- Cyber
- 1st Sep 2026
- 1 min read
Cyber Security in Financial Services: $6.29M AI Risk
- Written by
In Short..
- Financial-services breach costs are climbing fast: IBM's 2026 report puts the sector average at $6.29M, up 13% on 2025, driven by detection, containment, notification, regulatory response and customer attrition costs.
- AI-driven attacks concentrate on financial services more than most sectors: 62% of AI-driven attacks targeted critical infrastructure, with financial services and energy carrying the highest concentration of that targeting.
- The sector's structural profile makes it an easier AI-driven target: dense customer identity data, transaction infrastructure, third-party ecosystems and long-retention regulatory obligations sit inside one operating perimeter.
- Most programmes have a connection gap, not a detection gap: cyber, compliance, third-party risk and audit evidence held in separate systems slows board reporting exactly when speed matters most.
The average cost of a data breach in financial services reached $6.29 million in 2026, up from $5.56 million the previous year, a 13% rise, according to the IBM Cost of a Data Breach Report 2026. That places the sector as the second most expensive industry IBM tracks this year, behind only healthcare ($6.64 million), and moving in the opposite direction: healthcare's average fell about 10% while financial services rose 13%. That figure alone earns a place on any board pack or risk committee agenda.
The number that should concern financial-services risk leaders more is this: IBM found that AI-driven attacks concentrated on critical-infrastructure sectors (62% combined), with financial services and energy organisations experiencing the highest concentration of that targeting. The breach-cost figure reflects what an incident costs after it happens. The targeting concentration signals where the pressure is building beforehand, and it calls for a different response.
Expert View
Matt Davies Chief Product Officer, SureCloud |
What our experts say about board reporting on AI-driven cyber risk
"When a board asks what our exposure looks like right now, most programmes can only promise to get back to them next week. That delay is an evidence problem, and it's fixable before an incident forces the question." |
The breach-cost figure is only part of the financial-services risk story
The $6.29 million average is well-evidenced. It reflects detection, containment, notification, regulatory response, reputational damage and long-term customer attrition costs, and it's risen 13% on the 2025 figure, evidence that the financial consequence of a breach in this sector is accelerating.
A single cost figure can't tell a risk leader where to direct attention or investment. It blends every breach type and attack vector into one number, leaving out the structural factors that made the organisation a target, and used on its own, it tends to drive reactive, fear-based spending in place of informed programme design.
The more useful signal: where AI-driven attacks concentrate
IBM's 2026 data shows that one in four malicious breaches were AI-enabled, a 56% increase on last year. AI-enabled breaches cost an average of $6 million, roughly $1 million more than the global breach average of $4.99 million. Those are the headline supporting statistics.
The more operationally useful finding is the targeting pattern underneath them. AI-driven attacks concentrated on critical-infrastructure sectors (62% combined), and that concentration wasn't evenly spread.
Financial services and energy carried the highest share within that group, at averages of $6.29 million and $5.2 million respectively.
That shifts the question from how much a breach would cost to what it is about the sector that makes it a sustained focus of AI-enabled attack activity. A breach-cost figure is a post-incident measure. A targeting concentration is a pre-incident signal, and risk leaders need both without collapsing one into the other.
Why AI-driven targeting raises the stakes for financial services
Financial services sits within the highest concentration of AI-driven targeting in IBM's dataset because the sector holds an unusually dense combination of high-value assets inside one operating environment. This interpretation is SureCloud's own, drawn from the publicly available evidence.
- Customer identity data: authentication credentials, payment information and behavioural profiles, at scale.
- Transaction infrastructure: connects directly to payment systems, clearing networks and central banking rails.
- Third-party ecosystems: technology providers, outsourced processing and data-sharing arrangements extend the attack surface well beyond the organisation's own perimeter.
- Regulatory data obligations: require sensitive records to be retained across long time horizons, widening the window of exposure.
AI-enabled attack methods suit environments with exactly this profile. Automated reconnaissance, credential stuffing at scale and adaptive phishing campaigns can exploit the breadth of the financial-services attack surface in ways earlier generations of attack tooling couldn't.
The interconnection risk
The sector's interconnection with wider economic systems means a significant breach at one institution rarely stays inside that institution's perimeter. Third-party dependencies, shared infrastructure and correspondent banking relationships create pathways a single incident can travel through.
Many UK financial-services organisations invest heavily in detection and response capability. Sector-level targeting concentration is a structural risk that sits alongside individual organisations' security posture, one that mature programmes reduce the probability and cost of, without removing the underlying exposure.
For financial-services risk and compliance leaders, that reality belongs in how risk appetite is set, how third-party exposure is assessed and how resilience scenarios are designed.
Why this belongs in board risk reporting
The concentration of AI-driven attacks on critical infrastructure is a risk-appetite question for the board just as much as a technical finding for the security operations team.
Most financial-services boards already receive some form of cyber risk reporting. The real test is whether that reporting gives the board what it needs to make informed decisions about risk tolerance, resilience investment and third-party exposure, or whether it shows security metrics that are hard to connect to business impact.
From security metrics to risk-appetite conversations
IBM's evidence changes the conversation a risk leader should be having at board level. "How quickly can we detect and contain a breach?" is still the right question, and it now sits alongside another: does the current risk appetite account for AI-driven attacks concentrating in this sector, and is the organisation scenario-planning for the incidents that concentration implies?
