Global Digital Trust Insights

2027 cybersecurity outlook: Financial services

Hero Image
  • Insight
  • October 01, 2026

Explore the issues global leaders across financial services face, the threats they feel least prepared to handle, what’s driving security investments, and how emerging technologies are shaping their approach to cybersecurity.

No. 1

priority for AI in cyber defense is threat detection and alerting

No. 1

cyber threat that financial services firms are least prepared for is attacks targeting AI systems

49 %

are changing third-party and supply chain risk management strategies in response to geopolitics

Key takeaways:

  • Cyber risk is increasing as financial services becomes more interconnected. Greater reliance on cloud, software suppliers, and third-party ecosystems is expanding exposure and increasing the potential for disruption to critical services.
  • AI is both the leading cyber investment priority and the sector’s largest preparedness gap. Firms are investing in AI-enabled defense, yet attacks targeting AI systems rank as the threat financial services organizations feel least prepared to address.
  • AI is intensifying established risks such as fraud, identity compromise, and software exploitation. Deepfakes, synthetic identities, autonomous botnets, and AI-enabled vulnerability discovery are making familiar threats easier to scale.
  • Third-party resilience depends on understanding concentration across the ecosystem. Multi-cloud strategies and stronger supplier controls can help, but firms still need greater visibility into shared providers, infrastructure, and software dependencies.
  • Cybersecurity needs to advance alongside business transformation. Firms should embed security into AI adoption and modernization, strengthen data and identity foundations, and test whether critical services can withstand and recover from disruption.

The financial services sector is becoming more connected, and so are its cyber risks. Banks, insurers, and asset managers increasingly operate as part of an interconnected system of platforms and partners, expanding both the potential points of exposure and scale of disruption. For firms that provide critical services and depend on customer trust, cybersecurity is integral to operational resilience.

Cyber investments are rising as firms adapt to a world of moving targets. They’re driven by simultaneous shifts in technology, threats, and geopolitics. Eighty-two percent of security and finance leaders in the sector expect their cyber budgets to increase. Security leaders rank AI among their top cyber investment priorities (56%), followed by network security and zero trust (41%) and data protection and trust (40%).

AI is reshaping both the threat landscape and the sector’s cyber priorities. Among security leaders in financial services, 51% rank attacks targeting AI systems among the top cyber threats their organizations are least prepared to address, while 48% rank securing against AI-enabled attacks among their top cyber spend priorities. The leading areas where firms are prioritizing use of AI for cyber defense are threat detection and alerting and fraud detection.

Geopolitical shifts are putting third-party dependencies in sharper focus. Nearly half (49%) of financial services organizations are changing vendor, third-party, and supply chain risk strategies, while 51% of security, risk, and data leaders plan to adopt multi-cloud or hybrid cloud environments to address concentration risk. 

Together, these technology, geopolitical, and third-party pressures reinforce the need for financial services firms to embed cybersecurity more consistently into business decisions and operations. Building this enterprise-wide capability can help firms strengthen resilience, make better-informed decisions, and adapt as risks evolve.

Drawing on PwC’s 2027 Global Digital Trust Insights survey, this report highlights how 830 global leaders across banking and capital markets, insurance, and asset and wealth management, are confronting these challenges. It explores how financial services leaders are managing cybersecurity in a rapidly evolving digital environment and where critical gaps remain.

Banking and capital markets

Banking and capital markets (BCM) organizations are pursuing an ambitious modernization agenda, with AI and data central to how they operate, compete, and grow. But as firms embed modern tech across the enterprise and become more reliant on cloud, software suppliers, and other third parties, the cyber implications of that transformation are growing.

AI leads BCM cyber investment priorities for the coming year, with 60% of security leaders ranking it among their top focus areas. Cloud security and network security/zero trust follow at 41% each. But investment alone doesn’t translate into resilience. As tech environments become both more interconnected and more porous, the challenge is understanding and focusing cybersecurity where the business is most exposed.

The threat landscape

The BCM threat landscape is expanding in lockstep with the technologies transforming the sector. Emerging tech is creating new sources of exposure while longstanding issues around data protection and third-party risk remain firmly in view.

