Contact us
Marketing 22 April 2026 Alta Signa Press Insights

The 2026 Cyber Risk Horizon: AI, Trust and the New Threat Landscape

By Ralfi Vaso, Underwriter, Alta Signa

For years, cyber risk in financial institutions was framed around a familiar set of concerns: ransomware, business interruption, data theft and the ever-present question of who might be next. Those concerns have not gone away. But in 2026, the character of the threat is changing.

It is becoming faster, more convincing and more difficult to spot early.

Artificial intelligence is a big reason why. What was once a numbers game built around mass phishing emails and blunt social engineering has become far more personalised. Fraudsters can now mimic tone of voice, generate convincing identity documents, build believable fake investment content and automate attacks across multiple languages at scale. European regulators are already warning that AI is being used to power online financial fraud and scams, while industry data points to a sharp rise in deepfake-led fraud attempts across the financial sector.

That matters enormously for banks, lenders, asset managers and other financial institutions because trust is the product as much as the balance sheet is. A successful cyber event does not need to take core systems offline to cause real damage. In many cases, the greater harm comes from manipulated payments, compromised onboarding, impersonated executives, poisoned communications and shaken customer confidence.

At the same time, the risk is expanding beyond the organisation itself. Increasing reliance on third-party technology providers - particularly cloud services - means vulnerabilities often sit within the wider ecosystem. Regulators, including the ECB, continue to highlight concentration risk as a key concern.

Encouragingly, frameworks like DORA are helping firms move beyond prevention toward true operational resilience, focusing on recovery, testing and dependency management. But the reality is clear: controls alone are not enough.

Financial institutions need to strengthen identity verification, introduce deliberate friction into high-risk processes and take a broader view of resilience that includes suppliers and partners. Just as importantly, the response to cyber risk must become more collaborative: spanning insurers, banks, brokers and technology providers.

That is where the conversation should be now. Not whether AI-driven cyber crime is coming for financial institutions. It already is. The real question is which firms are adapting quickly enough to stay credible, resilient and trusted when the next incident lands.

Read the full article in European Financial Review
Cookie preferences

We use our own and third-party cookies for statistical and analytical purposes to provide you with the best experience on our website.

More information can be found in our cookie policy
We care about your privacy

You can set your cookie preferences by accepting or refusing the various cookies described below.

Necessary

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

Required
Preferences

Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.

Statistics

Statistical cookies help website owners understand how visitors interact with websites by collecting and reporting information anonymously.

Marketing

Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.