Banks Are Being Told to Prepare for AI Cyberattacks. Businesses Should Pay Attention Too

July 7, 2026

European regulators are warning banks to prepare for AI-enabled cyberattacks. The concern is not only about the banking industry. As AI makes cyber threats faster and more convincing, businesses need stronger security controls, better monitoring, proper backup and clear incident response planning.

Table of contents
Key Takeaways
  • The European Central Bank has told euro zone banks to prepare plans against AI-enabled cyberattacks.
  • Banks must submit their plans by 31 October 2026.
  • The Bank of England has also warned that AI is becoming a growing financial stability risk.
  • AI can help attackers create faster, more convincing and more automated cyber threats.
  • Businesses should review cybersecurity, backup, monitoring, access control and incident response before problems happen.

Cybersecurity is entering a new stage.

In the past, most companies worried about phishing emails, ransomware, weak passwords and outdated systems.

Those risks still matter.

But now, AI is making the threat more complicated.

On 7 July 2026, Reuters reported that the European Central Bank has instructed euro zone banks to prepare detailed plans against AI-enabled cyberattacks. The banks have been told to submit these plans by 31 October 2026.

On the same day, Reuters also reported that the Bank of England sees AI as a growing risk to financial stability. The concerns include cybersecurity risk, operational disruption, investor overconfidence and the challenge of regulating more autonomous AI systems.

This may sound like a banking issue.

But the message is much wider.

If banks are being asked to prepare for AI cyberattacks, other businesses should also start reviewing their own security readiness.

Why Regulators Are Concerned

Banks are highly regulated because they are critical to the economy.

If a bank suffers a major cyberattack, the impact can spread quickly.

Payments may be disrupted.

Customers may lose access to accounts.

Confidence may be affected.

Other financial institutions may also feel pressure.

That is why regulators are taking AI cyber risk seriously.

According to Reuters, the European Central Bank wants banks to secure internet-facing systems, update vulnerable technologies, improve cyber monitoring, strengthen crisis management and improve information-sharing.

These are not only banking controls.

They are practical security steps for almost any company.

The difference is that banks are being pushed by regulators.

Other businesses may need to push themselves before they are forced to respond after an incident.

How AI Changes Cyberattacks

AI does not create cybersecurity risk from nothing.

But it can make existing risks faster, cheaper and more scalable.

Attackers can use AI to improve phishing emails, write better scam messages, generate fake documents, translate attacks into different languages and automate research on targets.

This makes attacks harder to spot.

A phishing email may no longer look badly written.

A fake supplier message may sound professional.

A scam WhatsApp or email may copy the tone of a real company.

A malicious script may be generated faster.

A fake support request may look more believable.

That is the problem.

AI helps attackers reduce effort.

It also helps them increase volume.

The Risk Is Not Only Technical

Many companies think cybersecurity is only an IT department issue.

That is a mistake.

AI-enabled cyberattacks can affect the whole business.

A finance team may receive a fake invoice.

A sales team may receive a fake customer request.

An HR team may receive a fake job application attachment.

A manager may receive a fake approval email.

A supplier may receive a fake payment instruction.

A customer support team may be tricked into resetting an account.

These attacks are not only about firewalls and servers.

They target people, processes and trust.

That is why cybersecurity planning needs to involve management, finance, operations, HR, sales and IT.

Why Businesses Should Not Wait

Many businesses only improve cybersecurity after something goes wrong.

That is risky.

By the time a ransomware attack happens, the company may already be dealing with downtime, lost files, angry customers and urgent recovery cost.

By the time a business email compromise is discovered, money may already have been transferred.

By the time customer data is leaked, the reputation damage may already be done.

AI can make this timeline shorter.

Attacks may move faster.

Fake messages may look more convincing.

The window to detect and respond may become smaller.

This is why preparation matters.

The First Area to Review: Internet-Facing Systems

The European Central Bank specifically highlighted the need for banks to secure internet-facing systems.

This is important for all businesses.

Internet-facing systems are systems that can be accessed from outside the company network.

Examples include:

  • Company websites
  • Customer portals
  • Webmail
  • VPN access
  • Remote desktop access
  • Cloud admin portals
  • API endpoints
  • File sharing platforms
  • Firewall login pages
  • Public-facing applications

These systems are often the first target.

Businesses should check whether these systems are properly updated, protected and monitored.

Old systems should not be left exposed.

Admin access should not be open to the public without strong protection.

Remote access should use multi-factor authentication.

The Second Area: Monitoring and Alerts

Security tools are only useful if someone is watching the alerts.

Many companies have antivirus, firewall or cloud logs.

But nobody reviews them properly.

That creates a false sense of security.

AI-enabled attacks may move quickly, so businesses need better visibility.

This does not always mean building a large security operations centre.

But it does mean the company should know:

  • Who receives security alerts
  • What happens after an alert is triggered
  • Which alerts are high priority
  • How fast the team can respond
  • Whether logs are kept properly
  • Whether suspicious activity is reviewed

Monitoring should not be treated as optional.

If a company cannot see what is happening, it cannot respond properly.

The Third Area: Backup and Recovery

Backup is one of the most important protections against ransomware.

But backup must be properly designed.

A weak backup may fail when the company needs it most.

