Cybersecurity has always been a race, but financial institutions have at least been able to rely on one crucial advantage: time. Fraud teams could investigate anomalies, security analysts could assess alerts, and banks could contain an attack before it moved too far through the organisation. That advantage is beginning to disappear. As AI gives attackers the ability to automate reconnaissance, generate convincing identities, adapt phishing campaigns, discover vulnerabilities and change tactics almost instantly, the interval between detecting suspicious activity and suffering real damage is shrinking dramatically. The next cybersecurity challenge for banks may therefore be less about whether they can identify an attack and more about whether their systems can respond quickly enough when human decision-making is simply too slow.
Attack Speed Is Becoming the New Risk
Banks have spent years strengthening cybersecurity through layered controls, monitoring platforms, identity management, endpoint protection and increasingly sophisticated security operations centres. Much of this architecture, however, still assumes that somewhere in the process there will be enough time for a human to interpret what is happening and decide what to do next.
AI changes that assumption. An attacker no longer needs to manually perform every stage of an intrusion or fraud campaign. Increasingly capable tools can automate information gathering, identify potential weaknesses, produce targeted communications and adjust approaches according to the response they encounter. What previously required multiple specialists and significant preparation can increasingly be compressed into automated workflows.
For banks, this changes the economics as much as the speed of cybercrime. Automation allows attackers to test more targets simultaneously and abandon unsuccessful approaches at relatively little cost. Even if the success rate of individual attempts remains low, the ability to launch and continuously refine attacks at scale creates a fundamentally different threat environment.
The consequence is a cybersecurity window that keeps getting narrower. A control that identifies suspicious behaviour within 30 minutes may appear effective today, but it becomes inadequate if an automated attack can exploit the opportunity within three.
The Human Approval Model Has a Speed Limit
Financial institutions have traditionally been cautious about allowing security systems to take autonomous action. There are good reasons for that. Automatically freezing accounts, terminating network connections, blocking employees or shutting down services can create serious operational and customer consequences when a system gets the decision wrong.
The problem is that requiring human approval for every significant defensive action creates a natural speed limit. Attackers increasingly have no equivalent constraint.
This creates an uncomfortable cybersecurity trade-off. Banks need stronger automation to respond at machine speed, while simultaneously needing governance mechanisms that prevent automated security systems from creating new operational risks. The answer is unlikely to be removing humans from cybersecurity. Instead, institutions will need to become much more precise about which decisions machines can make independently and which decisions still require human authority.
Low-risk defensive actions could increasingly happen automatically. Credentials displaying clear signs of compromise might be temporarily restricted, suspicious sessions could face additional authentication, abnormal payment activity could be slowed, and compromised endpoints could be isolated while investigations continue. Humans would remain responsible for higher-impact decisions, but they would operate within an environment where automated systems have already contained the immediate threat.
This is effectively the cybersecurity equivalent of putting friction back into digital banking. As Finnoex explored in Banks Have Spent Years Removing Friction. Now They May Need to Put Some Back, the relentless pursuit of seamless experiences can become problematic when friction itself serves an important security function. The difference in the emerging threat environment is that such friction may increasingly need to be introduced dynamically rather than permanently.
Identity Could Become the Most Contested Layer
The acceleration of cyber threats becomes particularly important when combined with advances in synthetic identity, voice cloning and generative AI. Banks have traditionally relied on combinations of credentials, devices, behavioural signals and customer interactions to establish whether someone is who they claim to be. Many of those signals are becoming easier to imitate.
A convincing phishing message no longer requires excellent language skills. A fraudulent customer interaction can potentially include highly personalised information collected from multiple sources. Voice and video that once provided additional confidence in remote interactions are becoming less reliable as standalone indicators of identity.
This does not mean existing authentication systems suddenly become useless. It means banks will increasingly need several independent signals before trusting an interaction. Device intelligence, behavioural patterns, transaction history, network information, biometric signals and contextual risk assessment will need to work together rather than operate as isolated security checks.
The objective will gradually shift from proving identity once to continuously evaluating trust throughout a digital session. A customer may authenticate successfully at login but encounter additional controls if their behaviour subsequently becomes inconsistent with established patterns.
