The Next Cyber Crisis is Already Taking Shape

Security News
Typography
  • Smaller Small Medium Big Bigger
  • Default Helvetica Segoe Georgia Times

Imagine every bank robber in the world suddenly gaining access to a team of expert locksmiths. They can inspect millions of vaults simultaneously, identify weak locks and map the quickest route inside.

By Shweta Jain, Lead Partner, Financial Services and Insurance; IBM Promontory Risk and Compliance and Stephen Coraggio, Senior Partner, Cybersecurity Services, IBM Consulting

This analogy is not exactly what is happening in banking, but it’s close. For decades, advanced cyber capabilities have remained concentrated among nation-state threat actors and sophisticated financially motivated cybercriminals. Frontier AI models are beginning to change that equation, making powerful cyber capabilities more accessible and easier to deploy.

At the same time, banks are undertaking a massive overhaul of the cryptographic systems that secure everything from digital payments and customer accounts to identity verification. Known as post-quantum cryptography (PQC), the effort aims to protect today’s financial infrastructure against advances in computing that can render current encryption obsolete. The convergence of these trends comes at a critical time.

Financial institutions are undertaking a generational upgrade of the security infrastructure underpinning the digital economy. Meanwhile, attackers are gaining access to increasingly powerful cyber capabilities. The result is a growing imbalance that can shape the next cyber crisis.

When the locks change and the lockpicks improve

Advanced cyber operations have long required significant expertise, infrastructure and investment. Many attackers can purchase tools or obtain access through cybercrime marketplaces. However, only a relatively small group of highly capable actors can discover new vulnerabilities, develop exploits and operate at scale.

Recent advances in frontier AI are quickly eroding those barriers. Used responsibly, these tools strengthen cybersecurity defenses. In banking, they help security teams identify potential weaknesses and respond to threats more quickly.

However, these capabilities are becoming widely accessible. As a result, attackers can use these same capabilities offensively to develop exploits and accelerate cyber operations at a speed and scale that were previously out of reach. Early evidence indicates that the impact of AI-driven cyberattacks is already growing.

Advanced AI systems are becoming increasingly capable of identifying software vulnerabilities, chaining exploits together and accelerating offensive cyber techniques. IBM’s Cost of a Data Breach Report 2026 found that AI-driven attacks increased 56% year over year and added an average of USD 1 million to the cost of a breach. Financial services experienced some of the highest breach costs of any industry, averaging USD 6.29 million per incident.

The trend is becoming visible in other ways as well. Google’s Threat Intelligence Group reported what it believes to be the first observed case of a threat actor employing AI to help develop a zero-day exploit. The exploit targeted a vulnerability that was unknown to defenders and had no available patch.

These events are significant beyond a single isolated incident. Banking leaders should expect a future in which advanced attacks become faster, more scalable and increasingly difficult to predict.

Banks’ earlier security playbook no longer applies

The use of frontier AI by threat actors is significant on its own. The transition to post-quantum cryptography is a major shift in its own right. Together they create a more complex problem.

Modern banking runs on cryptography. It secures customer information, protects transactions, verifies identities, enables digital channels and underpins the trust that allows billions of financial interactions to take place every day. Customers rarely see it. Yet every customer depends on it.

Post-quantum cryptography represents the next evolution of that foundation. Its purpose is straightforward: to ensure that the systems securing financial institutions remain resilient against future technological advances that can weaken today’s encryption standards. The need for PQC is easy to understand. The complexity lies in the scale of the transition itself.

Large banks operate thousands of applications, databases, interfaces, APIs and vendor relationships. Over decades, cryptographic dependencies have become deeply embedded throughout those environments. Identifying them, understanding the risks they create and executing a migration strategy often demands years of planning and coordination.

Y2K is a useful comparison. Often remembered as a crisis that did not happen, Y2K was in fact a crisis that organizations spent years preventing. Banks, governments and businesses identified a systemic vulnerability buried deep within critical infrastructure and invested heavily to address it before it disrupted operations. The post-quantum transition shares many of those characteristics.

