Cyber Security Insights July 2026

Cyber Security Insights July 2026

Written by Bryan Altimas

This month, Riverside Court Consulting turns twelve.

Over that time, we have helped organisations of all sizes understand the difference between thinking they are protected and actually being protected. The threat landscape looks very different from 2014. The gap between assumption and reality does not.

So in July’s newsletter, we focus on three areas where that gap is most exposed for firms in financial services. Regulatory deadlines that have already passed. A joint warning from the UK's most senior financial regulators. And an uncomfortable truth about where most incidents actually begin.

None of these are new risks. What is new is the cost of continuing to ignore them..

The Bank of England, the FCA, and HM Treasury Have Issued a Joint AI Warning. What It Means for Your Firm.

In May 2026, three of the UK's most senior financial authorities spoke with one voice on AI risk. The Bank of England, the FCA, and HM Treasury issued a joint statement warning that frontier AI models pose a growing and material threat to the cyber resilience of regulated financial firms.

This is not a theoretical concern from a future-gazing committee. It is a current supervisory expectation from the bodies that regulate, supervise, and set policy for every firm in the UK financial services sector.

The warning covers two distinct but related threats.

The first is the use of AI by attackers. AI is enabling phishing campaigns that are more convincing, more targeted, and harder to detect than anything seen previously. It is enabling voice and video impersonation at a quality that defeats human verification. It is enabling the automation of attacks at a scale that was not previously viable for most threat actors. The financial services sector, with its combination of valuable data and client trust, is a primary target.

The second is the risk introduced by AI tools inside regulated firms. Staff are using AI assistants, AI-generated code, and AI-powered workflow tools, often without IT or compliance awareness. Each of these represents a potential data pathway, a third-party dependency, or a source of unreviewed output entering business processes.

What firms should be doing now:

  • Conduct an audit of AI tools in use across the business, including those adopted informally by staff
  • Assess what data those tools can access and whether that is consistent with your data governance obligations
  • Review your phishing awareness programme to include AI-generated content and voice impersonation scenarios
  • Ensure your incident response plan addresses AI-enabled attack vectors specifically
  • Document your position on AI risk for regulatory purposes

This is where Riverside Court Consulting’s RAID-AI™ risk assessment methodology comes in. We can review your use of AI, both formal and informal or shadow AI. We work with you to show where you are vulnerable and help you with an action plan to make you compliant.

For smaller firms in wealth management, financial advice, and mortgage broking, the proportionality principle applies. The FCA does not expect the same response from a five-person IFA practice as from a large asset manager. But it does expect a considered, documented, and proportionate response from every regulated firm.

Final Thought 

The joint statement from the Bank of England, the FCA, and HM Treasury is a supervisory signal, not a consultation. Firms that can demonstrate they have assessed AI risk and taken proportionate action are in a defensible position. Firms that have not considered it at all are not.

Are you concerned about whether you can demonstrate you have assessed your risk? Book a call to discuss your options. Book a call.

Image

Your Clients Trust You With Everything. That Is Exactly Why Attackers Are Targeting You.

The most common cyber attack hitting UK financial services firms right now is not sophisticated. It does not exploit a technical vulnerability or breach a firewall. It sends an email.

Business email compromise and AI-powered phishing are the number one attack type across the sector. And the reason financial advisers, wealth managers, and mortgage brokers are a primary target is straightforward. You hold sensitive client data. You handle significant sums of money. And your clients trust you enough to act quickly when you ask them to.

That trust is the attack surface.

What has changed in 2026 is the quality of the attack. AI has removed the indicators that trained staff to spot phishing. The misspellings are gone. The awkward phrasing is gone. Emails now arrive written in fluent, professional English, referencing the right names, the right firms, and sometimes the right recent conversations. Voice impersonation has reached a point where a call that sounds like a colleague or a client may not be. 89% of UK financial organisations have raised concern about AI-powered phishing attacks. The other 11% should be paying closer attention.

The most common scenarios hitting firms in this sector right now:

  • A client receives an email appearing to come from their adviser, requesting an urgent transfer or change of account details
  • A staff member receives what appears to be an internal request from a senior colleague to process a payment or share client data
  • A firm receives a supplier invoice with updated bank details, submitted via a compromised or spoofed email account
  • A mortgage broker receives a client identity document that has been digitally altered to pass basic checks

In each case the attack succeeds not because the technology failed but because a person made a reasonable judgement based on information that looked legitimate.

What reduces that risk:

  • A verbal verification process for any request involving money movement or changes to client details, regardless of how the request arrives
  • Staff training that uses real examples of AI-generated phishing, updated regularly as attack methods evolve
  • Clear internal protocols for escalating anything that feels unusual, even slightly
  • Email authentication controls such as DMARC, DKIM, and SPF to reduce the risk of your domain being spoofed
  • Client communications that set expectations about how your firm will and will not contact them

Final Thought

The firms most vulnerable to phishing and business email compromise are not those without technology. They are those without process. A clear, consistently followed verification step costs nothing and stops the majority of these attacks before they succeed. The question is not whether your firm will be targeted. It will be. The question is whether your people know what to do when it happens.

Image

Human Error Is Still the Biggest Cyber Risk in Financial Services. Here Is Why That Does Not Change With More Technology.

The cybersecurity industry sells technology. More detection. More automation. More layers of protection. And much of it is genuinely useful.

But the majority of significant incidents investigated in financial services firms in 2026 do not begin with a technical failure. They begin with a person.

A credential given away in response to a convincing phishing email. A password reused across a personal and a work account. An email sent to the wrong recipient carrying client data. A member of staff who transferred funds following a call from someone claiming to be a senior colleague. A contractor whose access was never revoked.

These are not edge cases. They are the dominant pattern.

The reason this does not change with more technology is that technology does not alter behaviour. It can slow an attacker down once they are inside. It cannot prevent the door from being opened in the first place if a person opens it.

What reduces human-initiated risk is a combination of culture, process, and regular practice. Staff who understand why the rules exist are more likely to follow them. Processes that make the right behaviour easier than the wrong behaviour reduce friction-based errors. Regular, realistic training that reflects actual attack methods builds genuine awareness rather than checkbox compliance.

The basics that make the most difference:

  • Phishing simulations that reflect current attack techniques, including AI-generated content
  • Clear and simple processes for verifying unusual requests, particularly those involving money or data
  • A culture where staff feel confident reporting something that does not look right
  • Access controls that ensure staff only hold the permissions they need
  • Offboarding processes that remove access promptly when people leave or change roles

For financial services firms, the stakes are elevated. Clients trust advisers, wealth managers, and brokers with sensitive financial information and with the authority to act on their behalf. An incident that compromises that trust does not just create a regulatory problem. It ends relationships that took years to build.

Final Thought 

Technology is a necessary part of a resilience strategy. It is not sufficient on its own. The firms that have the fewest incidents are not those with the most tools. They are those where every member of staff understands their role in keeping the business safe, and where that understanding is reinforced consistently. That is a leadership and culture question as much as a technology one.

Image

Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right