That transition could ultimately make authentication less visible for legitimate customers while making it considerably harder for attackers to maintain a convincing identity throughout an entire transaction journey.
Cyber Defence Will Become an AI-versus-AI Contest
The logical response to machine-speed attacks is machine-speed defence. Banks are already applying AI across security operations to prioritise alerts, identify anomalies and reduce the enormous volume of information analysts must process. The next stage is likely to involve systems capable of taking increasingly sophisticated defensive actions themselves.
This is where cybersecurity begins moving beyond conventional automation. Instead of following predetermined rules, defensive systems could evaluate multiple signals, estimate the probability and potential impact of an attack, select an appropriate response and continuously reassess that decision as new information appears.
The strategic implications are significant. The institutions with the strongest cybersecurity capabilities may not necessarily be those generating the greatest number of alerts. They may be those capable of converting security intelligence into action fastest.
That idea connects directly with the broader shift explored in The Next Cybersecurity Arms Race Will Move at Machine Speed. Once attackers and defenders are both using AI to adapt their behaviour, cybersecurity becomes a continuous contest between systems that are observing and responding to one another. Human security teams remain essential, but their role moves further towards setting boundaries, investigating complex incidents and governing the machines operating inside those boundaries.
Banks Will Need to Rethink What “Real Time” Means
Banking has spent much of the past decade becoming real time. Payments move instantly, customers expect immediate account access, digital onboarding can happen within minutes and banking platforms increasingly connect through APIs to large ecosystems of external services.
Cybersecurity cannot remain asynchronous inside that environment.
If money can move in seconds while fraud investigations take hours, the imbalance becomes increasingly difficult to sustain. Faster payments and interconnected banking platforms do not inherently make financial institutions less secure, but they reduce the amount of time available to reverse mistakes or stop suspicious activity before value leaves the institution.
This becomes particularly important as banks increasingly operate as infrastructure rather than isolated destinations. As discussed in Your Bank Is Becoming an API. Customers May Never Know It, financial services are becoming embedded across platforms and digital journeys that banks do not fully control. Every additional connection potentially increases the number of signals that must be assessed and the speed at which security decisions must be made.
Cybersecurity architecture will therefore need to become part of transaction architecture rather than a separate monitoring layer sitting behind it. Risk assessment, authentication and behavioural analysis will increasingly need to happen during the transaction itself.
The Bigger Challenge Is Governance
Giving automated systems greater authority introduces another problem: who is responsible when the machine makes the wrong decision?
An overly aggressive security model could freeze legitimate payments, block customers during critical transactions or interrupt important banking services. A model that is too cautious could allow an attack to progress while waiting for sufficient certainty. Banks will have to determine acceptable thresholds between those outcomes.
That makes AI governance inseparable from cybersecurity strategy. Institutions will need clear rules governing what automated systems can do, the evidence required before particular actions are triggered, how decisions are logged and explained, and when humans must regain control.
Testing will also become more important. Banks cannot assume that defensive models will behave predictably against adversaries deliberately attempting to manipulate them. Security systems themselves will become targets, creating a requirement for continuous validation, adversarial testing and independent oversight.
The strongest cybersecurity architecture may consequently combine two seemingly contradictory characteristics: enormous automated speed at the operational level and extremely deliberate governance around the boundaries within which that automation operates.
What it means for the industry
- Detection will no longer be enough. Banks will increasingly be measured by how quickly they can contain and respond to threats after identifying them.
- Security automation will move closer to autonomous defence. More low-risk containment decisions are likely to happen without waiting for human approval.
- Identity verification will become continuous. Banks will rely increasingly on combinations of behavioural, device, contextual and transaction signals rather than individual authentication events.
- Real-time banking will require real-time security. Instant payments, APIs and embedded finance will make delayed cybersecurity responses increasingly difficult to tolerate.
- AI governance will become a core security discipline. Banks will need clearly defined boundaries determining what defensive systems can decide and when humans must intervene.
- Speed could become a competitive security advantage. The cybersecurity leaders may ultimately be the institutions capable of safely making defensive decisions at machine speed.

