Claude Mythos and co.: New Cyber Risks for Financial Institutions
Fact sheet as a result of the webinar of Bank-Verlag in cooperation with the Association of German Banks and the Bankenakademie
The webinar highlighted a range of perspectives, including the supervisory viewpoint, assessments from the national cybersecurity authority and practical insights from several financial institutions.
The situation from Bafin’s perspective
Key message: Cyber risks remain a key focus for supervisors due to the high threat level and the potential for cyber incidents to spread quickly beyond individual institutions, affecting both the wider financial system and the broader economy. Digital innovation is seen as essential to maintaining a functional, competitive and resilient financial system. At the same time, increasing utilisation of digital technologies is expanding the cyber risk landscape.
This applies equally to the opportunities and risks associated with new frontier AI models. From a supervisory perspective, full implementation of DORA and strong cyber hygiene provide a solid foundation for addressing the current challenges. However, additional measures are required. Financial institutions must be prepared to assess and remediate a growing number of new vulnerabilities within short timeframes, or to mitigate them using appropriate measures. A risk-based approach is vital, with priority given to protecting critical systems. Organisations must also develop strategies for legacy systems that can no longer be patched. In doing so, they need to consider not only risks within their own environments but also those affecting ICT third-party service providers.
Key drivers: Complex IT environments, geopolitical conflicts and concentrations and dependencies are key factors contributing to the elevated risk landscape. The growing use of AI is creating new risks.
Particular attention is currently focused on powerful frontier AI models such as Claude Mythos 5, GPT‑5.5 and MDASH. These models are expected to be capable of identifying and exploiting previously unknown vulnerabilities in ICT systems within a short period of time. As the provision of these models is concentrated among a small number of providers, this development could further increase dependencies on individual providers in third countries. The conditions governing access, data protection and legal requirements are currently evolving on an almost daily basis.
Further Reading: The importance of information sharing, discussion and the exchange of practical experience and best practices was highlighted throughout the webinar. Nikolas Speer’s full keynote is available here .
Factsheet Bank-Verlag englisch
Contact
André Nash
Head of Banking Technology and Security
Contact
Oliver Seidel
Banking Supervision and Accounting