  • AI threats are expanding: When asked about the AI-enabled attacks their businesses are least prepared to address, 55% of BCM security and risk leaders ranked adversarial attacks among the top, followed by data poisoning (53%). BCM firms also show heightened gaps in preparedness for attackers using AI for “vulnerability identification and exploit development” (46%) and synthetic identity fraud (46%)—two threats that rank high for BCM but not for the broader financial services sector. For BCM firms, these risks span both the AI systems supporting modernization and the potential for attackers to use AI across highly connected operations.
  • Cyber investment focuses on AI: As BCM firms prepare to increase cyber spending, they’re prioritizing both “responsible AI governance and compliance” with 44% of security leaders ranking it among their top priorities, and cyber defenses, including SOC/incident response (38%), platform hardening (37%), and application security (37%). The combination reflects the need to govern AI while strengthening the environments in which it operates.
  • Still not preparing for quantum: Although quantum computing is the second-highest-ranked cyber threat that BCM firms are least prepared to address, just 2% include quantum readiness among their top three cyber budget priorities this year. The disconnect suggests more immediate cyber demands are taking precedence.
  • Software supply chains widen exposure: Software supply chain compromise ranks as a more prominent threat among BCM firms than the broader financial services sector. Their heightened concern is reflected in planned changes to manage supply chain cyber risk. Fifty-three percent of security, risk, and operations leaders plan to implement continuous monitoring of supplier cyber risk, 47% are strengthening security software pipelines, and 43% are tightening contractual security requirements.
  • Trust in autonomous AI agents must be earned: Just 21% of BCM firms would authorize AI agents to execute defensive maneuvers without human approval. AI accountability, explainability, and liability concerns remain barriers to increasing autonomous AI use in cybersecurity. It’s no surprise then that security leaders say they opt to use agents in well-defined, repeatable activities. Forty-five percent of security leaders ranked phishing email quarantine or deletion among their top activities, followed by threat intelligence enrichment and correlation at 42%, suggesting autonomy will advance first where actions and outcomes are easier to govern.

The cybersecurity agenda

As BCM organizations pursue an ambitious tech agenda, cybersecurity needs to move in lockstep. That means using insights on emerging threats to shape the foundations of modernization—from trusted data and AI governance to visibility across the ecosystem—so they can innovate securely.

  • Build trust into AI from the start: Expand governance to keep pace with the autonomy of your firm’s AI agents. Establish clear decision rights, accountability, human oversight, and controls for how AI and autonomous agents access your firm’s data and interact with its systems.
  • Strengthen your data foundation: Secure and govern critical data through consistent discovery, classification, access controls, and monitoring across the enterprise. Bring cyber risk data into a more connected view across your organization to support better decisions and spot emerging risks.
  • See and manage risk across the ecosystem: Map the software, cloud, and third-party dependencies supporting critical operations. Move toward continuous monitoring of critical suppliers and software supply chains with clear security expectations and an understanding of where concentration could create operational risk.
  • Extend capacity through automation and managed services: Be deliberate about where internal cyber capability adds the most value and where other resources can take on more of the load. Consider managed security services for specialized or resource-intensive capabilities while using autonomous agents for well-defined, repeatable activities where appropriate controls are in place.
  • Design for disruption: Build resilience around the services your business needs to keep running. Map the tech, data, and third parties that support critical operations, determine recovery approaches, and test how your organization will respond when those dependencies are disrupted.

Insurance

Insurance has always been about understanding risk. What’s changing is how quickly insurers can identify it and what they can do about it. AI, connected devices, and new sources of data are helping insurers move from primarily assessing and compensating for losses toward anticipating risk and, in some cases, helping prevent losses before they occur.

This is changing insurer risk profiles. More data, connected tech, cloud environments, and external partners create more opportunities for innovation but also bring more systems, access points, and relationships to safeguard. Cyber investment is rising accordingly, and 86% of security and finance leaders expect their cyber budgets to increase, compared with 82% across financial services overall. AI is a leading investment focus, with 50% of security leaders ranking it among their top priorities, followed closely by network security and zero trust (47%).

