite criminal penalties.
Source: Finance Magnates