A good backup plan should include:

  • Automatic scheduled backups
  • Offsite backup storage
  • Immutable backup where possible
  • Recovery testing
  • Clear retention policy
  • Protection from accidental deletion
  • Defined recovery time objective
  • Defined recovery point objective

In simple words, the company must know how fast it can recover and how much data it can afford to lose.

If the answer is unclear, the recovery plan is not ready.

The Fourth Area: Access Control

Many cyber incidents happen because access is too open.

Too many users have admin rights.

Old accounts are still active.

Shared passwords are used.

Multi-factor authentication is missing.

Vendor access is not reviewed.

Cloud storage permissions are too broad.

This creates easy paths for attackers.

Businesses should follow a simple rule:

Give users only the access they need.

Then review it regularly.

This applies to employees, vendors, contractors and temporary users.

The Fifth Area: Incident Response

An incident response plan explains what the company should do when something goes wrong.

Without a plan, people panic.

They may make slow decisions.

They may contact the wrong person.

They may shut down the wrong system.

They may lose important evidence.

They may communicate poorly with customers.

A practical incident response plan should answer:

  • Who is in charge during an incident?
  • Who must be contacted first?
  • What systems are most critical?
  • How do we isolate affected devices?
  • How do we check whether data was exposed?
  • How do we restore from backup?
  • How do we communicate with customers?
  • When do we involve legal, management or external support?

The plan does not need to be perfect on day one.

But it must exist.

AI Also Creates Business Continuity Risk

The Bank of England warned that AI could create broader financial stability risks, including cybersecurity and operational vulnerabilities.

For companies, the same idea applies at business level.

If more business processes depend on AI tools, cloud services and automation, downtime can become more serious.

For example:

  • Customer support may depend on AI ticket summaries.
  • Finance may depend on cloud accounting platforms.
  • Sales may depend on CRM automation.
  • Operations may depend on cloud dashboards.
  • IT may depend on AI-assisted security tools.
  • Management may depend on data analytics platforms.

If these systems fail, work slows down.

That is why AI adoption and business continuity planning should go together.

What Businesses Should Do Now

Businesses do not need to be banks to take this seriously.

AI cyber risk is becoming relevant to every organisation that uses email, cloud systems, online payments, customer data or digital operations.

Here are practical steps to start.

1. Review Exposed Systems

List all public-facing systems and check whether they are updated, protected and still needed.

Remove or restrict anything unnecessary.

2. Enable Multi-Factor Authentication

MFA should be enabled for email, cloud platforms, remote access, admin panels and business-critical systems.

This is one of the most effective basic protections.

3. Improve Email Security

AI can make phishing more convincing.

Email security should include spam filtering, malware scanning, domain protection, user awareness and clear verification steps for payment changes.

4. Train Staff on AI-Generated Scams

Employees should understand that fake messages may now look polished and professional.

Train teams to verify unusual requests, especially those involving payment, login access, confidential files or account changes.

5. Strengthen Backup and Recovery

Do not only create backups.

Test recovery.

A backup that cannot be restored is not a real backup plan.

6. Monitor Security Events

Make sure alerts are reviewed and escalated properly.

The company should know who handles security alerts and what action should be taken.

7. Prepare an Incident Response Plan

Create a simple plan for ransomware, phishing, data leakage and system compromise.

Test the plan with a basic tabletop exercise.

The Bigger Picture

The warning from European regulators is part of a larger shift.

AI is no longer only a productivity topic.

It is now part of cybersecurity, financial stability, governance and business continuity.

Companies that use AI without improving security may expose themselves to new risks.

Companies that prepare early will be in a better position.

The right approach is not fear.

It is readiness.

Closing Thoughts

AI can help businesses work faster.

But it can also help attackers move faster.

The latest warnings from the European Central Bank and Bank of England show that AI-enabled cyber risk is now serious enough for financial regulators to act.

Businesses should treat this as an early warning.

Review your systems.

Strengthen access control.

Protect email.

Monitor alerts.

Test backup.

Prepare incident response.

Train your staff.

Cybersecurity is no longer only about blocking yesterday’s threats. It is about preparing for faster, smarter and more convincing attacks.

At Net Onboard, we help businesses build secure, reliable and scalable cloud environments through managed cloud hosting, cybersecurity, backup and business continuity solutions.

If your company wants to strengthen cybersecurity, improve backup readiness or review cloud infrastructure risk, speak to our team today.

Frequently Asked Questions

  1. What did the European Central Bank tell banks to do?

    The European Central Bank told euro zone banks to prepare comprehensive plans against AI-enabled cyberattacks and submit them by 31 October 2026.

  2. Why is AI a cybersecurity risk?

    AI can help attackers create more convincing phishing messages, automate attacks, generate malicious code and move faster. This makes detection and response more difficult.

  3. Does this only affect banks?

    No. Banks are being highlighted because they are critical to the economy, but AI-enabled cyber risk can affect any business that uses email, cloud systems, online platforms or customer data.

  4. What is the first thing a business should review?

    Start with internet-facing systems, email security, multi-factor authentication, backup and user access. These are common areas attackers try to exploit.

  5. Why is backup important against AI-enabled cyberattacks?

    If an attack leads to ransomware, data deletion or system compromise, backup gives the company a way to recover. The backup must be secure, tested and protected from deletion.