The financial system has always been a target for state-aligned cyber operations. What has changed in the last two years is the cost structure of those operations. Generative artificial intelligence has not introduced new categories of state-on-state cyber activity. It has compressed the resource footprint required to run them, broadened the set of actors capable of running them at scale, and reduced the time required to conduct the reconnaissance that historically constituted the largest investment in any sustained campaign.
The shift in cost structure
The economics of state-aligned cyber operations against financial infrastructure have, until recently, favoured a small number of well-resourced services. Sustained campaigns required intelligence officers fluent in the target language, technical operators with detailed knowledge of the target environment, and analysts capable of synthesising the resulting intelligence into actionable plans. The cost of assembling and maintaining such teams was substantial, which constrained both the number of campaigns that could be run simultaneously and the breadth of targets that any one service could prosecute.
Generative artificial intelligence has not eliminated any of these requirements. It has lowered the cost of each. Language proficiency for the purposes of social engineering can now be approximated by a model trained on freely available material. Reconnaissance against publicly accessible infrastructure can be automated and run continuously across thousands of targets. Synthesis of open-source intelligence, formerly a labour-intensive analyst task, can be performed in volume at a fraction of the previous cost.
The consequence is a broadening of the set of state-aligned actors capable of conducting sustained campaigns against financial infrastructure, and an increase in the number of simultaneous campaigns that any single actor can support. The resource constraint that historically limited the operational tempo has been relaxed.
What state actors target in the financial system
The targets within the financial system that state-aligned actors prioritise are not, in general, retail customer accounts. They are the systems whose disruption would have systemic consequences. Settlement infrastructure, central counterparties, large-value payment systems, the messaging networks that carry instructions between institutions, and the cloud infrastructure on which an increasing share of regulated activity depends are the categories that supervisors and intelligence services consistently identify as priority concerns.
The interest in these targets is not solely about disruption. It is about positioning. Maintaining quiet access to systemically significant infrastructure, without exercising it, is itself a strategic objective. The capability to disrupt at a moment of choice is a form of leverage, and the value of the leverage depends on the access being established before the moment in which it is needed.
This dynamic produces an asymmetry that conventional intrusion detection is poorly equipped to surface. The activity that is most strategically consequential is the activity that is most carefully calibrated to remain undetected. The adversary's incentive is to maintain access without exercising it, which is the opposite of the incentive that historically drove most criminal intrusion activity.
The infrastructure that has become contested
Three categories of infrastructure have moved into sustained focus over the past eighteen months.
The first is large-value payment systems. The networks that carry the instructions for the highest-value institutional payments are tightly governed and subject to substantial controls, but they remain attractive targets because of the consequence of any successful disruption. Resilience exercises run by the operators of these networks have begun to incorporate scenarios that explicitly assume the presence of a state-aligned adversary with prior reconnaissance.
The second is the messaging networks that connect institutions to each other and to those payment systems. These networks are governed by industry consortiums and have invested heavily in security, but they remain a high-leverage target because of the breadth of the institutional dependency on them. Compromises observed in this category in the past have been associated with substantial financial losses and with sustained reputational consequences for the affected institutions.
The third is the cloud infrastructure on which an increasing share of financial activity is hosted. The concentration of regulated workloads in a small number of hyperscale cloud providers has produced a category of systemic exposure that supervisors have made explicit. The Digital Operational Resilience Act in the European Union and the Bank of England's emerging oversight regime for critical third parties are direct responses to this concentration. The supervisory expectation is that institutions will maintain the capability to substitute providers in the event of a sustained outage, an expectation that is straightforward to articulate and substantially harder to operationalise.
How regulators are responding
The supervisory response to the elevated state-aligned threat has taken several forms. The first is more explicit reference to the threat in supervisory priorities. The European Banking Authority's 2025 work programme references AI-enabled threats and the broader cyber risk environment in terms that are noticeably more direct than equivalent material from earlier years. The Bank of England's CBEST cyber resilience programme has incorporated adversarial scenarios that reflect the current threat landscape. The Federal Reserve and the Office of the Comptroller of the Currency have issued joint statements on the heightened risk environment.
The second is the increased use of sector-wide exercises that test the collective response to a state-aligned scenario. These exercises, often run jointly between supervisors, central banks, and infrastructure operators, surface the gaps that no single institution can close on its own. The exercises are not always made public, but the supervisory community has been more transparent about their existence and about the categories of finding they have produced.
The third is the closer integration between financial supervisors and national security agencies. The boundary between cyber risk to financial institutions and broader national security concerns has, in practice, been blurred for some time. The institutional acknowledgement of that fact, and the corresponding increase in the formality of the relationships between supervisors and intelligence services, is more recent.
What this means for institutions
For institutions, the implication is not that they are now expected to defend against state-aligned adversaries on their own. The expectation is that they will participate constructively in the collective defensive architecture, that they will maintain the operational capabilities required to detect and respond to the categories of activity associated with state-aligned operations, and that they will be candid with supervisors about the gaps that remain.
The operational capabilities most consistently associated with effective participation in the collective defence are continuous behavioural detection, integration with industry intelligence-sharing bodies, and the institutional capacity to act on intelligence shared in restricted forums in something close to real time. None of these capabilities is novel. The level of investment required to maintain them at the standard the current threat landscape warrants is, in many cases, materially higher than the level institutions had previously planned for.
The next instalment in this series turns to the question that frames the entire architecture of operational resilience, which is whether the institutions that pass their resilience assessments are, in fact, prepared.
