Skip to navigation Skip to main content Skip to footer

AI is accelerating cyber risk

Why the ECB is calling for action,
and all industries should take note

By Natalie Walker

17 September 2026

 

Artificial Intelligence (AI) is not simply creating new cyber risks; it is accelerating and amplifying existing risks financial services organisations already face.

In July 2026, the European Central Bank (ECB) warned that emerging AI models are enabling attackers to identify software vulnerabilities and develop exploits at unprecedented speed. As a result, leaders of significant financial institutions have been asked to assess the impact on their organisations and submit action plans addressing AI-enabled cyber risk to the ECB.

At the heart of the challenge is the shrinking window between vulnerability discovery, disclosure and exploitation.
AI can rapidly analyse exposed systems, identify vulnerable technologies and assist in developing exploit techniques. It can also help attackers combine vulnerabilities, misconfigurations, weak credentials and excessive privileges into complete attack paths far more efficiently than before.

This fundamentally changes the questions organisations need to answer. Rather than simply asking, "How many vulnerabilities do we have?", security teams must understand:

  • Which weaknesses are genuinely exploitable?
  • How could they be combined by an attacker?
  • What systems, data or business processes could be reached?
  • Which remediation activities will most effectively reduce risk?

Growing volumes of vulnerabilities

Recent vulnerability disclosures illustrate the scale of the challenge. Security research indicates a significant increase in reported vulnerabilities throughout 2026, with organisations facing hundreds of new issues each month.

More vulnerabilities do not necessarily mean less secure software. However, they do create additional pressure on security teams to assess findings, prioritise remediation and determine which exposures represent genuine business risk.

The objective is not simply to remediate everything faster. The objective is to focus resources on the vulnerabilities and attack paths most likely to result in material business impact.

What is the ECB asking organisations to address?

The ECB's guidance focuses on six key areas:

  1. Protect attack surfaces.
  2. Accelerate vulnerability and patch management.
  3. Enhance monitoring, detection and AI-enabled defensive capabilities.
  4. Strengthen governance, awareness, funding and supply-chain assurance.
  5. Improve cyber hygiene and defence-in-depth controls.
  6. Enhance operational resilience, including incident response and recovery.

Importantly, the ECB's message goes beyond vulnerability management. It highlights the need for organisations to develop the people, processes, governance and technology required to anticipate, withstand, respond to and recover from AI-enabled cyber threats.

Why this matters beyond financial services

Although the ECB's requirements are directed at significant financial institutions, the underlying risks affect every sector.

AI is increasing the effectiveness of vulnerability discovery, reconnaissance, social engineering and cyber intrusion activity across industries. Governments and regulators worldwide have warned that AI will increase both the speed and scale of cyber-attacks.

As a result, organisations outside financial services may face similar expectations through:

  • Industry-specific regulation.
  • National cyber security guidance.
  • Critical infrastructure requirements.
  • NIS2 and Cyber Resilience Act obligations.
  • Customer and supply-chain assurance requirements.
  • Board and investor scrutiny.


While the ECB letter may not apply directly to every organisation, it provides a valuable benchmark for an important question:

Can the organisation identify exposures, prioritise exploitable risks, remediate effectively and maintain resilience as AI accelerates the threat landscape?

How should organisations respond?

A proportionate response should focus on visibility, prioritisation, remediation and resilience.

1. Understand the attack surface

Organisations need a comprehensive understanding of their internal and external attack surface, including internet-facing assets, cloud services, remote access technologies, third-party connections and critical infrastructure.
This visibility should identify what assets exist, which are business-critical and which may provide attackers with an entry point.

2. Prioritise based on exploitability

Traditional vulnerability severity scores remain useful, but they should be considered alongside:

  • Asset criticality.
  • Exposure to attackers.
  • Exploitability.
  • Identity and credential weaknesses.
  • Misconfigurations.
  • Known threat activity.
  • Attack path context.
  • Potential business impact.

This helps distinguish theoretical vulnerabilities from risks that could realistically be exploited.

3. Accelerate targeted remediation

Organisations should focus on remediation activities that break the highest-risk attack paths.

This may include:

  • Patching vulnerable systems.
  • Correcting misconfigurations.
  • Reducing excessive privileges.
  • Improving identity controls.
  • Removing unnecessary assets from the environment.

As vulnerability volumes continue to increase, mature prioritisation and remediation processes become essential.

4. Validate remediation effectiveness

Closing a vulnerability ticket does not necessarily mean risk has been removed.

Targeted retesting and validation activities can confirm whether a vulnerability, exposure or attack path remains exploitable and identify any residual risk.

