“While banks continue to face a number of risks like ransomware, business email compromise and vendor data breaches, the increased availability and use of AI by threat actors adds complexity to the risk environment,” Bowman said in remarks prepared for Tuesday’s (Sept. 29) Community Bank Cyber Workshop in Denver, Colorado. “AI offers great potential—both to threat actors and those buttressing their defenses to those threats. It has the ability to accelerate vulnerability identification, create sophisticated social engineering campaigns, lower the barrier to entry for cyber criminals, and adapt attacks in real time as they are carried out.”
Protecting against these risks requires robust cyber hygiene, which includes up-to-date asset inventories, phishing-resistant multifactor authentication, sturdy identity and access controls, and strong vulnerability identification and patch management programs, Bowman said.
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
“AI is becoming a critical component of these security measures as both a defensive tool and an evolving risk,” Bowman said.
While cybersecurity requires proactive risk management on the part of banks, regulators recognize that preparing for such threats can be burdensome and challenging for community lenders, Bowman said.
“That’s why we continue to tailor our approach to IT examinations to consider risk profile and emerging threats and risks,” Bowman said, calling on small banks to provide feedback on how the Fed can provide more clarity on its expectations.
The International Monetary Fund found last month that AI does not need to come up with new types of cyberattacks to pose a threat, PYMNTS reported Aug. 11.
“By accelerating vulnerability discovery and exploitation across shared technologies, AI can turn weaknesses that once produced isolated incidents into correlated disruptions affecting multiple institutions simultaneously,” the report said.
The question is what powerful models can do when given tools, credentials, network access or a poorly-planned test environment. Companies must consider how much autonomy systems should receive, what they should be allowed to touch and whether organizations can contain them when something goes wrong.
For all PYMNTS AI coverage, subscribe to the daily AI newsletter.