Skip to content
il Cantonale

Independent digital newspaper of Italian-speaking Switzerland

Economy Supervision

Finma: cyberattacks up by a third at supervised institutions

Chair Marlene Amstad points to advanced artificial intelligence as a risk for the whole financial sector. And is already looking at quantum computers.

by Redazione 16 August 2026 2 min read

The Swiss Financial Market Supervisory Authority has warned the country's banking and insurance sector about risks tied to information security and artificial intelligence. "Across all the financial institutions we supervise, we are seeing a marked increase in cyberattacks, of about a third," said the chair of its board of directors, Marlene Amstad.

The increase is not only in frequency. According to Amstad, the availability of advanced language models lowers the cost of preparing an attack and raises its credibility, particularly in techniques that target human error rather than a technical flaw. "The threat posed by highly developed AI concerns the entire sector," she said.

The regulator wants institutions to treat these as operational risks in their own right, with the same discipline applied to credit and market risk. The focus extends to third-party providers, because a growing share of banks' IT infrastructure is outsourced and an attack on one supplier spreads to all its clients.

Finma uses the same tools

The authority is expanding its own artificial intelligence applications, used above all to analyse supervisory data. "We have to be fast enough to keep pace with technological development," Amstad explained. It is an admission that the skills gap between supervisors and supervised is itself a risk.

Amstad also cited a threat that has not yet materialised: quantum computers, which in time could break the encryption algorithms in use today. The issue matters for bank archives, because data intercepted and stored now could be decrypted in a few years.

The Swiss financial sector is a target because of its size and its reputation. In 2025 the attack on the document management system used by the federal administration showed how quickly a known vulnerability turns into a widespread incident. Finma's recommendations do not take the form of new rules but of supervisory expectations, and failing to meet them can trigger proceedings.

Comments

No comments

There are no comments yet. Yours can be the first voice.

Leave a comment