Why Financial Services Organizations Can’t Afford Security Blind Spots in the Age of AI
For financial services executives, cybersecurity is no longer just a technology problem. It is a resilience and business performance issue with compliance consequences.
Key Findings: Financial Services Cybersecurity in the Age of AI
- The majority (91 percent) of financial services organizations have deployed artificial intelligence (AI)-powered tools to strengthen data security.
- More than three in four (77 percent) have experienced a breach involving AI, which shows that AI is accelerating risk as well as defense.
- Half (52 percent) cite fragmented security tools as their biggest challenge in securing hybrid cloud infrastructure.
- Nearly all (95 percent) say effective security depends on complete visibility across all data in motion.
- More than one in three (36 percent) identify encrypted traffic as their greatest breach vulnerability. Meanwhile, 93 percent say visibility into encrypted traffic is critical to post-quantum cryptography readiness.
As firms accelerate AI adoption and expand hybrid cloud, financial services cybersecurity must evolve beyond protecting infrastructure to provide the visibility needed to manage risk and maintain confidence. The greatest risk may not be what security teams know, but what they cannot see.
That is the central finding of the latest report from the 2026 Hybrid Cloud Security Survey: Financial Services Industry Insights: The Visibility Imperative in the Age of AI. The survey includes nearly 150 security and IT leaders across the financial services sector. Firms are moving quickly toward AI-driven automation, but many still cannot prove their controls are working. Security budgets are rising. Confidence is not.
AI Is Accelerating Both Defense and Cyberattacks
Financial services firms are adopting AI faster than other industries. Two-thirds (66 percent) already allow AI-driven automation to initiate security functions without human intervention, compared with 53 percent overall. More than nine in ten (91 percent) financial services organizations have deployed AI-powered tools to improve data security.
Attackers are moving just as fast. More than three-quarters (77 percent) of financial services organizations reported experiencing a breach involving AI. More than half (54 percent) reported an increase in AI-powered social engineering attacks, such as phishing and smishing. Nearly half (47 percent) reported an increase in attacks targeting AI and large language model (LLM) deployments.
For financial services, the impact extends far beyond the security operations center (SOC). A cyber incident can disrupt operations and erode customer trust. It can also trigger regulatory scrutiny and hit the bottom line. Among organizations that suffered a breach, most reported material business impact, from data loss or direct financial damage to regulatory penalties and higher cyber insurance costs.
That changes the executive question. The issue is no longer whether to buy more tools. It is whether leadership can prove it has visibility into how risk moves across the business.
Hybrid Cloud Security: More Tools, Less Clarity
Nearly all respondents say they have invested in new security technologies to improve detection and visibility. Yet a significant share also say breach detection is taking longer. More than half identify fragmented security tools as their biggest challenge in securing hybrid cloud infrastructure. At the same time, nearly all say effective security depends on complete visibility across all data in motion.
That is the contradiction at the heart of many security programs: more controls and alerts, yet no coherent view of risk.
Complexity is outpacing understanding. Security teams are collecting more signals, but not always turning them into evidence. The result is a widening gap between perceived readiness and the ability to validate what is happening across cloud and on-premises environments, along with AI systems and encrypted traffic.

Lateral Movement Expands the Hybrid Cloud Attack Surface
Modern financial environments are not contained. Risk moves laterally across hybrid cloud infrastructure, through east-west traffic, across AI systems, and inside encrypted communications.
The research shows how priorities are shifting. Public cloud remains a top concern. Other concerns include private AI environments and lateral traffic. Encrypted traffic and data lakes that hold large volumes of sensitive information are also part of the core attack surface.
If teams cannot see how data and threats move between systems, they cannot prove that controls are effective.
Encrypted Traffic Visibility and Post-Quantum Readiness Need Board Attention
More than one in three respondents identify encrypted traffic as their greatest breach vulnerability. A large majority are concerned about “harvest now, decrypt later” attacks. Nearly all say visibility into encrypted traffic is important for post-quantum cryptography (PQC) readiness.
For financial institutions, this is not a distant technical debate. They manage long-lived sensitive data and operate under heavy regulatory scrutiny. They also depend on trust. Data captured today may still matter to an attacker years from now.
Regulatory expectations now extend beyond documentation and periodic audits. A control that exists on paper is only the starting point. Financial services organizations must demonstrate that those controls work in practice across complex environments and continue to perform over time. Visibility connects security operations to governance by providing evidence that controls are operating as intended.
From Security Confidence to Security Proof
The next phase of cyber resilience will belong to organizations that replace assumption with evidence. Leaders need to know not only what tools are deployed, but whether those tools provide a validated picture of data in motion across hybrid cloud and AI environments, as well as encrypted traffic.
The winners will be the firms that connect fragmented signals and reduce blind spots. They also validate controls over time. Deep observability helps turn disconnected alerts into a real understanding of risk.
In the AI era, that may become one of the most important competitive and regulatory differentiators in financial services.
To learn more, read the complete Financial Services Industry Insights: The Visibility Imperative in the Age of AI report.
CONTINUE THE DISCUSSION
People are talking about this in the Gigamon Community’s Security group.
Share your thoughts today