Why finance talent needs new skills for AI cyber threats
.webp)
- AI has collapsed the window between a vulnerability being discovered and exploited - leaving banks exposed to cyber sttscks
- 60% of breaches still involve human error, yet AI literacy remains absent from most financial institutions' leadership capability frameworks
- The five human skills banks need to train now: threat judgment, AI literacy, incident leadership, shadow AI risk management, and cross-functional coordination
In April 2026, the European Central Bank (ECB) summoned an emergency meeting. The concern? An AI model so powerful that it exposed critical cyber security weaknesses - before the teams responsible for fixing them even knew the weaknesses existed.
The model, Anthropic's Mythos, was made available first to JPMorgan Chase, Microsoft, Google, and CrowdStrike - giving them a head start to find and fix vulnerabilities before bad actors could exploit them. No European bank made the cut, leaving them exposed at precisely the moment the threat landscape shifted.
Having scaled high-volume and new payment tech across international markets at Mollie, I know that with growth comes responsibility - particularly when it comes to protecting your customer data in a trust-based financial industry.
AI can now reverse-engineer software fixes within minutes of their release, collapsing the window between a vulnerability being patched and exploited by cybercriminals. Today, even unskilled criminals can target banks more easily and cheaply than before.
While regulatory frameworks like DORA have introduced mandatory guidelines, what combination of technology, regulation, and human capability do financial institutions need to protect themselves against sophisticated AI-driven attacks?
60% of breaches are human error
What I see is that teams within financial institutions need new capabilities to combat AI cyber threats.
In the past year, 87% of global organisations experienced an AI-powered cyberattack as the entry barrier for sophisticated attacks keeps falling. But 60% of breaches still involve human error: misconfiguration, poor judgment calls, shadow AI deployments, data inappropriately shared with tools.
In 2025, ECB uncovered that about half of surveyed banks had not introduced dedicated AI oversight policies or committees.
The people responsible for managing cyber risk - risk officers, CISOs, compliance leads, and the managers who sit between strategy and execution - are operating in organisations where AI literacy is still not a core leadership capability. That gap between technical understanding and decision-making authority is precisely where I see cyber risk widening.
The human skills banks need for cyber security
The instinct after Mythos has been to focus on tools: better detection software, faster patching infrastructure and AI-assisted threat monitoring. Those are necessary. But the human capability question is being underinvested, and it is more specific than "AI awareness training."
As a former FinTech leader and now a commercial lead in an AI-savvy workplace, there are certain skills I see growing in importance.
The ECB's own supervisory findings, DORA's incident response requirements, and SoSafe's 2025 Cybercrime Trends data reveal that a weak point in a bank's defence infrastructure is the people operating within it and the specific capabilities they lack.
Threat judgment: the ability to distinguish between a true exploit risk and noise, to prioritise response under pressure, and to make defensible decisions without full information. This demands critical thinking and decision-making capability that most banks are not training at scale.
AI literacy with an ethics layer: understanding what AI systems can and cannot do, where human oversight is non-negotiable, and how to identify when a tool is being used in ways that create regulatory or reputational exposure. The EU AI Act classifies several banking AI applications as high-risk; the people operating within those systems need more than a click-through compliance module.
Incident leadership: how to communicate clearly and credibly during an active incident, manage a team under time pressure, and maintain stakeholder confidence when information is incomplete. These are leadership and communication skills, not technical ones, and they matter most precisely when the systems are failing.
Shadow AI risk management: the ability to recognise and challenge unauthorised AI use within teams, understand data governance boundaries, and build cultures where people raise concerns rather than quietly workaround controls. This requires psychological safety and managerial capability.
Cross-functional coordination: security incidents move into legal, communications, operations, and compliance simultaneously. The people who bridge those functions and translate between technical and non-technical stakeholders at speed are among the most valuable assets in a bank's defence posture, and among the most undertrained.
What modern AI cyber security demands
DORA requires banks to implement consistent ICT third-party risk management and incident response frameworks. What it cannot mandate is the quality of human judgment inside those frameworks.
A risk register is only as good as the person completing it. An incident response plan depends on the team executing it under pressure. A shadow AI policy is as effective as the managers who know how to apply it without killing the innovation it's trying to govern.
The current mismatch in the finance industry is where the budget goes. Tool investment without human capability building produces better-equipped teams who still make the same judgment errors.
Anthropic has given the financial sector a serious warning. The technical response is already mobilising. The question is whether the human infrastructure - the judgment, the literacy, the leadership capability - will be ready for a more powerful wave of AI tech.
What I firmly believe is that the systems will hold or fail based on the quality of human capability inside them.

We offer a scalable employee training solution. It lets you continuously upskill your people.
Book a call
Related articles