The threat landscape

Innovation is changing both sides of the risk equation for insurers. AI is creating new targets and new tools for attackers, while insurer reliance on third parties and connected tech is putting greater pressure on preparedness and continuity. Frontier AI is giving threat actors new ways to discover and exploit vulnerabilities and scale attacks.

  • AI raises the stakes for fraud and cyber defense: Attacks targeting AI systems are the cyber threat insurers feel least prepared to address, with 51% of security leaders ranking them among their top threats. Among AI-enabled attacks, security and risk leaders rank compromise by autonomous botnets (57%) and deepfake fraud (52%) among the top threats they face. These findings point to risks both within insurer AI systems and from attackers using AI to scale fraud and disruption.
  • Third-party dependencies test resilience: Forty-one percent of security leaders rank third-party breach among the top threats their organizations are least prepared to address. Although 62% of security, data, and risk leaders are adopting multi-cloud or hybrid cloud environments to address concentration risk, insurers still face practical challenges in moving services between providers and holding them to agreed service levels. Among insurance security, risk, and operations leaders in our survey, 57% rank developing viable exit or portability plans among their greatest challenges, while 52% point to enforcing contractual service level agreements.
  • Data protection drives spend, but risks persist: Data protection and trust is the leading influence on cyber spending, but implementation remains uneven. About half of insurers report having data classification policies implemented across the organization, while only 30% are using data quality capabilities firm-wide. This limits their ability to build the trusted data foundation needed for AI and other advanced cyber capabilities.
  • Continuity capability is not keeping pace with dependency: Just 37% of security, risk, and operations leaders have fully formalized and integrated operational continuity plans that specifically address cybersecurity threats. As dependencies on cloud, suppliers, and connected technology grow, incomplete planning increases the potential impact of disruption on critical operations.
  • Hesitancy persists around AI autonomy: Only 18% of insurance security leaders would authorize AI agents to execute defensive actions without human approval, the lowest across financial services. Leaders say they’re more comfortable delegating defined activities such as “threat intelligence enrichment and correlation” and phishing email quarantine (47% each), while concerns about the reliability and maturity of current AI technology (58%) and workforce skills gaps (46%) constrain broader use.

The cybersecurity agenda

The opportunity for insurers is to do for themselves what they’re offering policyholders: getting ahead of risk. Building a more intelligent enterprise can help you anticipate new exposures and act before they become bigger problems.

  • Prepare defenses for AI-enabled attacks: Strengthen identity and access controls and use behavioral and anomaly detection to identify threats that traditional approaches might miss.
  • Put AI trust before agent autonomy: Insurer caution around autonomous cyber defense offers a logical starting point. Use agents first for bounded, repeatable activities where risks can be controlled and results readily assessed. As the technology matures, strengthen governance, accountability, and human oversight to expand autonomy with confidence.
  • Get ahead of third-party dependencies: Map the tech providers and services supporting your critical operations and identify where concentration creates vulnerability. Continuously monitor critical providers, strengthen contractual requirements, and establish viable exit plans to identify changing risks earlier and prepare for disruption of critical providers.
  • Turn continuity plans into operational capability: Move beyond documented plans to regularly testing how your critical services would withstand and recover from cyber disruption. Account for all systems in your exercises, including cloud, supplier, and partner dependencies.

Asset and wealth management

The rapid growth of digital assets like cryptocurrency and tokenized assets is changing what AWM firms offer and how investors interact with them. AI is accelerating this transformation, changing how firms operate and serve clients. As firms become more dependent on technology and external providers, understanding where cyber risk is concentrated across those relationships becomes more difficult and important.

Against that backdrop, cyber investment is rising, but not as widely as elsewhere in financial services. Seventy-seven percent of AWM security and finance leaders expect their cyber budgets to increase, below the industry average of 82%. AI leads AWM cyber investment priorities, with 60% of security leaders placing it among their top priorities, followed by data protection and trust at 47%. Fifty-five percent of AWM security leaders rank AI among their top managed security service priorities, followed by identity and access management (43%) and cloud security (42%).

The threat landscape

For AWM firms, using technology to improve efficiency, utilize digital assets, and differentiate the client experience is adding complexity to their security challenges. While AI is creating some of the sector’s largest preparedness gaps, long-standing issues in credential theft remain a prevalent attack path and reliance on third-party providers makes risk across the broader ecosystem more difficult to detect.

