video thumbnail

Fintech agility and AI-Powered Cyberthreats

In less than 3 minutes, Daniela Sozzi answers key questions on the fintech’s ability to prevent and respond to AI-powered cyberthreats. Given their agile and digitally-native infrastructure, the experience of the fintechs can be “exported” to more traditional financial services organisations, that tend to be more hierarchical and slow to respond to attacks.
It is also an opportunity to revise traditional processes, operational structures and headcount, where more emphasis should go towards distributed decision making, empowerment and upskilling to respond to AI-driven cyberattacks.

0:00 – 0:59: New AI-based cyberthreats – an opportunity or a threat for fintech companies?

1:00 – 2:06: Processes and operating models need to shift from reactive to proactive.

2:07 – 2:48: Why traditional financial institutions can learn cyber resilience from fintech companies

A brief transcript of what was discussed

Bruno: Daniela, based on your your fintech experience: from your point of view, does the fintech ecosystem see what is happening as a threat, an opportunity, or both?

Daniela: It is a bit of both, and I will focus particularly on European fintech, which is where I am closest to the market.

From a cybersecurity perspective, there is an opportunity, because the largest fintechs in Europe are often perceived as more agile and potentially more resilient to cyberattacks. I stress that this is still a perception. The real test would come if an incident actually occurred. But at the moment, this is definitely seen as an opportunity to win market share from incumbents and more traditional players.

At the same time, it is also a threat, because fintechs do not operate in a silo or in a parallel world. They are interconnected. In many cases, they resell services or asset management products produced by traditional financial players. Because they are part of the same ecosystem, an attack on the ecosystem is also a threat to fintechs. And they know that. That is why this is both a threat and an opportunity, and why it is fully reflected in their risk assessments.

Bruno: Thank you. The key point is velocity. So if we look at financial institutions, what are the main operational impacts of these new models? Daniela, what is your view?

Daniela: The first issue is really processes.

We are seeing a shift from being reactive — waiting for an incident to happen and then asking what to do next — to focusing much more on prevention. That includes the separation of decision-making from automated solutions so that attacks can be prevented and responded to as fast as they unfold.

This changes operations as well. I would borrow a concept from military strategy here. What do you do if your opponent no longer follows the code of war or the usual rules of engagement? You have to adapt your strategy.

If it becomes a guerrilla-style environment, you cannot simply deploy your battalion and rely on numbers anymore. You need to be more agile and more responsive, and operations need to be designed accordingly.

That requires a lot of training. It is not something that can be improvised. It is not something you can wait to learn after an incident happens. It has to be prepared in advance.

Historically, operations in financial services have often been more hands-oriented than brains-oriented, with people waiting for instructions from the top or following checklists. That will not work in today’s environment. There has to be a shift. This also affects headcount. It is no longer just about numbers. It is about the quality of the people available when an incident occurs, and all hands need to be ready. Those people need a skill set that is different from the past — one that fits the present and the future. Empowerment follows from that. There is no time to wait for instructions, and no time to wait for a traditional analysis process.

So processes, operations, and headcount all need to be adapted. Some people may assume that this means fewer people, but that is not the point. It is not about reducing headcount. It is about having the right skill set available at the right time.

Bruno: We discussed earlier that fintechs can see what is happening as both a threat and an opportunity. Do you also see them as being able to adapt more quickly than traditional institutions? What is your view, Daniela?

Daniela: Yes, I do.

If we think about how fintechs were designed from the start, many of them were built on cloud infrastructure while everyone else was still operating on-premise. From the beginning, they had to deal with being more exposed to vulnerabilities while also guaranteeing uptime — 99.999 percent in some cases.

So they built redundancy into their infrastructure, with backups and always-on solutions. They also built their organizations in a very agile way, usually with flatter structures where the lines between operational capability and IT capability were blurred.

That created cross-functional expertise at all levels and across all functions, which gave them a degree of resilience that is probably different from traditional players. I would not say higher in every case, but definitely different.

Traditional institutions often have stronger silos and thicker walls between IT and operations, and that is frequently what slows down their response when an incident occurs.

This is where experience and expertise can be shared. I believe traditional institutions can learn a great deal from fintechs.

At the same time, the divide between fintechs and traditional players is not as strong or as clear as it used to be, because many traditional players have gone through several waves of digital transformation. But more can still be done in that direction, and there is a lot to learn from both sides. That is probably the best way forward for responding to these threats.

more insights about AI and Cyber Resilience

This post: https://www.dnyc.uk/dora-ai-cyber-resilience-webinar/

Scroll to Top