Review by:
Jeroen Kraaijenbrink: How organizations can overcome the honesty gap
Senior leadership and boardroom teams invest heavily in commercial strategies to win market shares. Yet the most important and honest information driving strategy circulates in teams underneath, never making it to the table where decisions are made.Jeroen Kraaijenbrink, Executive Coach and Strategy Consultant at Kraaijenbrink Advisory, has spent years working on what he calls the honesty gap. We sat down with him to understand what the honesty gap actually is, where it lives in organizations, and why fixing it requires a leadership shift.How do you define the honesty gap?There's a narrow definition and a broad one. The broad one is: we have created organizations and systems where it's barely possible to be honest to yourself, about yourself, and honest to other people.Honesty isn't just lying. It's integrity, being authentically connected to other people and being aware of your own emotions and your own biases.The honesty gap, in a narrow sense, is the fact that truth and information don’t travel vertically upwards in a company. It's often hard to speak openly to your manager because it’s become rational not to. Many people have the experience: 'I've tried it once but then I was punished for it, or was ignored, so let it be, never mind.' That's the fascinating part: it's not good for people, it's not good for organizations and yet we somehow keep this system intact.Is it less about individual dishonesty and more about a collective culture?A lot of the most important information going through your company is between people and in conversations. You need to find a way to have an honest conversation, where the things that matter get on the meeting table, not just in the informal circuit. And I think that's pretty rare.A more systematic definition is that we're not using the collective intelligence of a company enough. We can radically improve it because we’ve made it rational to hide the truth and to keep things to yourself. A lot of it may not be intentional, but the very fact that someone is in a position above you automatically creates this tension: 'What do I show? What don't I show? Because my next performance appraisal is coming up.'Where does the honesty gap typically show up first, and who owns the problem?It starts with leaders. Solving it needs one leader at the top, the CEO at least, being open and reflective enough to admit that there is an honesty gap and that they are part of it. That's the self-reflection you need for any improvement and any change. Like in coaching: you need to be aware that there is stuff to improve. You don't need to be a perfect leader, but you need to be open enough to admit that there is an issue.You talk about the 'persona trap', what is that?You're stuck in a persona where you perform in a certain way within your company. You have a role, a position, a reputation, and that locks you into specific behaviors. The worse the match between who you are as a person and how you need to show up in your organization, the more inner conflict that’s created. Especially at the top, it’s a problem for many executives. They're supposed to be the people who know it all and be decisive. While if you're honest, you don't necessarily know everything, you’re uncertain and have anxieties.The inner core of the honesty gap is breaking the performance, breaking the acting you feel you must do. If you've put yourself in a role of being the strong, decisive, number-oriented leader, that's how you have to behave. But most people don't feel very comfortable in that kind of role because it's not who they are.Can you fix the honesty gap through individual coaching alone or does the system have to change?Part of it is a personal change, part of it is a system change. You can be on your own and be very authentic, but if the system doesn't change at all, you’ll struggle to break the honesty gap.What you need to do is work on the people, the culture, and the system. Ideally that has to include the top, because otherwise it stays at the level of the person being coached. If it's a team lead or a mid-manager, that person can partly create an island in the organization, a safe space for their team and their department. But still, the appraisal systems, objectives, and culture are company-wide. Why is this so hard to shift, even when leaders recognize the problem?We have normalized this idea that you have to be strategic in what you tell and what you show. You have to show up in a certain role at work. It's also the result of how we have separated work from life, which is a very unnatural thing. It's from the industrial age, because for any other species, work is life. But now there’s a split between work, with all the routines in companies, and then your private life. There's just one you, you're the same person at home as you are at work. The good news is that the honesty gap can be closed. While many companies have unintentionally created environments where people hesitate to speak openly, organizations prioritizing trust, authenticity, and psychological safety can unlock a competitive advantage. When employees feel safe to share concerns, ideas, and perspectives, collective intelligence grows, decision-making improves, and stronger relationships emerge across every level of the business.
Ready to drive impact together?
Close skill gaps, accelerate growth, and future-proof your workforce.


Frequently Asked Questions
What is Anthropic's Mythos and why does it matter for banks?
Anthropic's Mythos is an AI model capable of identifying critical software vulnerabilities — known as zero-day flaws — across major operating systems and web browsers before defenders are even aware they exist. No European bank was among the first organisations granted access, leaving them exposed at a moment when the cybersecurity threat landscape shifted significantly. For banks, this signals that AI has fundamentally changed the speed and sophistication of cyberattacks.
Why are human skills important for cybersecurity in financial institutions?
Despite rapid advances in detection software and security tooling, 60% of breaches still involve human error - including misconfiguration, poor judgment calls, and unauthorised AI tool use. Technology alone cannot close this gap. The people responsible for managing cyber risk need specific capabilities: the judgment to make decisions under pressure, the literacy to understand AI systems, and the leadership to coordinate an effective response when an incident occurs.
What does DORA require from banks on cybersecurity?
DORA - the EU's Digital Operational Resilience Act - requires financial institutions to implement consistent ICT risk management and incident response frameworks across their operations and third-party suppliers. However, compliance frameworks define what banks must do, not whether the people inside them have the judgment and capability to do it effectively under pressure.
What is shadow AI and why is it a risk for banks?
Shadow AI refers to the unauthorised use of AI tools by employees outside of approved governance frameworks. It creates significant risk in financial institutions because sensitive data can be inadvertently shared with external platforms, creating regulatory exposure, data leakage, and compliance failures. Managing this risk requires managerial capability and a culture where employees feel safe raising concerns - not just IT policy.
What are the most important human skills banks should train for cybersecurity?
Based on ECB supervisory findings, DORA requirements, and SoSafe's 2025 Cybercrime Trends data, the five most critical human capabilities are: threat judgment, AI literacy with an ethics layer, incident leadership, shadow AI risk management, and cross-functional coordination. These are leadership and decision-making skills as much as technical ones.
How is AI changing the cybersecurity threat landscape for financial institutions?
AI has dramatically lowered the barrier for cyberattacks. It can now reverse-engineer software patches within minutes of their release, collapsing the window between a vulnerability being fixed and being exploited. This means even unskilled criminal actors can mount sophisticated attacks against banks more cheaply and easily than before. 87% of global organisations experienced an AI-powered cyberattack in the past year, according to SoSafe's 2025 Cybercrime Trends report.

.webp)
.webp)
.webp)