Financial services cybersecurity in 2027: How should businesses prepare?
To prepare for 2027, financial services businesses need to incorporate cybersecurity into service development plans from the outset. When an organization expands its use of AI, adds data processing partners, or changes its infrastructure, the questions to answer are: Which services could be affected? How would customers be impacted? And who has decision-making authority when an incident occurs?
PwC’s 2027 cybersecurity outlook: Financial services page provides data that helps organizations revisit these questions. This article draws on PwC’s key findings, adds perspectives from the FSB and the Basel Committee, and proposes preparation approaches for different areas of financial activity.
This in-depth article follows “Cybersecurity 2027: How Should Businesses Prepare for Emerging Trends?”, focusing on banking, insurance, and asset management. The implementation approaches below are editorial analysis and should be adapted to each organization’s services, systems, and resources.
What does PwC’s report reveal about financial services cybersecurity?
PwC published its analysis on 1 October 2026, drawing on responses from 830 financial services executives in the Global Digital Trust Insights 2027 survey. The overall survey was conducted from May to July 2026.
Finding | Respondent Scope |
82% expect to increase cybersecurity budgets | Security and finance executives in the sector |
51% rank attacks on AI systems among the threats they are least prepared to address | Security executives in the sector |
49% are changing their vendor, third-party, and supply chain risk strategies in response to geopolitics | Financial institutions in the survey |
These figures relate to different question groups; they are neither statistics on incidents in 2027 nor percentages specific to Vietnam.

From broad trends to their impact on financial services
To turn survey data into concrete action, an organization can select a service and examine the entire process of delivering it. For payments, the scope might include customer authentication, transaction approval, partner connections, and reconciliation. For insurance, it could start with receiving claims and continue through assessment and payment.
A service-based assessment helps technology and business teams agree on a shared objective: placing controls where an incident could disrupt work or harm customers.
The FSB has identified AI-related risks in finance, including dependencies on service providers, cyber risks, model risks, and data quality. Its 2024 report also notes the potential for generative AI to increase financial fraud. This source provides risk context, rather than a forecast specifically for 2027. [2]
5 cybersecurity priorities for financial services businesses in 2027
1. Assess AI based on access rights and business impact
An organization may already be using AI to help read documents, analyze records, or handle alerts. Before expanding its use, identify which applications only provide suggestions and which can affect actual data or processes.
For each application, businesses should record:
What data is entered and where that data comes from.
Which systems the tool can read from, modify, or send information to.
Who reviews the results and responds when discrepancies are detected.
Under what conditions the application can be paused or the previous process restored.
For example, an assistant that drafts customer responses needs a process for reviewing the content before it is sent. A tool that supports transaction record processing requires additional consideration of access rights and responsibility for approval.
These questions help organizations define an appropriate scope for controls. The article on AI governance in the enterprise can provide background for assigning responsibilities.
2. Design verification steps for requests that could lead to financial loss or loss of access rights
When preparing for 2027, financial institutions should first review decision points that require a high level of trust. Starting points could include changes to customer information, fund transfer requests, account recovery, and the granting of special access rights.
A practical exercise is to introduce a hypothetical request that appears legitimate and test how the team verifies it. Employees need to know which information sources are acceptable, when to escalate, and who can approve exceptions.
For example, if a request is made to change a beneficiary account, check the confirmation process through an established channel. If a caller asks for a locked account to be reopened, clarify how the requester’s identity is verified before changing access rights.
For administrator accounts, organizations can review permissions based on the task and the period of use. Content on privileged access management (PAM) provides additional reading for teams responsible for access controls.
3. Examine shared dependencies across suppliers
An important assessment approach is to check whether different partners depend on the same infrastructure component. This question can be included in service mapping as an organization prepares its 2027 plan.
For each critical service, identify the direct suppliers, known supporting components, and areas where information is missing. Then test a scenario in which a component is unavailable: Which services are affected? How can the organization continue operating? And who needs to be involved in the response?
Alternative arrangements need to be assessed for feasibility. Having an additional supplier will only help in a disruption scenario if the organization can use the necessary data, accounts, and processes with that alternative.
The assessment team should record untested assumptions, such as the time needed to retrieve data or the conditions for switching services. These can inform a review of IT infrastructure for financial services and fintech companies.
4. Run recovery exercises based on the tasks customers need to complete
The Basel Committee’s approach to operational resilience focuses on improving banks’ ability to withstand disruptions, including cyber incidents and technology failures. The document provides reference principles for operations; it does not automatically replace requirements applicable to individual organizations in Vietnam.
