Posted inAnalysis

QuantumGate’s CTO: Financial Cyber Resilience is a Foundations Problem 

UAE and ECB cyber rules put accountability, AI threats and post-quantum cryptography at the heart of banks’ security priorities says Janne Hirvimies, CTO, QuantumGate.

Janne Hirvimies, CTO, QuantumGate 
Janne Hirvimies, CTO, QuantumGate 

This month, two regulatory actions, taken days apart, pointed to the same priority.

On 3 July, the UAE Cyber Security Council announced it had detected and contained a wave of sophisticated attacks targeting financial-sector entities, urging institutions to strengthen preventive controls and keep systems current.

Five days later, the European Central Bank (ECB) instructed the banks it supervises to submit action plans by the end of October outlining how they will address AI-driven cyber threats, including named measures, owners, budgets, and delivery timelines. 

Regulators Want Accountability

The common thread is accountability. Regulators are asking banks to show how cyber risk is being reduced, who owns the work, how it will be funded, and when it will be delivered. That moves the discussion beyond technical controls and into planning, investment, and board oversight. 

AI as a Double Edged Sword

The ECB also highlighted how artificial intelligence changes the economics of cyber attacks.  AI enables attackers to identify vulnerabilities faster, automate reconnaissance, personalise phishing campaigns, and identify and exploit weaknesses at a scale that was previously impractical. 

Systems that have remained unpatched for years… become more attractive when attackers can automatically identify vulnerable systems and match them with known exploits. 

Identification is Key

For banks, the challenge is rarely applying patches. It is knowing where to start. Large financial institutions operate thousands of applications, platforms, certificates, keys, APIs, and third-party components accumulated over decades. Visibility, rather than patching itself, is often the limiting factor. 

The attacks described by the UAE Cyber Security Council also highlight another foundation: identity. 

The techniques described included phishing and stolen credentials, both areas where AI is already making attacks more convincing and significantly easier to scale. Banks have invested heavily in monitoring suspicious logins and strengthening authentication, yet attackers continue to relay one-time passcodes in real time, hijack authenticated sessions through adversary-in-the-middle techniques, and automate credential attacks against public-facing services. 

Changing the Authentication Model to Reduce Risk

Reducing this risk requires changing the underlying authentication model rather than simply adding more protection around passwords. Authentication methods based on public-key cryptography eliminate shared secrets, making phishing, credential theft, and credential replay significantly more difficult while preventing reusable credentials from being stolen or reused across services.

The business case is straightforward. Reducing reliance on passwords lowers fraud, reduces operational overhead, and removes an attack path that continues to generate incidents. 

ECB Post-Quantum Cryptography 

The ECB also addressed post-quantum cryptography.

It acknowledged that the transition will take time and require sustained investment, with further supervisory guidance expected. That creates an immediate challenge for banks because many still cannot answer a basic question: Where is cryptography used across the organisation? 

Without that visibility, no migration plan can be credible. 

The Case for Action

A read-only cryptographic discovery assessment provides the inventory that every migration begins with, identifying the keys, certificates, algorithms, protocols and systems that underpin critical business services. Because modern banking applications often inherit cryptography through libraries, operating systems, middleware, and third-party software, many organisations do not know where cryptography is actually being used or which algorithms underpin their critical systems.

Banks often discover expired certificates, weak algorithms, unmanaged cryptographic assets, and audit gaps long before quantum migration becomes the priority. The longer-term value is a documented migration roadmap with clear ownership, priorities, timelines, and investment decisions, precisely the kind of evidence supervisors are beginning to ask for. 

Neither regulator prescribed a particular technology. Both asked institutions to demonstrate that cyber risk is being reduced through documented actions, clear ownership, realistic timelines, and sustained investment. 

Identity and cryptography are logical places to start because strengthening them addresses both today’s threats and tomorrow’s regulatory expectations. A documented cryptographic inventory supports compliance with existing standards while establishing the foundation for post-quantum migration. Phishing-resistant authentication directly addresses one of the attack techniques regulators continue to highlight while strengthening security and simplifying operations. 

These investments do not depend on a future quantum computer to justify themselves. They deliver value today through stronger resilience, better visibility, and improved governance, while preparing banks for the next generation of cryptographic change. 

The institutions that invest in those foundations now will find themselves answering tomorrow’s supervisory questions with work already underway, rather than explaining why it never began. 


Stay Up to Date with the Latest Updates at Finance ME

Sarah Al-Shawwaf: Vision 2030 Has Unlocked the Potential of Saudi Women

EDGE’s Rodrigo Torres on Risk, Sovereignty and Defence Finance in a Multipolar World

ADNOC Distribution’s Ali Siddiqi: “Growth, Growth and Growth”