Answering that well means connecting workstreams that boards often see separately:
|
Workstream |
Board-level question |
|
Cyber risk |
What is our exposure to AI-enabled attack vectors, and how does it compare to our stated appetite? |
|
Third-party risk |
Which critical suppliers sit within the same targeting concentration, and how is their exposure monitored? |
|
Operational resilience |
Have we scenario-tested a systemic incident affecting multiple institutions at once? |
|
Compliance and regulatory |
How does our DORA compliance posture account for AI-driven threat evolution? |
DORA, now in enforcement, requires financial-services organisations to demonstrate ICT resilience and third-party risk oversight in a structured, evidenced way. That gives cyber risk data a natural anchor in board reporting, but the connection has to be built deliberately. Details of the Digital Operational Resilience Act's requirements are set out in the regulation itself.
For well-run security teams, the real risk is evidence that stays siloed, keeping the board from seeing the full picture even when the underlying programme is strong. A mature security programme operating in a sector with heightened AI-driven targeting concentration needs board reporting that reflects both the programme's capability and the sector's structural exposure.
Build a cross-domain view before the next incident tests it
The structural argument above points to a practical conclusion: cyber security in financial services works best as a connected discipline. Cyber, compliance, third-party risk, audit and privacy information need to stay linked continuously, well before pressure forces a reconciliation during an incident.
Many financial-services organisations face a genuine programme gap here. The data exists, the controls exist, the teams exist.
What's often missing is a unified view that lets risk leaders answer, in near real time, questions such as:
- Which critical third parties have cyber risk assessments that are current, and which have lapsed?
- Do control test results reflect the threat environment described in the latest risk appetite statement?
- Can the organisation produce board-ready evidence of its operational resilience posture within hours, not weeks?
Connecting the evidence before an incident forces it
SureCloud's view is that financial-services risk management needs cyber, compliance, third-party risk, audit and privacy evidence held in a single, connected programme.
Integrating those workstreams gives risk leaders two things a siloed approach can't. First, they can identify cross-domain exposure before an incident, rather than discovering it during one. Second, they can produce the board-ready evidence that regulators and stakeholders increasingly expect, without the manual effort that turns reporting into a lagging indicator.
SureCloud's platform supports this through unified risk data, continuous control monitoring and enterprise-wide evidence that connects across GRC domains. Gracie AI Agents with Personas and Skills, SureCloud's AI capability, includes Senior Agent Collaboration, a cross-domain capability that lets senior Personas convene across risk, compliance, third-party risk and audit when a question touches multiple domains at once. Every action stays recorded, observable and human-redirectable.
For financial-services compliance programmes, that connected approach also supports the AI governance obligations the FCA and PRA are increasingly setting out, including the PRA's SS1/23 model risk management principles, alongside DORA's ICT risk and third-party oversight requirements.
The goal is to strengthen the risk programme surrounding the security function, so it can surface, connect and communicate the evidence boards and regulators need to make informed decisions.
Turn the figure into a diagnostic question
IBM's $6.29 million figure works best as a prompt for a specific diagnostic exercise.
Financial-services organisations should use it to test one question honestly: if a significant AI-driven incident hit the sector tomorrow, could the organisation's cyber, risk, third-party and compliance evidence support fast, board-ready decisions within hours?
If the honest answer involves manually consolidating data from separate systems, chasing control owners for evidence, or producing a risk summary that reflects the position three months ago, the gap sits in the risk infrastructure surrounding the security programme.
The $6.29 million average is what an incident costs once it happens. The more valuable investment is making sure the cross-domain risk picture is clear, current and board-ready before one does.
Found this useful?
Choose SureCloud as a preferred source in Google and you will see more of our GRC guidance in Top Stories, AI Overviews and AI Mode. It takes one click and you can undo it at any time.
Give Your Board the Evidence Before They Ask For It
FAQ’s
What is the average cost of a data breach in financial services?
According to the IBM Cost of a Data Breach Report 2026, the average cost of a data breach in financial services reached $6.29 million in 2026, up from $5.56 million in 2025.
That figure covers detection, containment, notification, regulatory response and reputational costs, and it sits among the highest sector averages globally, reflecting both the value of financial data and the regulatory obligations that follow a breach.
Why are AI-driven attacks a growing risk for financial services?
IBM's 2026 data shows one in four malicious breaches were AI-enabled, up 56% year on year. IBM's July 2026 research also found that AI-driven attacks concentrated on critical-infrastructure sectors (62% combined), with financial services and energy carrying the highest concentration. Financial services is a dense target environment: customer identity data, transaction infrastructure, third-party ecosystems and long-retention regulatory data all sit inside the same operating perimeter, and automated reconnaissance and adaptive phishing are well-suited to exploiting that breadth.
What should financial-services boards report on after an AI-driven cyber incident?
Board reporting after an AI-driven incident should cover four areas: the nature and scope of the breach, including which systems and data were affected; the status of third-party exposure, including whether any suppliers were involved; the organisation's regulatory position, including notification obligations under DORA, UK GDPR and FCA requirements; and the resilience actions taken and planned. Boards should also be asking, before an incident, whether their reporting infrastructure can produce that picture quickly, since cyber, risk, compliance and third-party data held in separate systems will slow both the speed and accuracy of reporting during a live incident.
What does DORA require of UK and EU financial-services firms?
The Digital Operational Resilience Act requires in-scope EU financial entities to demonstrate ICT risk management, incident reporting, resilience testing and third-party oversight on an ongoing basis. It's been enforceable since 17 January 2025, and it gives boards a structured, evidenced basis for connecting cyber risk data to wider risk reporting.
How can financial-services organisations build a cross-domain risk view?
The most direct route is connecting cyber, compliance, third-party risk, audit and privacy evidence into a single programme. That's what lets risk leaders spot cross-domain exposure early and produce board-ready evidence within hours.
Platform +
Frameworks +
Products +
Industries +
Resources +
Company +
London Office
1 Sherwood Street, London, W1F 7BL, United Kingdom
US Headquarters
6010 W. Spring Creek Pkwy., Plano, TX 75024, United States of America
© SureCloud 2026. All rights reserved.