Y2K arrived with a fixed deadline. Every boardroom knew exactly when the clock would strike midnight. Every institution worked toward the same immovable date. But post-quantum cryptography offers no such universally recognized deadline.

Unlike Y2K, there won’t be a single moment when everything breaks all at once. Quantum risks will materialize over several years as different cryptographic systems become vulnerable at different times. As a result, the absence of urgency can prove to be the greatest challenge of all and can lead to unnecessary cost and business disruption.

Without a fixed deadline, institutions risk delaying action, leaving critical systems exposed for longer and increasing the cost and complexity of a transition.

Redefining resilience from IT recovery to managed degradation

This convergence forces a fundamental shift in how financial institutions define enterprise risk. Traditional frameworks treat resilience as an IT recovery exercise, aimed at restoring systems to a pre-breach state based on static recovery time objectives (RTOs). But when AI accelerates exploit velocity and post-quantum migration disrupts core cryptographic dependencies, static recovery targets fall apart. 

True enterprise resiliency is an executive capability for managed degradation. It requires boards and risk officers to establish the governance needed to consciously shed non-essential digital services while defending core clearing, settlement and liquidity mechanisms under active, sustained compromise. Ultimately, resilience is not system uptime. It is balance-sheet and trust preservation when failure is already occurring.

Preparing before the clock runs out

Replacing those cryptographic foundations involves far more than deploying a new application or upgrading a piece of hardware. It requires reengineering cryptographic systems embedded across decades of applications, networks, vendor relationships and business processes.

The scale of that challenge is easy to underestimate. According to the IBM Institute for Business Value’s 2026 Tech Leader Study, 82% of banking and financial markets technology leaders say that they are not fully prepared for the scale of change ahead. AI is expected to drive that change over the next year.

As awareness grows, so too do the efforts to close the gap. In May, IBM® and Red Hat® announced Lightwell, a USD 5 billion commitment and a global force of more than 20,000 engineers dedicated to securing open source software. Several major global banks have already signed on as early adopters as attackers use AI to accelerate the discovery of vulnerabilities.

The sobering reality is that banks still face a year-long transition. And because time is one resource no institution can buy back once it has been lost, the organizations that wait for certainty will find they have waited too long.

IBM is a leading global hybrid cloud and AI, and business services provider, helping clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs and gain the competitive edge in their industries. Nearly 3,000 government and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM's hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently, and securely. IBM's breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and business services deliver open and flexible options to our clients. All of this is backed by IBM's legendary commitment to trust, transparency, responsibility, inclusivity, and service.

For more information, visit: www.ibm.com.

LATEST COMMENTS

Buyer's Guide Search

Popular Products

Nexus Portal
43,973
IPCharge
38,954
IPCharge
38,954
Barcode400
37,626
WebSmart ILE and PHP
37,109
Presto
36,876
Catapult
35,738
Catapult
35,738
EDI Software - EZConnect iSeries EDI/XML Software Solutions
25,559
EDI Software - EZConnect iSeries EDI/XML Software Solutions
25,559

Support MC Press Online

$

Book Reviews

Resource Center

  •  

  • LANSA Business users want new applications now. Market and regulatory pressures require faster application updates and delivery into production. Your IBM i developers may be approaching retirement, and you see no sure way to fill their positions with experienced developers. In addition, you may be caught between maintaining your existing applications and the uncertainty of moving to something new.

  • The MC Resource Centers bring you the widest selection of white papers, trial software, and on-demand webcasts for you to choose from. >> Review the list of White Papers, Trial Software or On-Demand Webcast at the MC Press Resource Center. >> Add the items to yru Cart and complet he checkout process and submit

  • SB Profound WC 5536Join us for this hour-long webcast that will explore:

  • Fortra IT managers hoping to find new IBM i talent are discovering that the pool of experienced RPG programmers and operators or administrators with intimate knowledge of the operating system and the applications that run on it is small. This begs the question: How will you manage the platform that supports such a big part of your business? This guide offers strategies and software suggestions to help you plan IT staffing and resources and smooth the transition after your AS/400 talent retires. Read on to learn: