The risk landscape in financial services is more perilous than ever. In addition to rising cybercrime in general, “state-sponsored cyberattacks targeting financial institutions are becoming more frequent, sophisticated and destructive,” the Carnegie Endowment for International Peace reports.
To understand the evolving risk and how institutions are responding, we convened a roundtable of industry insiders and experts. Participants included Rick Hill, vice president of industry technology for the Mortgage Bankers Association; Jeremy Koppen, CISO of Equifax, one of the nation’s largest credit bureaus; Brian Minick, chief technology and information security officer of Cincinnati-based Fifth Third Bank, America’s 18th-largest; and Brett Wait, CIO of Five Star Bank, a Warsaw, N.Y.-based regional institution.
Click the banner below to subscribe to our newsletter for the latest financial services IT insights.
BIZTECH: What are your most urgent security priorities right now?
Minick: All the things that are happening with these new frontier artificial intelligence models — Anthropic Mythos being the prime example of that — and their ability to find vulnerabilities, to exploit vulnerabilities very quickly. We are thinking through vulnerability management in terms of how we can handle an order of magnitude more vulnerabilities coming at us.
Wait: First and foremost, it’s combating fraud. We’ve seen an uptick in check fraud, which is consistent with the industry. We’ve seen the emergence of Fraud as a Service by threat actors, especially leveraging AI tools to create more carefully crafted, quality deepfakes.
Koppen: Interestingly, one of our top priorities right now is prioritization. It has to be, because threat actors are using AI to increase the speed and sophistication of attacks. We’re relentlessly reviewing and weighing risk variables from across our environment to ensure we focus on the highest-risk threats.
Hill: The biggest threat today continues to be ransomware and data extortion. There’s also a focus on identity as an evolving method to protect yourself. Historically, you might validate someone’s identity as they entered a network, and then you trusted them across the network. Now you don’t trust the identity unless it is validated everywhere it goes.
BIZTECH: What types of solutions and technologies are helping to support those priorities?
Hill: Identity-centric security is an evolving thing. The other piece is continuous monitoring: What is everybody doing inside of my network? Also, backup and recovery are being done a little differently, so that if a bad actor gets in, you have another way to more rapidly come back up again.
Koppen: We’ve custom-built (and are continually refining) a centralized risk engine that aggregates data across our entire security stack. We’re feeding it everything from specific system configuration data, vulnerability scans and application tests to red team findings and internal audit results. For speed, we have a strong set of custom AI capabilities that wrap around our commercial tools to make them work together more effectively.
Minick: In terms of helping our customers protect themselves, we recently added to Fifth Third’s mobile app the ability for customers to upload screenshots of text messages, emails, things like that, that they have received. They can ask us if it’s legit, and our security team looks at it and gives them an assessment.
Wait: Overall, it’s a layered security approach, with tools at the perimeter layer, at the endpoint layer, at the identity and provisioning layers — making sure users have a minimum level of access required to do their jobs and not more permission than needed.
BIZTECH: What kinds of things are worrying you, as leaders of financial institutions, that probably don’t worry other industries as much?
Wait: As tech infrastructure has continued migrating to the public cloud, we’ve seen several massive outages in the past year or so that have impacted some financial institutions’ critical systems or those that customers transact with. In these situations, the financial institution has limited ability to mitigate on their own despite having business continuity and recovery plans.
Hill: In a cyber event, I still have customers whose loans are going to close tomorrow or next week, or they are trying to get an offer in. All of these things are important. You need to do certain things quickly, and people need to be able to trust what’s going on. And then you have a whole regulatory regime on top of all of that.
Koppen: We operate in a digital supply chain that’s an inherently attractive target. That shared risk across Equifax, our vendors and our customers is always top of mind. There’s also the reality that trust, including the security aspect, is a big differentiator in our space. It’s not enough for us to just meet the highest security standards behind closed doors. We need to transparently demonstrate that rigor to the market every single day.
