AI Can Strengthen Cybersecurity—But It Can Also Break It

Artificial Intelligence (“AI”) is no longer a concept associated solely with innovation and operational efficiency. It has become one of the defining technologies shaping the future of cybersecurity, offering financial institutions significant opportunities to strengthen their cyber defences while simultaneously introducing a new generation of sophisticated threats. As organisations increasingly integrate AI into their operations, cybercriminals are doing the same, fundamentally changing the way cyber-attacks are planned, executed and scaled.

Against this backdrop, the Cyprus Securities and Exchange Commission (“CySEC”) recently issued Circular C786, drawing the attention of regulated entities to the cybersecurity implications of frontier Artificial Intelligence models and reminding firms of their obligations under the Digital Operational Resilience Act (“DORA”). While the Circular does not introduce new legal requirements, it reinforces an important regulatory expectation: ICT risk management frameworks must continuously evolve to address emerging technologies and the changing cyber threat landscape.

This message is particularly significant because AI is reshaping cyber risk at a pace that traditional security frameworks were never designed to address. Financial institutions can no longer rely solely on historical threat patterns or traditional security controls. Instead, they must ensure that operational resilience, governance and ICT risk management remain dynamic, proportionate and capable of responding to increasingly intelligent and automated attacks.

 

Frontier AI Has Changed the Cybersecurity Landscape

Artificial Intelligence has already demonstrated enormous value in strengthening cybersecurity. Financial institutions increasingly rely on AI-powered solutions to detect unusual activity, analyse vast quantities of security data, identify potential fraud, automate threat intelligence and improve incident response. These capabilities allow security teams to identify threats more quickly than traditional manual processes and, in many cases, prevent cyber incidents before they materialise.

However, AI is inherently neutral. The same technologies that improve cyber resilience can equally be exploited by malicious actors.

CySEC’s Circular focuses specifically on frontier AI models—highly advanced AI systems capable of analysing software, generating code, identifying vulnerabilities and adapting their outputs with remarkable speed and sophistication. These models significantly reduce the technical barriers traditionally associated with cyber-attacks, enabling threat actors to automate activities that previously required substantial expertise and time.

This development represents a fundamental shift in the cyber threat landscape. Rather than relying on manual techniques to identify weaknesses, attackers can increasingly leverage AI to scan software for vulnerabilities, generate malicious code, develop highly personalised phishing campaigns and identify new attack methods within a fraction of the time previously required. As a result, organisations face an environment in which vulnerabilities may be discovered and exploited much faster than conventional remediation processes were designed to accommodate.

CySEC also highlights that these risks extend beyond regulated entities themselves. As financial institutions continue to rely on cloud providers, software vendors and other ICT third-party service providers, AI-driven attacks targeting supply chains may create significant operational disruptions across multiple organisations simultaneously.

 

DORA Was Designed to Address Exactly These Types of Risks

One of DORA’s greatest strengths lies in its technology-neutral approach. Rather than regulating individual technologies, the Regulation establishes a comprehensive framework requiring financial entities to identify, assess, manage and continuously monitor ICT risks irrespective of how those risks emerge.

This means that although DORA contains no dedicated chapter on Artificial Intelligence, AI-generated cyber threats naturally fall within its scope. Financial entities remain responsible for ensuring that their ICT risk management framework is capable of protecting information assets, maintaining operational resilience and responding effectively to evolving cyber threats.

The Circular reinforces this principle by encouraging regulated entities to critically assess whether their existing ICT governance arrangements remain adequate in light of frontier AI developments. Importantly, this assessment should not be treated as a one-off compliance exercise. DORA is built around continuous improvement, recognising that operational resilience depends upon organisations regularly reviewing, testing and enhancing their controls as technologies and risks evolve.

This principle reflects one of the core objectives of DORA: resilience is not achieved simply by implementing security controls. It requires organisations to continuously evaluate whether those controls remain effective within an increasingly complex technological environment.

 

Operational Resilience Must Now Evolve Alongside Artificial Intelligence

CySEC’s Circular encourages regulated entities to revisit several key components of their ICT risk management frameworks, many of which already form central pillars of DORA.

One of the most immediate considerations concerns vulnerability management. As AI significantly accelerates the identification of software vulnerabilities, financial institutions must ensure that their own processes for vulnerability monitoring, patch management and remediation operate at a comparable pace. Delays that may previously have represented acceptable operational risks could now create significantly greater exposure, particularly where critical systems or traditional infrastructure are involved.

