There’s a lot of buzz right now about banks going all-in on AI, not just for chatbots and fraud alerts, but for rewiring core operations like HR, lending, and back-office processing. It’s a real shift. But while everyone’s talking about the shiny new AI layer, some quieter guidance from CISA and researchers at outlets like Dark Reading is pointing at something more basic: the plumbing underneath still has holes in it.
CISA (the Cybersecurity and Infrastructure Security Agency) recently put out advice on isolating critical systems during a cyberattack, basically how to wall off the parts of your network that absolutely cannot go down, like payment rails or patient records, from the parts that got compromised. It sounds obvious, but a lot of organizations still run flat networks where one phished employee laptop can eventually lead to the transaction system. That’s a problem AI adoption doesn’t fix. In some ways it makes it worse, because now you’ve got AI tools plugged into HR data, customer records, and decision-making systems, all needing access to talk to each other.
Then there’s the password reset issue. For years, “reset your password” has been the default response to a breach. Dark Reading’s reporting makes a good point: that reflex doesn’t cut it anymore. Attackers today often aren’t just stealing passwords, they’re stealing session tokens, or living inside systems long enough that a password change doesn’t remove them. If your identity and access setup hasn’t evolved past “just reset it,” you’re behind.
Put those two threads together and you get the real story. Banks (and hospitals, and government agencies) are racing to bolt AI onto front and back office systems to save money and speed things up. Meanwhile, the fundamentals of network segmentation and identity security haven’t caught up. For finance specifically, this matters because AI systems touching HR and lending data become juicy targets, a breach there isn’t just embarrassing, it can mean regulatory fines and real customer harm. For government agencies modernizing legacy systems, the stakes are similar: AI efficiency gains mean nothing if attackers can move laterally once they’re in.
The lesson isn’t “don’t use AI.” It’s that modernization has to include the boring stuff, isolation, identity, access controls, not just the exciting stuff.
Questions Worth Asking
- Should regulators require proof of network segmentation before approving AI systems in banking infrastructure?
- Is the finance sector’s rush to adopt AI outpacing its ability to secure the systems AI touches?
- What would it take for organizations to move past password resets as a default incident response?
- How much responsibility should AI vendors bear for the security of the systems their tools integrate with?
- Could government agencies realistically keep pace with private-sector AI adoption while maintaining security standards?
- Do customers deserve more transparency about how AI-driven decisions in banking are secured behind the scenes?