
Cyberattacks on Swiss financial institutions have risen by a third. That number alone should give pause to anyone who still thinks the banking sector has its digital defenses figured out. Switzerland’s financial regulator, FINMA, is now pushing banks and insurers to take that reality seriously, and the warning covers more than just hackers.
Marlene Amstad, chair of FINMA’s board of directors, told Swiss financial newspaper Finanz und Wirtschaft that the regulator is seeing a clear and measurable spike in attacks across every institution it oversees. “We are seeing a marked increase in cyber attacks, amounting to a third, across all the financial institutions we supervise,” she said. That’s not a vague concern. That’s a documented trend with a number attached to it.
But the cyberattack figures are only part of the picture. When asked specifically about the risk that advanced AI models pose to banking giant UBS, Amstad pushed back on the idea that this is one institution’s problem. “The threat posed by highly developed AI affects the entire sector,” she said. So the risk isn’t concentrated. It’s spread across every firm using AI tools, every firm relying on third-party tech providers, and every firm that hasn’t yet stress-tested its systems against AI-assisted attacks.
This matters because FINMA is not just issuing a warning. It’s placing direct legal and operational responsibility on financial institutions themselves to prevent systemic failure. The regulator is specifically targeting risks tied to third-party service providers, which is exactly where many of the most damaging breaches originate. Banks outsource critical functions to cloud platforms, data processors, and software vendors. When those vendors are compromised, the bank’s customers pay the price, often without knowing it happened.
Amstad also flagged something that most regulators are still treating as a future problem: quantum computing. She said the technology, still in development, could have “major implications for the security” of the financial system. That’s a significant statement. Quantum computers, once mature, could break the encryption that currently protects financial data, transaction records, and customer information. The window to prepare is open now, not later.
FINMA says it is expanding its own internal use of AI and working to strengthen international cooperation. Those are the right moves, but regulators saying they’re “keeping pace” with technology is a claim worth watching closely. The gap between regulatory speed and the speed of actual threats has historically not favored the regulators. And when that gap widens, it’s ordinary account holders who are most exposed.