Conference Description
Key Takeaways
- One-day summit addressing cyber resilience strategies for banks, insurers and fintechs
- Focus areas include AI security governance, incident response, supply chain risk and regulatory compliance
- Designed for CISOs, risk managers, compliance officers and IT security directors
- Features insights from regulators, technology leaders and practising security executives
- Takes place 25 November 2026 at The Minster Building, London
Introduction
The 9th Annual Cyber Security in Financial Services Summit returns to London in November 2026, bringing together senior security, risk and compliance professionals from across the banking, insurance and fintech sectors. As financial institutions face mounting pressure from sophisticated threat actors, evolving regulatory frameworks and the rapid integration of artificial intelligence into business operations, the summit provides a dedicated forum for examining practical resilience strategies.
With cyber incidents increasingly capable of disrupting critical financial infrastructure, the event addresses how organisations can strengthen their defensive posture while maintaining operational continuity. The timing reflects growing regulatory attention on operational resilience requirements and the emerging challenges posed by AI-enabled threats.
About This Event
This executive-level gathering convenes over 200 senior leaders for a day of expert-led sessions and peer networking. The programme features more than 30 speakers drawn from regulatory bodies, technology providers and financial institutions, including practising CISOs who can share direct operational experience. The format emphasises actionable insights over theoretical discussion, with content structured around the specific challenges facing security teams in regulated financial environments.
Sponsors and exhibitors at this year’s summit include AmberWolf, HackerOne, Invicti, Nethermind, Rubrik, Socura and ThreatLocker, representing capabilities across vulnerability management, threat detection, data protection and endpoint security.
Cyber Resilience and Incident Response
Operational resilience has become a central concern for financial regulators worldwide, with frameworks now requiring institutions to demonstrate they can withstand and recover from severe disruptions. The summit examines how organisations are building resilience capabilities that extend beyond traditional perimeter defence, encompassing incident response planning, crisis communication and business continuity under attack conditions.
Sessions address the practical realities of responding to incidents when they occur, including coordination across technical teams, executive leadership and external stakeholders. For institutions operating complex technology estates, the ability to detect, contain and remediate threats rapidly has become a competitive and regulatory necessity.
AI Security and Governance Challenges
The integration of artificial intelligence into financial services creates both opportunities and vulnerabilities. While AI enhances fraud detection and automates security operations, it also introduces new attack surfaces and governance complexities. The summit explores secure-by-design approaches to AI deployment, examining how institutions can implement appropriate controls without stifling innovation.
Deepfake detection represents a particularly pressing concern as synthetic media becomes increasingly sophisticated. Financial institutions face scenarios where AI-generated voice or video content could be used to authorise fraudulent transactions or manipulate market-sensitive communications. Understanding these emerging threat vectors is essential for security leaders responsible for protecting institutional assets and customer trust.
Supply Chain and Third-Party Risk
Financial institutions typically depend on extensive networks of technology vendors, cloud providers and outsourced service partners. Each relationship introduces potential vulnerabilities that adversaries can exploit to reach high-value targets. The summit addresses how organisations are maturing their third-party risk management programmes, from initial due diligence through ongoing monitoring and contractual controls.
Recent high-profile supply chain compromises have demonstrated that even well-resourced institutions can be affected by weaknesses in their vendor ecosystems. Building visibility into these extended attack surfaces requires both technical capabilities and governance frameworks that hold suppliers accountable for security outcomes.
Human Risk and Security Culture
Technical controls alone cannot address the full spectrum of cyber risk. Social engineering, insider threats and simple human error continue to feature prominently in breach investigations. The summit examines how leading institutions are cultivating security-aware cultures that reduce human risk without creating friction that drives workarounds.
Effective security awareness programmes have evolved beyond compliance-driven training exercises toward behavioural approaches that embed security thinking into daily operations. For organisations where employees handle sensitive financial data and high-value transactions, this cultural dimension of security is increasingly recognised as foundational.
Who Should Attend
The summit is designed for director and C-suite professionals responsible for cyber security, information risk, compliance and technology governance within financial services. This includes CISOs, heads of information security, risk managers, compliance officers and IT security directors working in banks, insurers, asset managers and fintech organisations. The executive-level focus ensures discussions address strategic and operational concerns relevant to senior decision-makers.

