Skip to main content
    Back to LUMINAIRE
    AI & Capital№ 000 / 2026

    When Static Controls Meet Adaptive Threats

    Why annual penetration tests, threshold-based detection, and impact tolerances built for discrete events fail against adversaries engineered to operate beneath them.

    When Static Controls Meet Adaptive Threats

    AI & Capital
    15 min read7 sourcesLIVE

    Click to generate an iQ-powered summary of this article

    The frameworks that govern operational resilience in modern banking were drafted during a period when cyber incidents were understood as discrete events with clear start points and recoverable end states. A breach was a moment, an outage was a window, and the regulatory architecture could reasonably ask an institution to define impact tolerances around bounded disruptions. That premise is now under sustained pressure, not because the frameworks are wrong, but because the threat they were designed to govern has changed shape.

    What annual penetration testing was built to do

    Annual penetration testing is one of the oldest controls in financial services cybersecurity. The premise is straightforward. A skilled team, given limited information about a target environment, attempts to reach a defined objective and reports its findings. The institution remediates the issues identified. Supervisors review the report. The cycle repeats.

    For most of the period in which the practice matured, the threat landscape moved at a pace that an annual cadence could plausibly track. Attacker techniques diffused slowly. The most consequential attacks were performed by a small number of well-resourced actors. The space between tests was the space in which defenders could close gaps without the gaps materially widening.

    That equilibrium has been disrupted. The diffusion of attacker tooling, accelerated by generative artificial intelligence in a way that compresses both training time and operational tempo, has made the space between annual tests a space in which the threat landscape itself can change. The control is not obsolete. It is no longer self-sufficient.

    The migration that is underway in the institutions making the most progress is from annual penetration testing to continuous adversarial emulation. The distinction is not cosmetic. Continuous adversarial emulation runs simulated attacks against the production environment on a rolling basis, often weekly or monthly, using techniques that mirror those observed in the wild. The result is a test cadence that approaches the cadence of the threat itself.

    What threshold-based detection was built to do

    Threshold-based detection is the dominant detection paradigm in financial services security operations. A rule is written. A signal that exceeds a defined value triggers an alert. An analyst investigates. The premise is that consequential adversarial activity will produce signals large enough to cross the threshold.

    The premise held for most of the previous decade because the adversaries that produced the most consequential incidents were, on the whole, not engineered to be undetectable. They were engineered to be fast. The race was between attacker speed and defender response time, and the threshold was the starting gun.

    Generative artificial intelligence has shifted the race. The class of attack that now produces the most consistent results is engineered specifically to operate beneath thresholds. Reconnaissance is paced to mimic legitimate traffic. Lateral movement is fragmented to avoid signature matches. Data exfiltration is metered to remain within network volume baselines. Each of these techniques is individually trivial. In combination, they produce an engagement profile that the threshold-based system was not built to recognise.

    The migration that is underway is from threshold-based detection to behavioural analytics, in which the system scores deviations from a learned baseline rather than absolute values. An account exhibiting three small unusual behaviours simultaneously is more interesting than the same account exhibiting any one of them in isolation. The analytics are not new. The deployment at scale, integrated with case management workflows and regulatory reporting obligations, is what is changing.

    What impact tolerances were built to do

    Impact tolerances are a comparatively recent regulatory construct, formalised in the United Kingdom by the Prudential Regulation Authority's operational resilience regime, in the European Union by the Digital Operational Resilience Act, and in equivalent guidance in other jurisdictions. The premise is that for each of an institution's important business services, the institution must define the maximum tolerable disruption it can sustain without causing material harm to consumers, the institution itself, or financial stability.

    The construct has been productive. It forced institutions to map their important business services, to understand the dependencies that support them, and to plan for the recovery of those services within defined windows. It also encoded an assumption about the shape of the threat. The assumption is that disruption is a discrete event with a measurable start and a measurable end.

    Adaptive adversaries do not always produce events of this shape. An adversary that has obtained access to a critical business service and is extracting value continuously over a period of weeks is not producing a disruption that begins on a Tuesday and ends on a Thursday. The impact tolerance, framed in hours of downtime, does not capture the consequence.

    The institutions that are making the most progress are those that have begun to develop a parallel construct alongside their impact tolerances. The construct is sometimes called residual exposure. It is the assessment of consequence under a continuous, sub-threshold compromise scenario, expressed in terms that supervisors can engage with. The work is early. The direction is correct.

