AI is compressing the cybersecurity timeline faster than most institutions can adapt to it. Not only do security leaders have to deal with this new reality, they have to answer key questions to internal and external audiences about their efforts — including regulators.
A new letter from European Central Bank Banking Supervision requires institutions under its direct supervision (i.e. major European financial institutions) to submit an action plan addressing AI-enabled cybersecurity threats by October 31, 2026. The action plan must identify concrete measures, allocate the necessary resources, assign clear roles and responsibilities, and establish timelines for implementation. It must also build on the institution’s existing cyber risk strategy and be submitted to its respective Joint Supervisory Team.
This is not a replacement for DORA — the European Central Bank (ECB) makes that explicit. What it is, in our view, is a pointed question to every bank under its supervision: is your existing cybersecurity and operational resilience program actually built for a threat landscape that's becoming faster, broader, and more automated?
AI is changing the cyber clock
The ECB warns that emerging AI models can identify software vulnerabilities and generate functioning exploits at unprecedented speed. This compresses the time between vulnerability discovery and exploitation and gives defenders less time to identify affected systems, prioritize remediation, test patches, and deploy fixes. The European Systemic Risk Board issued a related warning on the same day. It found that frontier AI models could increase the speed, scale, and sophistication of cyberattacks. While these models may eventually strengthen cyber defense, the ESRB believes threat actors may hold an advantage in the short to medium term. That shift is already beginning to appear in real-world attacks. Sysdig recently documented JADEPUFFER, which it assessed as the first end-to-end LLM-driven ransomware operation, with the AI agent adapting when attack steps failed and carrying the operation through to database extortion.
Vulnerabilities have been around forever. What's changed is how fast attackers can now identify, weaponize, and scale attacks across more targets. Incomplete asset inventories, internet-facing legacy systems, slow patching processes, and poorly understood third-party dependencies all become far more dangerous once the remediation window starts to shrink.
This is about more than patching faster
The ECB’s expectations cover both immediate actions and longer-term improvements. In the short term, institutions are expected to protect their most exposed attack surfaces, accelerate vulnerability and patch management, improve monitoring and detection, evaluate AI-enabled defensive capabilities, and make sure third-party risk management is still fit for purpose.
The letter also calls for stronger governance, appropriate funding and staffing, updated training, supply chain assurance, defense-in-depth, infrastructure modernization, tested recovery capabilities, crisis management, and secure information sharing. This can’t sit with one security team or depend on one tool. It requires coordination across security, IT, third-party risk, operational resilience, risk management, and executive leadership. We observe that many organizations are developing internal committees and/or task forces with the goal of coordinating an inter-organizational response to the myriad challenges associated with AI cyber risk.
What is exposed?
The ECB specifically calls on institutions to identify and continuously monitor internet-facing and externally exposed assets, including cloud environments, VPN connections, third-party software, and open-source components. That visibility can’t depend entirely on an internal asset inventory. Cloud services may be deployed outside normal processes. Subsidiaries may manage infrastructure that central security teams can’t fully see. Systems believed to be retired may still be accessible from the internet. Financial institutions need to understand what an attacker can actually see from the outside, not just what internal records say should be there.
This is exactly where Bitsight helps. We help organizations continuously discover and monitor internet-facing assets, cloud infrastructure, VPNs, exposed services, and risky software, creating an outside-in view of the attack surface so teams can identify unknown or unmanaged exposures before they become an attacker's entry point.
What should we fix first?
AI may increase both the speed and volume of vulnerability discovery. This underscores the importance of prioritization. The ECB recommends prioritized vulnerability scanning, adequate staffing, faster risk-based remediation, and change-management processes that allow critical fixes to be deployed without creating unnecessary operational disruption. It also notes that patching expectations should be reflected in contracts and service-level agreements when an ICT provider is responsible for the affected technology. Severity scores alone don’t provide enough context. Financial institutions need to know whether a vulnerability is present on an asset they actually operate, whether that asset is externally exposed, how critical it is to the business, and whether attackers are actively targeting or discussing the vulnerability.
Bitsight connects vulnerability information to the organization’s real external attack surface and adds adversary context to help teams prioritize the exposures most likely to create risk. This helps teams determine which risks need attention first.
Which third parties increase our risk?
Financial institutions rely on cloud providers, software vendors, managed service providers, payment platforms, data processors, and other ICT suppliers to support critical operations.
The ECB makes it clear that institutions remain accountable for risks arising from outsourced ICT services. Organizations should assess whether critical providers are prepared for faster vulnerability disclosure and patching and whether current third-party risk processes can keep up with the changing threat landscape.
Several critical providers may rely on the same software product, cloud platform, or open-source component. A single vulnerability or disruption could therefore affect multiple vendors and business services at the same time. Questionnaires and periodic assessments still have value, but they only capture a moment in time. They may not show that a provider’s security posture has deteriorated, that a new service has become exposed, or that several important vendors share the same vulnerable dependency.
Bitsight helps institutions continuously monitor critical ICT providers and identify shared dependencies that may create concentrated risk across the vendor ecosystem.