To apply this approach in an exercise, an organization can select a scenario in which customers cannot complete transactions or cases accumulate because of a system disruption. Both technology leads and service managers should participate in the test.
Questions to validate include:
How does the team detect the disruption?
Who decides to switch to temporary working arrangements?
Where does the customer service team obtain information?
After recovery, who confirms that the data and processing results are correct?
For example, reopening an application is not enough to confirm that reconciliation has been completed. The exercise should include a step to check outstanding work and the results that need to be confirmed before normal operations resume.
Organizations can connect this activity with a disaster recovery plan, then add scenarios tailored to their financial services.
5. Connect the SOC and automation with incident handling procedures
Before introducing AI into the SOC or expanding monitoring services, organizations should agree on how an alert leads to a decision. For each event category, clarify the data needed for assessment, who should be notified, and which actions are permitted.
For example, an alert on an employee’s device may require a different response from an alert involving a transaction service. If isolating a component could disrupt a service, the organization needs to establish in advance how to coordinate with the business owner.
An automation trial can begin with assistance in consolidating information. After checking quality against known scenarios, the organization can consider expanding permissions in line with the test results.
When working with a partner, the scope of cooperation should clearly specify escalation responsibilities and decision-making authority. SOC and MDR: a detailed guide can help organizations choose a suitable model.
Banking, insurance and asset management should choose different starting points
The table below suggests implementation scenarios based on business activities; it is not a risk ranking from PwC’s survey.
Organization Type | Suggested Starting Point | Validation Scenario |
Banks and organizations operating in capital markets | A transaction process involving multiple systems and partners | Check the response when an authentication or connectivity component is unavailable |
Insurance companies | The process for receiving, assessing, and paying claims | Test arrangements for continuing processing when the claims portal or a partner service is disrupted |
Asset and wealth management companies | The process for receiving, verifying, and executing customer requests | Test how a suspicious change request is detected, verified, and escalated |
Each organization can select a priority scenario, conduct an assessment and exercise, and use the results to identify where further investment is needed. This approach creates a basis for discussion among IT, risk management, and business teams.
A 90-day preparation roadmap
The reference roadmap below helps organizations start with a scope that can be validated. Actual timelines depend on systems and resources.
Phase | Activities | Required Deliverables |
Days 1–30 | Select a critical service; inventory the associated data, AI, access rights, and partners | A service map, assigned owners, and information gaps |
Days 31–60 | Review priority controls; test verification and alert escalation procedures | Recorded findings, remediation measures, and validation criteria |
Days 61–90 | Run a disruption exercise; test recovery and reconciliation capabilities | Test records, remaining gaps, and proposals for further investment |
When submitting a budget, each proposal should clearly state the service being protected, the problem to address, the accountable owner, and the evidence used to evaluate effectiveness. Organizations can prioritize items whose impact is already clear from the initial assessment.
For systems that require in-depth testing, the scope should be defined by the application and assessment objectives. Content on an enterprise penetration testing matrix can support preparation.
Organizations developing a monitoring plan for 2027 can discuss 24/7 SOC services with IPSIP Vietnam, starting with the system scope, log sources, and coordination procedures when an alert arises.
---------------
Frequently asked questions
What should a cybersecurity plan for financial services focus on?
This article focuses on the impact on specific financial activities: request verification, transactions, case processing, reconciliation, and customer service. Measures are selected according to the service and the outcomes that need to be validated.
Should banking, insurance and asset management use the same plan?
They can share an assessment approach and methods for assigning responsibility, but scenarios, data, and recovery conditions should be designed around each organization’s activities.
Is PwC’s report a statistical study specifically of Vietnam’s financial services sector?
No. It is an international survey. When using it for planning, organizations need to compare it with their current circumstances and the requirements applicable to their activities.
Should organizations prioritize new tools or validate existing measures?
Start with a critical service and identify the gaps. The assessment results will help determine where to improve processes, add resources, or invest in tools.
------------
References
PwC — 2027 cybersecurity outlook: Financial services. Published on 1 October 2026. Source for the survey scope and the figures in the table. Read PwC’s financial services analysis.
Financial Stability Board — The Financial Stability Implications of Artificial Intelligence. Published on 14 November 2024. Background source on AI risks in finance, including dependencies on service providers, cyber risks, model risks, and data quality. Read the FSB report.
Basel Committee on Banking Supervision — Principles for operational resilience. Published on 31 March 2021. Reference source on banks’ ability to withstand operational disruptions. Read the document on the BIS website.