  • AI creates an outsized preparedness gap: Nearly two-thirds (64%) of the AWM security leaders in our survey rank attacks targeting AI systems among the top cyber threats they’re least prepared to address, a more pronounced concern than elsewhere in financial services. Asked separately about AI-enabled attacks, 55% of security and risk leaders rank both “autonomous botnets” and “adaptive malware” among their leading preparedness gaps. The findings place AI risk at the center of AWM security priorities, spanning both the systems firms deploy and the threats they face.
  • Verifying client identities has become harder: Forty-three percent of security and risk leaders rank deepfake audio or video fraud among the top AI-enabled threats their firms are least prepared to address, followed by synthetic identity fraud (41%) and credential stuffing or account takeover (26%). Although identity-based attacks have been a long-standing sector risk, AI is making impersonation easier and cheaper to execute at scale.
  • Third-party concentration has a visibility problem: Third-party breaches rank among the top threats that security leaders feel least prepared to address. Although AWM firms are building redundancy and adopting multi-cloud or hybrid cloud strategies, 49% of security, risk, and operations leaders cite a lack of visibility into vendor risk as a leading challenge. These blind spots obscure shared dependencies across third-party services, where a single disruption could affect multiple critical operations.
  • AI investment is putting the supply chain in focus: Forty-two percent (42%) of security leaders rank supply chain security among their top AI-related cyber investment priorities, followed by platform hardening (38%) and observability and monitoring (38%). These priorities reflect the need to secure the broader technology and provider ecosystem supporting the business.

The cybersecurity agenda

With industry-wide pressure on costs and profitability, AWM firms will likely need to focus their cyber budget spending on their most urgent needs.

  • Prioritize AI security: Secure the data feeding your AI systems, strengthen access controls, test for vulnerabilities, and monitor for manipulation or unexpected behavior.
  • Get a clearer view of concentration risk: Treat vendor concentration like an attacker would. Simulate the paths and shared infrastructure that could let a single incident cascade across multiple "independent" vendors. Supplement third-party self-attestations with independent, always-on signals such as attack surface scans, infrastructure fingerprinting, and financial/news monitoring to verify actual vendor dependencies and catch risk in real time.
  • Safeguard the data behind the business: Strengthen governance and controls around sensitive client and investment data, particularly as more of that data is accessed and used by AI-enabled applications.
  • Use managed services strategically: Use external professionals who can provide specialized capabilities or scale, while keeping accountability for cyber risk and critical decisions within your organization.

The 2027 Global Digital Trust Insights survey captured the views of 3,934 business and technology leaders and was conducted in May through July 2026.

More than one-third of the executives (36%) are from large companies with $5 billion or more in revenue. Respondents operate in a range of industries, including financial services (21%); industrial manufacturing and automotive (19%); tech, media and telecom (20%); retail and consumer markets (16%); healthcare (10%); energy, utilities and resources (10%); and government and public services (3%).

Respondents are based in 71 countries. The regional breakdown of responses is Western Europe (32%), North America (26%), Asia Pacific (18%), Latin America (12%), Central and Eastern Europe (4%), Africa (5%), and the Middle East (3%).

The Global Digital Trust Insights survey was previously known as the Global State of Information Security Survey (GSISS). Now in its 29th year, it’s the longest-running annual survey on cybersecurity trends. It’s also one of the largest surveys in the cybersecurity industry and the only one that draws participation from senior business leaders, not just security and technology leaders.

PwC Research, PwC’s global Centre of Excellence for market research and insight, conducted this survey.

Moving targets: Cybersecurity in a dynamic digital world

Findings from the 2027 Global Digital Trust Insights

Contact us

Amandeep Lamba

Amandeep Lamba

Principal, Cyber, Data & Tech Risk, PwC US

Gavin Mead

Gavin Mead

Partner, Cyber, Data, and Tech Risk, PwC US

Joseph Krause

Joseph Krause

Principal, Cyber, Data & Tech Risk, PwC US

Matthew Wilson

Matthew Wilson

Principal, Cyber, Data & Tech Risk, PwC US

Follow us