Similarly, organisations should carefully reassess whether their security architecture continues to provide sufficient protection against increasingly sophisticated attacks. Identity and access management, privileged access controls, authentication mechanisms and network segmentation should all be evaluated through the lens of AI-enabled cyber threats. Security by design is no longer simply a regulatory expectation under DORA—it has become an operational necessity.

CySEC also places considerable emphasis on monitoring and detection capabilities. Traditional monitoring solutions that rely heavily on predefined rules or manual analysis may struggle to identify increasingly complex AI-generated attacks. Firms should therefore consider whether their existing detection capabilities remain proportionate to the evolving threat landscape and whether greater automation, threat intelligence integration or security coordination could improve their ability to identify incidents before they escalate.

Equally important is an organisation’s ability to recover from a cyber incident. DORA deliberately shifts the regulatory focus away from prevention alone and towards operational resilience. No organisation can eliminate cyber risk entirely. Instead, firms must demonstrate that they can continue operating, restore critical services promptly and minimise disruption even when attacks occur.

This makes robust backup arrangements, disaster recovery planning and restoration testing increasingly important. CySEC specifically reminds firms to ensure that backup systems remain appropriately segregated from production environments and are tested regularly under realistic operational conditions. These measures become particularly relevant when responding to AI-driven attacks that may spread rapidly across multiple systems or attempt to compromise recovery environments themselves.

 

Third-Party Risk Management Has Become More Important Than Ever

Another important message arising from both DORA and CySEC’s Circular concerns ICT third-party risk.

Financial institutions increasingly rely on external providers for cloud infrastructure, software development, cybersecurity solutions, managed services and data processing. While outsourcing delivers considerable operational benefits, it also extends an organisation’s attack surface beyond its own internal environment.

AI further amplifies these risks. A vulnerability affecting a single ICT provider may now be identified and exploited far more rapidly, potentially affecting multiple regulated entities simultaneously. Consequently, organisations should ensure that their third-party risk management arrangements remain sufficiently robust to address these evolving threats.

This extends beyond contractual compliance. Firms should maintain ongoing oversight of critical ICT providers, assess their cybersecurity maturity, understand their incident response capabilities and ensure that appropriate contingency arrangements remain in place should disruptions occur. Effective third-party risk management has become an essential component of operational resilience rather than merely a procurement exercise.

 

Strong Governance Will Ultimately Determine Operational Resilience

Perhaps the most important message conveyed by CySEC is that managing AI-related cyber risks is not solely the responsibility of ICT departments.

Operational resilience begins with governance.

Boards of Directors and senior management remain ultimately responsible for ensuring that ICT risks are properly identified, assessed and managed throughout the organisation. As frontier AI continues to reshape cybersecurity, governance arrangements must evolve accordingly. AI-related cyber risks should be incorporated into ICT risk assessments, operational resilience planning and Board-level discussions to ensure that strategic decisions reflect the changing technological environment.

This also requires organisations to foster a culture of continuous learning. Lessons arising from cyber incidents, penetration testing, vulnerability assessments and emerging threat intelligence should feed directly into governance processes, enabling firms to strengthen their resilience over time rather than merely reacting to individual incidents.

 

Conclusion

Artificial Intelligence is transforming both cybersecurity and the cyber threat landscape, creating new opportunities as well as new risks for financial institutions. CySEC’s Circular C786 serves as an important reminder that firms must ensure their ICT risk management frameworks, governance arrangements and operational resilience measures continue to evolve in line with these emerging threats.

While DORA already provides the framework for managing ICT risks, organisations should proactively reassess whether their existing controls remain effective in an increasingly AI-driven environment. Firms that embed AI-related cyber risks into their governance and resilience strategies will be better positioned to safeguard their operations, meet regulatory expectations and strengthen their overall digital resilience.

 

How FiveComply Can Help

Whether you are reviewing your DORA compliance programme, strengthening your ICT risk management framework, or preparing for regulatory expectations surrounding emerging technologies such as Artificial Intelligence, our team is here to support you.

 

Get in touch with our team to discuss your DORA compliance framework, ICT governance, or operational resilience strategy.

📞 +357 25 34 00 25
📧 regulatory@fivecomply.com

Author

Dafne Achniotou

Compliance Consultant – EU & MENA Region