Bitsight Recognized as a Visionary in 2026 Gartner® Magic Quadrant™ for Cyber Threat Intelligence Technologies
Get the report and see why Bitsight was named a Visionary.
AI is compressing the cybersecurity timeline faster than most institutions can adapt to it. Not only do security leaders have to deal with this new reality, they have to answer key questions to internal and external audiences about their efforts — including regulators.
A new letter from European Central Bank Banking Supervision requires institutions under its direct supervision (i.e. major European financial institutions) to submit an action plan addressing AI-enabled cybersecurity threats by October 31, 2026. The action plan must identify concrete measures, allocate the necessary resources, assign clear roles and responsibilities, and establish timelines for implementation. It must also build on the institution’s existing cyber risk strategy and be submitted to its respective Joint Supervisory Team.
This is not a replacement for DORA — the European Central Bank (ECB) makes that explicit. What it is, in our view, is a pointed question to every bank under its supervision: is your existing cybersecurity and operational resilience program actually built for a threat landscape that's becoming faster, broader, and more automated?
The ECB warns that emerging AI models can identify software vulnerabilities and generate functioning exploits at unprecedented speed. This compresses the time between vulnerability discovery and exploitation and gives defenders less time to identify affected systems, prioritize remediation, test patches, and deploy fixes. The European Systemic Risk Board issued a related warning on the same day. It found that frontier AI models could increase the speed, scale, and sophistication of cyberattacks. While these models may eventually strengthen cyber defense, the ESRB believes threat actors may hold an advantage in the short to medium term. That shift is already beginning to appear in real-world attacks. Sysdig recently documented JADEPUFFER, which it assessed as the first end-to-end LLM-driven ransomware operation, with the AI agent adapting when attack steps failed and carrying the operation through to database extortion.
Vulnerabilities have been around forever. What's changed is how fast attackers can now identify, weaponize, and scale attacks across more targets. Incomplete asset inventories, internet-facing legacy systems, slow patching processes, and poorly understood third-party dependencies all become far more dangerous once the remediation window starts to shrink.
The ECB’s expectations cover both immediate actions and longer-term improvements. In the short term, institutions are expected to protect their most exposed attack surfaces, accelerate vulnerability and patch management, improve monitoring and detection, evaluate AI-enabled defensive capabilities, and make sure third-party risk management is still fit for purpose.
The letter also calls for stronger governance, appropriate funding and staffing, updated training, supply chain assurance, defense-in-depth, infrastructure modernization, tested recovery capabilities, crisis management, and secure information sharing. This can’t sit with one security team or depend on one tool. It requires coordination across security, IT, third-party risk, operational resilience, risk management, and executive leadership. We observe that many organizations are developing internal committees and/or task forces with the goal of coordinating an inter-organizational response to the myriad challenges associated with AI cyber risk.
The ECB specifically calls on institutions to identify and continuously monitor internet-facing and externally exposed assets, including cloud environments, VPN connections, third-party software, and open-source components. That visibility can’t depend entirely on an internal asset inventory. Cloud services may be deployed outside normal processes. Subsidiaries may manage infrastructure that central security teams can’t fully see. Systems believed to be retired may still be accessible from the internet. Financial institutions need to understand what an attacker can actually see from the outside, not just what internal records say should be there.
This is exactly where Bitsight helps. We help organizations continuously discover and monitor internet-facing assets, cloud infrastructure, VPNs, exposed services, and risky software, creating an outside-in view of the attack surface so teams can identify unknown or unmanaged exposures before they become an attacker's entry point.
AI may increase both the speed and volume of vulnerability discovery. This underscores the importance of prioritization. The ECB recommends prioritized vulnerability scanning, adequate staffing, faster risk-based remediation, and change-management processes that allow critical fixes to be deployed without creating unnecessary operational disruption. It also notes that patching expectations should be reflected in contracts and service-level agreements when an ICT provider is responsible for the affected technology. Severity scores alone don’t provide enough context. Financial institutions need to know whether a vulnerability is present on an asset they actually operate, whether that asset is externally exposed, how critical it is to the business, and whether attackers are actively targeting or discussing the vulnerability.
Bitsight connects vulnerability information to the organization’s real external attack surface and adds adversary context to help teams prioritize the exposures most likely to create risk. This helps teams determine which risks need attention first.
Financial institutions rely on cloud providers, software vendors, managed service providers, payment platforms, data processors, and other ICT suppliers to support critical operations.
The ECB makes it clear that institutions remain accountable for risks arising from outsourced ICT services. Organizations should assess whether critical providers are prepared for faster vulnerability disclosure and patching and whether current third-party risk processes can keep up with the changing threat landscape.
Several critical providers may rely on the same software product, cloud platform, or open-source component. A single vulnerability or disruption could therefore affect multiple vendors and business services at the same time. Questionnaires and periodic assessments still have value, but they only capture a moment in time. They may not show that a provider’s security posture has deteriorated, that a new service has become exposed, or that several important vendors share the same vulnerable dependency.
Bitsight helps institutions continuously monitor critical ICT providers and identify shared dependencies that may create concentrated risk across the vendor ecosystem.
Institutions must be able to explain what risks they identified, what actions they will take, what resources are required, who owns each action, and when the work will be completed. Joint Supervisory Teams will then engage with the banks and monitor their progress. The ECB also plans to analyze the submitted action plans horizontally to identify common challenges and areas for improvement.
These are practical examples rather than a formal ECB checklist, but they're a useful way to turn the action plan into something measurable.
Bitsight provides continuous external data and evidence-ready reporting that can support action planning, board discussions, remediation tracking, and engagement with supervisory teams.
The ECB also calls on institutions to replace or update legacy, unsupported, and end-of-life technologies. Where replacement is not immediately possible, banks should apply additional controls to protect the affected systems. Banks should understand where these technologies exist, whether they are exposed, which critical services rely on them, and what will be done to reduce the risk. The action plan should distinguish between systems that can be upgraded quickly, systems that require longer modernization projects, and systems that need compensating controls until replacement is possible.
The ECB expects banks to maintain tested incident response, crisis management, backup, failover, restoration, and recovery arrangements aligned with DORA. It specifically recommends exercises involving high-speed and high-volume attacks, zero-day vulnerabilities, ransomware, destructive attacks, and supply chain or cloud disruption. These exercises should be informed by the organization’s real attack surface and threat environment. A ransomware exercise is more useful when it reflects the technologies the bank actually exposes, the providers it depends on, the weaknesses present in its environment, and the adversaries most likely to target it.
Meeting the European Central Bank’s expectations requires more than one security control or one team. Banks need visibility across their own infrastructure, their third parties, their vulnerabilities, and the threats targeting them. They also need a way to prioritize action, track progress, and communicate risk to leadership and supervisory teams.
We bring these areas together through Bitsight Cyber Risk Intelligence.
Together, these capabilities help financial institutions move from disconnected findings to a more complete view of their attack surface, exposures, third parties, and threats, with the business context needed to prioritize action and support the ECB response.
The immediate task is to submit an action plan by October 31. The larger challenge (the one we care about) is building a security program that can continue to operate as AI accelerates vulnerability discovery, exploitation, and attack automation.
That starts with four questions:
Financial institutions that can answer those questions with current, defensible data will be in a stronger position to meet the ECB’s expectations and respond to a threat landscape that is not slowing down.
Get the report and see why Bitsight was named a Visionary.