Building sustainable, scalable security
19th January 2027 • Park Plaza Victoria, London, UK
More people and more tools are not a sustainable answer to today's security challenge. So how are financial services firms responding to a threat environment transformed by Al and geopolitics?
Breaking the link between security workload and security headcount
Simply adding more people and more tools is not a sustainable security strategy. As Al and geopolitics reshape the threat landscape, how can financial services firms combine technology, talent and new operating models to strengthen protection while keeping cost and complexity under control? How do they increase capacity sustainably?
Financial services firms have invested heavily in cybersecurity. The challenge now is to build on that investment: increasing the capacity and effectiveness of security teams as threats evolve, technology estates change and businesses introduce new digital services.
Core defences remain essential. In September 2026, Revolut reportedly disclosed sensitive customer information following fraudulent requests through an apparently legitimate government email account, while saying its internal systems and customer funds were unaffected. The incident illustrates the continuing importance of identity verification and well-designed processes, even in technologically sophisticated organisations.
The previous month, hackers launched a wave of sophisticated attacks on Wall Street firms targeting information systems at major money managers. The attack featured voice phishing, or vishing, in which cyber criminals use technology to mimic voices in phone calls or messages to trick employees into revealing sensitive information or granting access. (In KPMG's 2026 survey of 39 wealth and investment firms, 92% placed cyber among their top five risks, with 41% identifying it as their biggest threat.)
These attacks show that banks must continue to focus on core defences against credential theft and other 'traditional' forms of attack.
But their real challenge is increasing the efficiency and sustainability of their security operations as Al and other forms of automation scale up the volume and sophistication of those attacks.
Maintaining their foundations while developing new capabilities creates difficult investment and organisational choices. Al offers opportunities to accelerate detection, investigation and response, but deploying it effectively requires reliable data, appropriate access controls and clear accountability. Leaders must decide which activities to automate, where human judgement adds most value, and how to measure whether new capabilities actually improve protection and release team capacity.
Technology choices and operating models need to evolve together. Consolidating platforms may simplify operations but can also create dependencies or leave gaps in specialist capabilities. Managed services can provide expertise and additional capacity but require effective oversight and clearly allocated responsibilities. Embedding security expertise in product and engineering teams can support faster delivery, provided common standards and accountability remain clear.
Regulation gives these decisions a concrete timetable. New UK requirements for operational incident and material third-party reporting take effect on 18 March 2027, with different scopes for each regime. For affected firms, this makes reliable incident information, clear reporting responsibilities and visibility of supplier arrangements immediate priorities-and strengthens the case for integrating them into everyday operations.
The FCA has also highlighted the potential for frontier models both to strengthen cyber defence and amplify threats to customers, firms and financial stability. The challenge for leaders is deciding where automation delivers dependable protection and where human judgement remains essential. The boardroom conversation is evolving alongside these demands.
Security leaders need to explain what additional investment will achieve, which capabilities can be simplified, and how their decisions support business priorities. Measuring effectiveness, demonstrating resilience and managing dependence on major technology providers are central to that discussion.
Through practical case studies and candid peer discussion, Securing Financial Services will examine how firms can expand security capability without costs and complexity growing at the same rate-and build teams and systems ready to support the next phase of financial innovation.
Key themes will include:
Al and automation that deliver provable value
The market is moving from "Al-powered" to "Alproven". Provable value starts with outcomes the customer already measures: mean time to detect and respond, analyst hours returned, false-positive rates, incidents contained before impact. Can CISOs evaluate Al-enabled security solutions like this? And what about the costs?
Changing the workforce pyramid
Cybersecurity has long been staffed as a pyramid: a broad base of junior analysts triaging alerts, narrowing to a small tier of senior specialists. How can organisations redesign early-career roles around supervising, validating and tuning Al, so that automation elevates junior talent instead of eliminating the route to seniority?
Data control and visibility when there is no perimeter
How can firms enforce confidentiality when data is constantly in motion across systems the firm does not fully control? For CISOs, does this mean that the focus must shift toward controlling data itself rather than the environments it resides in? If so, what kinds of architectures and solutions can deliver security in that context?
The future of the CISO
Cyber risk is now a board-level concern, but most CISOs still report into IT and get barely half an hour of board airtime a quarter. Meanwhile, risk, legal and GRC leaders are increasingly claiming ownership of cyber. So, who should own cyber risk, what the CRO's growing influence means, and what CISOs must do to earn, and keep, a strategic mandate?
Integrity and the Al-enabled supply chain
Al-native operating models imply dependence on a complex supply chain of foundation models, internal systems, and external APls and orchestration layers that collectively produce legal work. Imagine the consequences of hacking such a system. So how do CISOs stop that happening?
Moving security's ROI
Can we truly quantify the value protection of cybersecurity? Harder, can we prove that security creates value, not just defends it? Does good security mean faster sales cycles, increased trust and so premium pricing, M&A readiness? Can security vendors and their solutions help reveal and improve the ROI of cybersecurity?
Transforming the SOC: a case-study in building capacity
Most socs are drowning: too many alerts, too few analysts, and burnout that turns recruitment into a treadmill. How should CISOs chose which work to automate, how to keep analysts in control of Aldriven triage and how can they improve detection speed, reduce false positives and increase staff retention?
Securing algorithmic insiders
What does "insider threat" mean when the actor is non-human? For CISOs, the focus shifts to monitoring the behaviour of agents as well as users, developing capabilities to detect anomalous machine activity, and establishing effective controls that balance guardrails, detection, and containment. Do you need Al defences to do that?
Solving sprawl: getting security tooling under control
Security teams run dozens of tools that overlap and are seldom fully used. The result is wasted budget, alert noise and analysts who spend more time switching consoles than stopping attacks. Now Al is adding a fresh layer. So, what is the practical route to rationalisation and where do integrated platforms and outsourcing fit in?
The power of automation
There's too much manual intervention in security. SOAR pulls data from SIEMs, EDRs, firewalls, cloud APls, ticketing systems threat intelligence feeds, and even email servers and coordinates actions across tools via APls and prebuilt integrations and intelligent playbooks. Well, that's the theory. How does it work in the real world?
The Al productivity paradox: what does it all cost?
Al-powered platforms promise productivity, but is anyone totting up the price? If you add up consumption pricing, data preparation, integration, governance, and the hours spent checking what the machine got wrong plus the cost of securing Al itself then what? Is Al really the solution to sustainable scalability?
Regulation latest
Prescriptive regulatory requirements risk forcing investment into compliance and reporting over real risk reduction. The push to land banks with liability for third-party and systemic failures looks disproportionate, despite their limited control over cloud providers and critical vendors. All this creates cost, accountability, and insurability challenges. So, what are banks doing to mitigate costs and risks?