Tuesday, 01 September 2026 PDT | 03:18 PM
The 1 News Alt Logo Text Smart News for Global Indians

The next cyber crisis is already taking shape

AI News September 02, 2026 03:00 AM
The next cyber crisis is already taking shape

Meta description: AI is reshaping the economics of cyberattacks just as banks begin rebuilding the systems that underpin digital trust. Authors: Shweta Jain, Managing Client Partner, Head of Promontory, IBM Consulting; Stephen Coraggio, Senior Partner, Cybersecurity Services, IBM Consulting Imagine every bank robber in the world suddenly gaining access to a team of expert locksmiths. They can inspect millions of vaults simultaneously, identify weak locks and map the quickest route inside. This analogy is not exactly what is happening in banking, but it’s close. For decades, advanced cyber capabilities have remained concentrated among nation-state threat actors and sophisticated financially motivated cybercriminals. Frontier AI models are beginning to change that equation, making powerful cyber capabilities more accessible and easier to deploy. At the same time, banks are undertaking a massive overhaul of the cryptographic systems that secure everything from digital payments and customer accounts to identity verification. Known as post-quantum cryptography (PQC), the effort aims to protect today’s financial infrastructure against advances in computing that can render current encryption obsolete. The convergence of these trends comes at a critical time. Financial institutions are undertaking a generational upgrade of the security infrastructure underpinning the digital economy. Meanwhile, attackers are gaining access to increasingly powerful cyber capabilities. The result is a growing imbalance that can shape the next cyber crisis.

When the locks change and the lockpicks improve

Advanced cyber operations have long required significant expertise, infrastructure and investment. Many attackers can purchase tools or obtain access through cybercrime marketplaces. However, only a relatively small group of highly capable actors can discover new vulnerabilities, develop exploits and operate at scale.

Recent advances in frontier AI are quickly eroding those barriers. Used responsibly, these tools strengthen cybersecurity defenses. In banking, they help security teams identify potential weaknesses and respond to threats more quickly.

However, these capabilities are becoming widely accessible. As a result, attackers can use these same capabilities offensively to develop exploits and accelerate cyber operations at a speed and scale that were previously out of reach. Early evidence indicates that the impact of AI-driven cyberattacks is already growing. Advanced AI systems are becoming increasingly capable of identifying software vulnerabilities, chaining exploits together and accelerating offensive cyber techniques. IBM’s Cost of a Data Breach Report 2026 found that AI-driven attacks increased 56% year over year and added an average of USD 1 million to the cost of a breach. Financial services experienced some of the highest breach costs of any industry, averaging USD 6.29 million per incident.

The trend is becoming visible in other ways as well. Google’s Threat Intelligence Group reported what it believes to be the first observed case of a threat actor employing AI to help develop a zero-day exploit. The exploit targeted a vulnerability that was unknown to defenders and had no available patch.

These events are significant beyond a single isolated incident. Banking leaders should expect a future in which advanced attacks become faster, more scalable and increasingly difficult to predict.

Banks’ earlier security playbook no longer applies

The use of frontier AI by threat actors is significant on its own. The transition to post-quantum cryptography is a major shift in its own right. Together they create a more complex problem.

Modern banking runs on cryptography. It secures customer information, protects transactions, verifies identities, enables digital channels and underpins the trust that allows billions of financial interactions to take place every day. Customers rarely see it. Yet every customer depends on it.

Post-quantum cryptography represents the next evolution of that foundation. Its purpose is straightforward: to ensure that the systems securing financial institutions remain resilient against future technological advances that can weaken today’s encryption standards. The need for PQC is easy to understand. The complexity lies in the scale of the transition itself.

Large banks operate thousands of applications, databases, interfaces, APIs and vendor relationships. Over decades, cryptographic dependencies have become deeply embedded throughout those environments. Identifying them, understanding the risks they create and executing a migration strategy often demands years of planning and coordination.

Y2K is a useful comparison. Often remembered as a crisis that did not happen, Y2K was in fact a crisis that organizations spent years preventing. Banks, governments and businesses identified a systemic vulnerability buried deep within critical infrastructure and invested heavily to address it before it disrupted operations. The post-quantum transition shares many of those characteristics.

Y2K arrived with a fixed deadline. Every boardroom knew exactly when the clock would strike midnight. Every institution worked toward the same immovable date. But post-quantum cryptography offers no such universally recognized deadline.

Unlike Y2K, there won’t be a single moment when everything breaks all at once. Quantum risks will materialize over several years as different cryptographic systems become vulnerable at different times. As a result, the absence of urgency can prove to be the greatest challenge of all and can lead to unnecessary cost and business disruption.

Without a fixed deadline, institutions risk delaying action, leaving critical systems exposed for longer and increasing the cost and complexity of a transition.

Redefining resilience from IT recovery to managed degradation

This convergence forces a fundamental shift in how financial institutions define enterprise risk. Traditional frameworks treat resilience as an IT recovery exercise, aimed at restoring systems to a pre-breach state based on static recovery time objectives (RTOs). But when AI accelerates exploit velocity and post-quantum migration disrupts core cryptographic dependencies, static recovery targets fall apart. True enterprise resiliency is an executive capability for managed degradation. It requires boards and risk officers to establish the governance needed to consciously shed non-essential digital services while defending core clearing, settlement and liquidity mechanisms under active, sustained compromise. Ultimately, resilience is not system uptime. It is balance-sheet and trust preservation when failure is already occurring.

Preparing before the clock runs out

Replacing those cryptographic foundations involves far more than deploying a new application or upgrading a piece of hardware. It requires reengineering cryptographic systems embedded across decades of applications, networks, vendor relationships and business processes.

The scale of that challenge is easy to underestimate. According to the IBM Institute for Business Value’s 2026 Tech Leader Study, 82% of banking and financial markets technology leaders say that they are not fully prepared for the scale of change ahead. AI is expected to drive that change over the next year.

As awareness grows, so too do the efforts to close the gap. In May, IBM® and Red Hat® announced Lightwell, a USD 5 billion commitment and a global force of more than 20,000 engineers dedicated to securing open source software. Several major global banks have already signed on as early adopters as attackers use AI to accelerate the discovery of vulnerabilities.

The sobering reality is that banks still face a year-long transition. And because time is one resource no institution can buy back once it has been lost, the organizations that wait for certainty will find they have waited too long.

Lead Partner, Financial Services and Insurance

IBM Promontory Risk and Compliance

The global average cost of a data breach reached USD 4.99M while AI-driven attacks increased 56%. Explore the latest findings.