Preskoči na sadržaj

European banks get deadline to defend against AI attacks

Money3 min čitanja

The European Central Bank (ECB) has asked major banks in the Eurozone to prepare action plans by October 31 to defend against cyber-threats initiated or additionally enhanced by artificial intelligence (AI).

From Frankfurt, they say that AI is no longer just a tool for more efficient data processing and improving customer support, but also a potential source of systemic risk for the financial sector.
Focus on protecting key systems

The ECB requires banks to prioritize the protection of systems exposed to the Internet, third-party technologies and open source software.

Financial institutions are expected to improve:

– internet system protection,
– management of third-party technologies,
– security of open source software,
– faster removal of vulnerabilities,
– modernization of outdated IT infrastructure,
– strengthening cyber-hygiene,
– recovery plans after cyber-incidents.

Unlike some other central banks, the ECB does not just stick to recommendations. Banks will have to present concrete measures, deadlines and plans to respond to new threats.

AI is changing the nature of cyber risk

Special attention is focused on the so-called frontier AI models, i.e. the most advanced artificial intelligence systems that can affect both defensive and offensive cyber-operations.

The regulator warns that such models can accelerate the discovery of security flaws, automate the preparation of attacks and increase the number of threats to which banks, payment systems and financial infrastructure are exposed.

The European Systemic Risk Board has warned that AI is changing the entire landscape of cyber threats in the financial system of the European Union, which is why this issue is no longer just an IT challenge, but also a question of financial stability.

Payment systems represent a special risk

The ECB warns that a serious cyber-attack could have consequences far beyond a single bank.

An attack on a common technology vendor, cloud service, or software component used by multiple financial institutions could compromise payments, transaction settlement, and customer trust.

That is why the regulator asks banks to check the resilience of not only their own systems, but also their dependence on external suppliers and technology partners.

A message for countries outside the Eurozone as well

Although the deadline set by the ECB formally refers to the large banks of the eurozone, this decision represents an important signal for countries that are approaching the European financial framework.

The digitization of banking services and the development of instant payments increase the importance of cyber-security, so the regulatory standards introduced by the ECB are increasingly becoming a benchmark for financial markets outside the Eurozone.

Along with the development of new digital services, banks will have to demonstrate that behind speed and innovation are reliable protection, effective risk control and resistance to increasingly sophisticated cyber-threats, Investor reports.

Kako ti se čini ovaj članak?

Povezano

Sve →