Minick: Attackers understand that banks generally have good security hygiene. They don’t directly attack a bank, but they may attack the customer. In the financial sector, our security program doesn’t just stop at our borders or at the edge of our network. It extends to trying to protect our customers where they are and where they live.
BIZTECH: How is AI helping the bad actors?
Hill: Every tool that can be used for good can also be used for bad, and AI is no exception. I can do a phishing attack, but with AI, I can scale it really fast — I can scale up my phishing attack, my impersonation. There’s that ability to do more of it, against more potential victims.
Koppen: Attackers are using AI to comb through public data at a massive scale, then using what they find to craft extremely precise, believable phishing campaigns. They’re also using AI-driven bot swarms to test stolen credentials at speeds humans can’t match.
Minick: Cyber has always felt like an arms race. We would build a bigger wall, and they would build a bigger ladder, and you would go back and forth. The AI piece allows them to build that bigger ladder much more quickly. Now, my ability to change how I protect myself — at speed — becomes more important.
Wait: A couple of years ago, the talk in the industry was about Ransomware as a Service. Now, it has leapfrogged to Fraud as a Service. It’s a commodity that’s on the dark web: “Come buy this tool and use it to exploit a financial institution.” There’s also the ability to very easily create deepfakes of individuals to be used in new accounts.
BIZTECH: How is AI helping to defend against attackers?
Koppen: Three specific use cases stand out to me. First, to manage alert fatigue, we built an AI triage agent that’s helping auto-resolve nearly 50% of our security operations center tickets. Second, we built an engine that takes raw threat intelligence and instantly spins it into live attack simulations. This lets us proactively test our defenses against new tactics as soon as they emerge. Finally, we’re using an AI advisory assistant to instantly analyze new technical designs for our architects. It’s slashed our security consulting times by more than 60%, helping build security into our products from the beginning without slowing down innovation.
Hill: With continuous monitoring, there can be a lot of noise, all these alerts are going off: “Hey, look here, look here, look here.” AI can help you to decipher where the biggest priority is within all the noise. Where should I spend my time? What is more likely to be the biggest risk?
Minick: Our proprietary platform helps us detect and respond to attacks, and AI is a big piece of that. We are integrating it into those capabilities so we are able to detect more and respond more quickly to what we detect. As we go forward, thinking through that vulnerability side of things, we’re working on the ability to use AI to help us create patches and fix code.
Wait: The real level-up has been from machine learning to next-generation, predictive anti-fraud solution enablement. We are better chaining together the sequence of events leading up to a potential transaction and identifying it as potentially fraudulent. That allows us to rely on our human relationship to validate the legitimacy of a particular transaction.
Click the banner below to read the 2026 CDW Cybersecurity Research Report.
BIZTECH: What new risks are on the radar that weren't much of an issue a few years ago?
Minick: Quantum risk has been hanging out there for a long time, and there have been some advances within that space. It would change the ability for computers to break the current cryptographic standards, so we continue to keep an eye on that, ensuring that our encryption is safe and that we’re able to respond if something does happen within that space.
Hill: One is shadow AI. We are encouraging people to understand how AI can be used to make them more efficient, more effective. Your risk is that somebody creates something and starts to use it on transactions in some fashion, and the IT team may not know that it’s out there. They didn’t create it; they don’t know what it is and what it does. And if they’re unaware of it, they can’t govern it.
Koppen: Beyond the obvious AI risks, the nature of supply chain attacks is shifting. A few years ago, a top concern was software flaws in third-party tools. Now, attackers are stealing vendor credentials and riding those trusted connections right into the network. It’s increasing the identity security aspect of third-party risk.
Wait: It’s the unmanaged or undocumented use of artificial intelligence solutions that fall outside what we’ve evaluated and approved for use by staff. Other risks are related to the ability for frontier AI models to be able to daisy-chain vulnerabilities together to create new vulnerabilities. That’s a risk that was not on our bingo card even six months ago.