All News

- Previous Post >>

AI Cyber Risk in Finance: The Ticking Clock

Over the past few months, we have written several times about how AI may affect cyber security. In our previous blog post Infinite Zero Day Machine, so what?, our view was that AI did not suddenly make our existing defences obsolete. In Patching Faster Than Your Shadow?, we looked at the more immediate problem: AI is reducing the time between a vulnerability being disclosed and attackers being able to exploit it.

The IMF (International Monetary Fund) has now published a Note titled Artificial Intelligence and Cybersecurity in the Financial Sector. It looks at the same issue from a financial stability perspective and raises an important question: what happens when faster vulnerability discovery meets a financial system built on shared technology?

The Attack Is Not Necessarily New

The IMF's main warning is not that AI will invent a completely new category of cyberattack. It is that AI can make existing attacks faster, cheaper, more frequent and easier to conduct at scale.
Attackers already scan internet-facing systems, analyse patches, steal credentials, exploit known vulnerabilities, move laterally and target suppliers.

AI does not need to replace the attacker (even if it increasingly can!)
It simply needs to help the attacker perform those activities more quickly, against more targets and with less specialist expertise.

This is why banks may need to revisit vulnerability-remediation timelines designed for a slower threat environment.

When One Bank's Problem Becomes Everyone's Problem

The most useful part of the IMF Note is its focus on shared infrastructure. Banks depend on cloud platforms, operating systems, identity services, open-source components, payment networks, telecommunications and a number of major technology providers.

These dependencies are often there for efficiency/cost reasons, but they also create correlated exposure. A vulnerability affecting one bank is a security incident, but the same vulnerability affecting many banks, payment providers or a critical market platform may become a financial stability issue.

The impact can then move beyond IT: Payments may be delayed, trading or settlement disrupted, customers may lose access to services and confidence may fall.
During a prolonged incident, operational disruption can also create liquidity, legal and regulatory consequences.

This connects with a point we made in a previous blog post: Cyber Resilience: From the Floor to the Board, technical response cannot be separated from business response.
Executives need to know which services can still operate, what systems can be trusted, who is affected and which decisions cannot wait.

The IMF applies that principle across the wider financial system.

The Fundamentals Still Matter

The IMF's recommendations are mostly familiar: reduce the attack surface, patch critical systems, strengthen identity and access controls, segment networks, restrict lateral movement, improve detection, oversee third parties and test recovery.

This does not make the recommendations unimportant, quite the opposite! AI does not invalidate these controls; it increases the cost of implementing them poorly.

The document also calls for greater use of AI in defence. This is reasonable because purely manual vulnerability management and incident response will struggle if the number and speed of discoveries increase. AI can help analyse advisories, identify affected assets, prioritise exposure, detect suspicious behaviour and support containment.

However, machine-speed defence also needs controls.

An automated system that blocks an identity, isolates thousands of endpoints or deploys an emergency patch may stop an attacker quickly, but it may also interrupt critical services quickly. High-impact defensive actions need limited permissions, validation, logging, rollback and human accountability. The objective should be safe and bounded automation, not maximum autonomy.

Third-Party Risk Needs a More Practical View

Many organisations still manage third-party risk as an individual vendor exercise: issue a questionnaire, review a certification, negotiate clauses and repeat next year.
That may provide useful information about the supplier, but it does not show what happens when several critical services depend on the same cloud provider, identity platform, library or control plane.

Nor does a contractual exit clause prove that an alternative is genuinely usable during a crisis.
Banks should know which important services share providers, which "fourth" parties sit behind them, whether recovery depends on the same infrastructure as production, and whether failover has actually been tested.

An untested exit plan remains an assumption rather than a resilience capability.
As a side note, what is your AI resilience exit plan? probably something to discuss in a blog post another time!

This Is Becoming a Current Supervisory Issue

The IMF Note is part of a broader regulatory shift. On 7 July 2026, the European Systemic Risk Board reported that its assessment of systemic cyber risk had moved from "elevated" to "severe". On the same day, the ECB (European Central Bank) wrote separately to the CEOs of ECB-supervised significant institutions , asking them to prepare action plans covering exposed assets, patch management, AI-enabled defence, third-party risk, infrastructure modernisation and recovery.
The ECB letter, and not the IMF Note, requires those institutions to submit their plans to their joint supervisory teams by 31 October 2026.

When will something similar happen in other continents/countries?

The Bank of England's July 2026 Financial Stability Report raises a similar concern: even when individual firms improve their defences, disruption can still spread through common software, suppliers and critical infrastructure.

For banks, a practical response should include:
  • Reviewing internet-facing assets and critical third-party connections.
  • Shortening decision and remediation timelines for the most exposed vulnerabilities.
  • Preparing compensating controls when immediate patching is unsafe or impossible.
  • Using segmentation, least privilege and strong identity controls to limit blast radius.
  • Testing recovery when a cloud, identity or security provider is unavailable or untrusted.
  • Exercising incidents with operations, treasury, legal, communications and executives, not only the SOC.
  • Governing AI-enabled defensive actions so that important changes are observable and reversible.
  • Securing the bank's own AI systems against data leakage, prompt injection and excessive agent permissions.

  • None of this requires a separate 200-page AI cyber programme. It requires banks to revisit the assumptions behind their existing cyber and operational resilience programmes.

    The Bottom Line

    As discussed previously in this blog post: Maybe AI won't kill us after all, AI may ultimately give defenders significant advantages in vulnerability discovery, monitoring and response but a balanced view remains important (aka: there is no silver bullet in cyber security!)

    The IMF Note does not tell us that everything has changed. It tells us that familiar weaknesses can now be discovered and exploited faster, and that shared technology can turn an individual incident into correlated disruption.

    The fundamentals have not changed, but the clock has. In the financial sector, the possible blast radius has changed as well.
    - Previous Post >>