Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Major banks to rethink cyber playbooks

Bank leaders are rewriting their cyber playbooks as new threats and technologies, such as AI, dramatically alter the cyber landscape.

Tue, 28 Jul 2026
Major banks to rethink cyber playbooks

As full-year results quickly approach for the Aussie big four banks, discussions on how the organisations will protect themselves and their customers from the rising wave of AI-powered cyber threats are heating up.

Where previously, the largest threats faced by banks were credit, conduct, and market risk, cyber crime is increasingly becoming a priority for bank boards, with these organisations being ideal targets due to the wealth of data and funds they hold, as well as the role they play in critical day to day operations.

While these organisations are heavily investing in AI and getting their hands on new tools such as Anthropic’s Mythos, boards are rightfully wary that threat actors are gaining access to the same technologies.

 
 

These models are discovering vulnerabilities previously thought to not exist, some of which have existed for as long as a decade or more.

As reported by The Australian Financial Review, cyber organisations, such as Palo Alto Networks, are already shifting their responses to better tailor them to an AI-powered cyber crime environment.

“Crisis response used to plan for the first 24 to 48 hours, but now we’re down to the first hour,” said Palo Alto’s vice president for policy and government affairs, Nicole Quinn.

“You can’t afford to wait for all the board members to join a call, or for senior leaders to get on Zoom. You need a pre-agreed response plan, approved by the board and CEO, so security teams can just pull the trigger.”

Banks are considering lowering times, too, by shifting response decisions and approval away from senior executives and towards staff closer to operations.

Currently, waiting for board approval for a response could take a day longer if executives are unavailable. With AI-powered cyber crime, businesses do not have that long.

Palo Alto’s Unit 42 division is advising banks on how to change their cyber playbooks and highlighting how quickly it’s seeing vulnerabilities exploited.

Originally, a software vulnerability would take nine days to be exploited, and then, from last year, that dropped to three hours. Now, threat actors are abusing them within 25 minutes.

Mythos is also a game changer for organisations looking to plug holes in their systems and defences, able to identify vulnerabilities at record speeds, as well as chain them together to identify potential attack paths.

“Mythos picked up in weeks what would have taken our best penetration-testing teams about 12 months,” Quinn said.

Anthropic said Mythos would not be publicly released due to the danger it presents in the wrong hands. However, this left banks and other organisations scrambling to defend.

Australian banks, while increasing their focus on cyber, don’t rank at the top globally for preparedness, according to Oliver Wyman’s New York-based partner, Rico Brandenburg.

“Australia is in the middle of the pack on this,” he said.

“The rules [that corporate and banking regulations] have put in place are a good starting point, to make sure cyber is at the top of executives’ minds. It’s now up to institutions to use regulatory guidance and reduce exposures and accelerate strategic uplift.”

The Australian Prudential Regulation Authority (APRA) is also urging banks to think more about cyber security, and share cyber insights.

Following restrictions on foreign frontier AI models such as Mythos due to overseas bans, APRA has asked major lenders to share tools and insights with smaller rivals, in a letter sent to all banks on 30 April.

APRA executive board member Therese McCarthy Hockey warned that Australia was “entering a dangerous period in the AI revolution”, adding that it was confident that “frontier AI presents a paradigm shift.

“For Australian financial institutions, frontier AI is not just a cyber risk issue. It’s a third-party risk, a concentration risk and a sovereign access risk. A critical business process, control or cyber defence capability that depends on a single offshore frontier AI model may be disrupted not only by an outage or cyber incident but by a regulatory decision made overseas,” she said

In the letter, APRA said boards did not have the literacy needed to combat AI risks and oversight, and AI governance was not keeping up with adoption.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags:

Daniel Croft

Born in the heart of Western Sydney, Daniel Croft is a passionate journalist with an understanding for and experience writing in the technology space. Having studied at Macquarie University, he joined Momentum Media in 2022, writing across a number of publications including Australian Aviation, Cyber Security Connect and Defence Connect. Outside of writing, Daniel has a keen interest in music, and spends his time playing in bands around Sydney.