The financial services sector is becoming more connected, and so are its cyber risks. Banks, insurers, and asset managers increasingly operate as part of an interconnected system of platforms and partners, expanding both the potential points of exposure and scale of disruption. For firms that provide critical services and depend on customer trust, cybersecurity is integral to operational resilience.
Cyber investments are rising as firms adapt to a world of moving targets. They’re driven by simultaneous shifts in technology, threats, and geopolitics. Eighty-two percent of security and finance leaders in the sector expect their cyber budgets to increase. Security leaders rank AI among their top cyber investment priorities (56%), followed by network security and zero trust (41%) and data protection and trust (40%).
AI is reshaping both the threat landscape and the sector’s cyber priorities. Among security leaders in financial services, 51% rank attacks targeting AI systems among the top cyber threats their organizations are least prepared to address, while 48% rank securing against AI-enabled attacks among their top cyber spend priorities. The leading areas where firms are prioritizing use of AI for cyber defense are threat detection and alerting and fraud detection.
Geopolitical shifts are putting third-party dependencies in sharper focus. Nearly half (49%) of financial services organizations are changing vendor, third-party, and supply chain risk strategies, while 51% of security, risk, and data leaders plan to adopt multi-cloud or hybrid cloud environments to address concentration risk.
Together, these technology, geopolitical, and third-party pressures reinforce the need for financial services firms to embed cybersecurity more consistently into business decisions and operations. Building this enterprise-wide capability can help firms strengthen resilience, make better-informed decisions, and adapt as risks evolve.
Drawing on PwC’s 2027 Global Digital Trust Insights survey, this report highlights how 830 global leaders across banking and capital markets, insurance, and asset and wealth management, are confronting these challenges. It explores how financial services leaders are managing cybersecurity in a rapidly evolving digital environment and where critical gaps remain.
Banking and capital markets (BCM) organizations are pursuing an ambitious modernization agenda, with AI and data central to how they operate, compete, and grow. But as firms embed modern tech across the enterprise and become more reliant on cloud, software suppliers, and other third parties, the cyber implications of that transformation are growing.
AI leads BCM cyber investment priorities for the coming year, with 60% of security leaders ranking it among their top focus areas. Cloud security and network security/zero trust follow at 41% each. But investment alone doesn’t translate into resilience. As tech environments become both more interconnected and more porous, the challenge is understanding and focusing cybersecurity where the business is most exposed.
The BCM threat landscape is expanding in lockstep with the technologies transforming the sector. Emerging tech is creating new sources of exposure while longstanding issues around data protection and third-party risk remain firmly in view.
As BCM organizations pursue an ambitious tech agenda, cybersecurity needs to move in lockstep. That means using insights on emerging threats to shape the foundations of modernization—from trusted data and AI governance to visibility across the ecosystem—so they can innovate securely.
Insurance has always been about understanding risk. What’s changing is how quickly insurers can identify it and what they can do about it. AI, connected devices, and new sources of data are helping insurers move from primarily assessing and compensating for losses toward anticipating risk and, in some cases, helping prevent losses before they occur.
This is changing insurer risk profiles. More data, connected tech, cloud environments, and external partners create more opportunities for innovation but also bring more systems, access points, and relationships to safeguard. Cyber investment is rising accordingly, and 86% of security and finance leaders expect their cyber budgets to increase, compared with 82% across financial services overall. AI is a leading investment focus, with 50% of security leaders ranking it among their top priorities, followed closely by network security and zero trust (47%).
Innovation is changing both sides of the risk equation for insurers. AI is creating new targets and new tools for attackers, while insurer reliance on third parties and connected tech is putting greater pressure on preparedness and continuity. Frontier AI is giving threat actors new ways to discover and exploit vulnerabilities and scale attacks.
The opportunity for insurers is to do for themselves what they’re offering policyholders: getting ahead of risk. Building a more intelligent enterprise can help you anticipate new exposures and act before they become bigger problems.
The rapid growth of digital assets like cryptocurrency and tokenized assets is changing what AWM firms offer and how investors interact with them. AI is accelerating this transformation, changing how firms operate and serve clients. As firms become more dependent on technology and external providers, understanding where cyber risk is concentrated across those relationships becomes more difficult and important.
Against that backdrop, cyber investment is rising, but not as widely as elsewhere in financial services. Seventy-seven percent of AWM security and finance leaders expect their cyber budgets to increase, below the industry average of 82%. AI leads AWM cyber investment priorities, with 60% of security leaders placing it among their top priorities, followed by data protection and trust at 47%. Fifty-five percent of AWM security leaders rank AI among their top managed security service priorities, followed by identity and access management (43%) and cloud security (42%).
For AWM firms, using technology to improve efficiency, utilize digital assets, and differentiate the client experience is adding complexity to their security challenges. While AI is creating some of the sector’s largest preparedness gaps, long-standing issues in credential theft remain a prevalent attack path and reliance on third-party providers makes risk across the broader ecosystem more difficult to detect.
With industry-wide pressure on costs and profitability, AWM firms will likely need to focus their cyber budget spending on their most urgent needs.