5. Strengthen operational resilience

Technical controls should be supported by effective:

  • Governance and executive oversight.
  • Monitoring and detection capabilities.
  • AI risk management.
  • Third-party assurance.
  • Incident response planning.
  • Crisis management processes.
  • Recovery and resilience arrangements.

Organisations should view cyber resilience as a combination of technology, people, processes and governance rather than relying on a single security tool.

How NCC Group can help

NCC Group combines market-leading technologies with expert-led security services to help organisations address modern security challenges.

For organisations responding to the ECB's recommendations, NCC Group can conduct an ECB Action Plan Readiness Health Check, assessing organisational maturity across the ECB's six focus areas through stakeholder interviews, documentation reviews and targeted workshops.

In addition, NCC Group can provide an AI-Driven Exposure & Exploitability Review, providing a targeted assessment of selected environments and identifying the exposures that require the most urgent attention.

The ECB's message is clear: AI is reducing the time available for defenders to detect, prioritise and respond to cyber threats. Organisations must ensure they have the visibility, prioritisation, remediation and resilience capabilities needed to keep pace with increasingly sophisticated attacks.

 

Frequently Asked Questions

The risks identified by the ECB are not limited to significant institutions. ECBs guidance affects all organisations as none of us are immune to AI attacks, no matter how big or small we are. AI is accelerating vulnerability discovery, exploit development and attack-path analysis across the wider financial sector.

Less significant institutions may also face:

  • applicable DORA obligations;
  • national supervisory expectations;
  • customer and counterparty scrutiny;
  • third-party assurance requirements; and
  • increasing board attention around AI-enabled cyber risk.

The ECB’s six focus areas can therefore provide a valuable benchmark, and insight into best practices, even where the specific request does not directly apply.

NCC Group can adapt the Action Plan Readiness Healthcheck into a benchmark-based review, helping the organisation understand its current position and identify proportionate priorities.

Sources

1. European Central BankAddressing AI-enabled cybersecurity threats, 7 July 2026.
Read the ECB letter

2. Cyber Security NewsMicrosoft Patch Tuesday May 2026: 120 Vulnerabilities Fixed, 12 May 2026.
Read the May 2026 Patch Tuesday analysis

3. Tenable, Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs, 9 June 2026.
https://www.tenable.com/blog/microsofts-june-2026-patch-tuesday-addresses-198-cves-cve-2026-49160-cve-2026-50507

4. Qualys, Microsoft Patch Tuesday, June 2026 Security Update Review, 9 June 2026.
Read the Qualys June 2026 analysis

5. Tenable, July 2026 Patch Tuesday: Largest Patch Tuesday, 569 CVEs, 14 July 2026.
Read the Tenable July 2026 analysis

6. Windows Central, Windows 11’s massive July 2026 update fixes 570 vulnerabilities and shows how AI is reshaping Patch Tuesday, 18 July 2026.
Read the Windows Central Patch Tuesday analysis

7. UK National Cyber Security CentreImpact of AI on cyber threat from now to 2027.
Read the NCSC assessment

8. European CommissionEU Action Plan on Cybersecurity and Artificial Intelligence, 7 July 2026.
Read the European Commission Action Plan

9. European Commission, Commission presents EU Action Plan on Cybersecurity and Artificial Intelligence, 7 July 2026.
Read the European Commission announcement

10. Horizon3.ai, Cloud Pentesting with NodeZero.
https://horizon3.ai/nodezero/cloud-pentesting/

11. European Central BankList of supervised banks.
View the ECB list of supervised banks

12. European Central BankWhat makes a bank significant?
Review the ECB significance criteria

13. European Banking AuthorityDigital Operational Resilience Act.
https://www.eba.europa.eu/activities/direct-supervision-and-oversight/digital-operational-resilience-act

This article provides general cyber-security and resilience information. It does not constitute legal advice, a regulatory interpretation or confirmation that a specific organisation or legal entity is subject to the ECB letter, DORA or another regulatory requirement.

Natalie Walker

Natalie Walker

VP Managed Services Portfolio and Global Partnerships, NCC Group

Natalie Walker has worked in technology for 20+ years, most recently leading BT Security’s Cyber Portfolio and Partnership organization. She now heads NCC Group’s Global Managed Security Services portfolio delivering solutions to clients from vulnerability management to threat management and response. She also develops and manages NCC Group’s technology partnerships, enabling solutions across the group which combine industry leading technology with the Group’s strong heritage and highly skilled cyber professionals. 

Contact NCC Group to identify the most appropriate starting point for your organisation. 

 

Get in touch   View the full ECB AI Risk -Action Plan Readiness Package