    Where the frameworks have begun to acknowledge the gap

    It would be wrong to describe the regulatory architecture as static. Supervisors have begun to acknowledge the gap explicitly. The European Banking Authority's 2025 work programme cites artificial intelligence-enabled threats as a supervisory priority. The Bank of England's evolving expectations for cyber stress testing reference adversarial scenarios that include adaptive elements. The Federal Reserve and the Office of the Comptroller of the Currency in the United States have issued joint statements on the heightened risk landscape associated with generative artificial intelligence. The Financial Stability Board has commissioned work on cyber lexicons and incident reporting that anticipates the kind of continuous compromise scenarios that current frameworks struggle to capture.

    The work is not complete. The direction is consistent. Institutions that engage with supervisors candidly about the gap, and that demonstrate the migration from annual testing to continuous adversarial emulation, from threshold-based detection to behavioural analytics, and from impact tolerances framed solely as downtime windows to a parallel residual exposure construct, are positioning themselves for the next supervisory cycle.

    The cultural rather than technical constraint

    The constraint that most consistently prevents institutions from completing the migration is not technological. It is cultural. Annual penetration testing, threshold-based detection, and impact tolerances are deeply embedded in the institutional language of operational resilience. They are the constructs that boards understand, that auditors test against, and that supervisors evaluate. Replacing them is not a matter of procuring different tools. It is a matter of producing reports, dashboards, and conversations that translate the new constructs into language that boards and supervisors can act on.

    The institutions that have made the most progress have invested as much in the translation as in the underlying technology. They have rewritten their board reporting templates. They have updated their internal audit programmes. They have run joint exercises with supervisors that surface the gap candidly and rehearse the response.

    The next instalment in this series turns to the dimension of risk that sits above all of these, the encounter between AI-accelerated adversaries and the geopolitical layer in which national infrastructure becomes a target.

    #operational-resilience#ai-risk#regulation#cyber#banking

    Sources & References

    LUMINAIRE verifies all sources for accuracy and relevance.Read our editorial standards.

    Editorial Q&A

    Frequently Asked Questions

    8 questions answered by the LUMINAIRE editorial desk.

    Didn't find your answer?

    Ask LUMINAIRE iQ a follow-up question grounded in this article.

    Glossary

    Key Terms & Definitions

    16 terms defined for this briefing.

    A
    Adversarial emulation
    Simulated attack activity calibrated against techniques observed in the wild, run against production or near-production environments on a continuous basis.
    B
    Behavioural baseline
    A learned profile of normal activity for a user, account, system, or service against which deviations are scored.
    C
    Critical business service
    A service identified under operational resilience frameworks as one whose disruption would cause material harm to consumers, the institution, or financial stability.
    Cyber stress testing
    Supervisory exercises in which institutions demonstrate their response to defined cyber scenarios, increasingly incorporating adaptive and AI-enabled elements.
    D
    DORA
    The Digital Operational Resilience Act, the European Union regulation that establishes harmonised requirements for ICT risk management, third-party oversight, and incident reporting in financial services.
    I
    Impact tolerance
    The maximum tolerable disruption to an important business service, expressed as a duration or quantitative metric, beyond which material harm is presumed to occur.
    Important business service
    The Prudential Regulation Authority's term for the services in scope of operational resilience expectations, equivalent in substance to critical business services in DORA.
    L
    Lateral movement
    Adversary technique of moving from an initial foothold to other systems within the target environment, increasingly fragmented to avoid detection.
    P
    Penetration test
    A scoped security engagement in which a skilled team attempts to reach a defined objective and reports findings, traditionally conducted on an annual or semi-annual basis.
    R
    Red team engagement
    An extended objective-based exercise emulating a specific adversary, longer in duration and narrower in scope than continuous adversarial emulation.
    Residual exposure
    An emerging supplementary construct to impact tolerances that estimates consequences under continuous sub-threshold compromise scenarios.
    S
    Signal-to-noise ratio
    The proportion of detection signals that correspond to genuine adversarial activity, a key constraint on the operational viability of threshold-based detection.
    Sub-threshold activity
    Adversary actions calibrated to remain below the values that trigger threshold-based detection rules, often achieved through fragmentation and pacing.
    T
    Telemetry
    Operational data emitted by systems and used as the input to detection analytics, including authentication events, network flows, and process activity.
    Threshold-based detection
    Detection methodology in which an alert is generated when a defined signal exceeds a configured value, the dominant paradigm in security operations centres.
    Tolerance window
    The duration component of an impact tolerance, expressing the maximum permissible downtime for a critical or important business service.

    This article was researched and written by human editors with analytical assistance from AI tools. All conclusions are independently reviewed.

    The Byline

    LUMINAIRE Editorial

    The LUMINAIRE Editorial Team brings together analysts, technologists, and subject matter experts to chronicle humanity's transformation in the age of artificial intelligence.

    Report an issue with this article