

Banks and Financial Market Infrastructures remain firmly in the sights of cyber criminals. That is not new. What has changed is the scale, speed and sophistication of the threat.
Last year, up to 20 million people in the UK were impacted by cyber incidents affecting financial services organisations, a rise of 143 percent. At the same time, eight tier one banks, including Barclays, Lloyds and Nationwide, reportedly experienced 158 IT failures between them across just two years.
For institutions classed as Critical National Infrastructure, the pressure is relentless. Hundreds of millions are invested into defensive measures each year, yet the threat landscape continues to evolve. Ian Stuart, CEO of HSBC, has stated the bank makes around 8,000 IT changes and updates every week. That level of constant iteration is not optional. It is necessary to stay resilient.
From our perspective as a specialist cyber security recruitment partner, one theme is clear. Technology alone is not enough. The right people, with the right expertise, are what turn investment into real resilience.
Here are the key threats shaping 2026.
Banks have always been high value targets. In 2026, as global political tensions remain strained, we expect continued activity from state aligned threat actors.
These groups are deploying highly tailored malware and exploiting zero day vulnerabilities to probe payment systems, liquidity platforms and core banking infrastructure. Their objectives are not always financial. Some campaigns are designed to destabilise markets, undermine trust in institutions or create uncertainty across the wider economy.
There is also growing concern around destructive attacks such as wiper malware, alongside attempts to compromise trusted third parties within the financial ecosystem.
For banks, this means strengthening threat intelligence, red teaming capabilities and incident response functions. It also means hiring cyber professionals who understand both technical controls and the broader geopolitical context shaping risk.
The commercialisation of cybercrime continues to lower the barrier to entry for attackers.
Ransomware as a Service allows individuals with limited technical capability to launch sophisticated attacks through subscription based models. Modular attack kits can now be customised to target outdated middleware, exposed APIs or misconfigured cloud environments specific to banking operations.
This makes attacks more frequent, more varied and harder to anticipate.
Security teams must be able to respond at pace. That requires experienced cloud security specialists, application security experts and security architects who can assess and remediate vulnerabilities before they are exploited.
We are seeing increased demand for professionals who combine hands on technical depth with the ability to embed secure by design principles across transformation programmes. In our experience, these individuals are in short supply and highly sought after.
Artificial intelligence is reshaping social engineering at an alarming rate.
Traditional phishing is now accompanied by vishing and smishing campaigns powered by AI generated deepfake audio and visuals. Synthetic voice technology can convincingly replicate senior executives or regulators. That opens the door to fraudulent payment approvals or unauthorised system access.
Publicly available AI models have made these techniques accessible and scalable.
Mitigating this risk goes beyond awareness training. It requires robust identity verification processes, behavioural monitoring and well rehearsed response protocols. It also requires cyber professionals who understand emerging AI driven threats and can translate technical risk into clear guidance for boards and executive teams.
Regulators are acutely aware of the growing risk.
In the UK, the Financial Conduct Authority, Prudential Regulation Authority and Bank of England oversee CBEST, an intelligence led testing framework designed to assess firms’ resilience against real world threats.
Firms operating in the EU must align with DORA and TIBER EU testing requirements, while those with footprints in Asia Pacific face equivalent frameworks such as iCAST and CORIE. The forthcoming UK Cyber Resilience Bill, expected in 2026, is set to introduce further obligations.
For banks operating across multiple jurisdictions, aligning regulatory requirements, testing schedules and internal capabilities is becoming increasingly complex.
This is where capability gaps quickly become risk exposure.
The common thread across all of these challenges is people.
Advanced tooling, regulatory testing and large scale investment programmes all depend on the expertise of cyber security specialists. Without experienced practitioners leading threat intelligence, security operations, cloud security, red teaming and governance functions, resilience cannot keep pace with threat evolution.
At Broster Buchanan, we work closely with banks and financial services organisations to identify and secure high calibre cyber security professionals who can operate in complex, regulated environments. We understand the pressures facing CISOs and technology leaders, from managing regulatory scrutiny to delivering transformation at speed.
If your organisation is reviewing its cyber capability in light of the risks ahead in 2026, we are here to support you.
Speak to our cyber recruitment team to strengthen your defences with the right talent.
Speak to our cyber recruitment team to strengthen your defences with the right talent