This article shares three observations from FS-ISAC APAC on the changing meaning of cyber resilience, the democratisation of sophisticated attacks through DarkAI and the need for more predictive threat intelligence. It considers how financial institutions can identify reconnaissance and third-party exposure earlier, before attackers have the context needed to launch a targeted attack.
Cyber resilience is often discussed in terms of maintaining operations, recovering quickly and reducing the impact of an incident. However, conversations at FS-ISAC APAC reflected a broader shift in how financial-services security leaders are thinking about resilience.
Increasingly, resilience is also about identifying and interrupting the activity that happens before an attack begins. This includes cybercriminal reconnaissance, intelligence gathering through compromised third-party accounts and the early signals that an attacker may be preparing a targeted fraud or impersonation attempt.
Following RPost CEO Zafar Khan’s session, “Rethinking Third-Party Risk, CTI & Attack Surface in this Age of DarkAI,” three themes stood out.
Frameworks such as DORA have reinforced the importance of operational resilience across financial services. But resilience is increasingly being interpreted as more than the ability to recover after disruption.
Security leaders are also considering whether they can detect reconnaissance earlier, identify exposure within third- and fourth-party environments, preserve forensic evidence and provide meaningful resilience metrics for executive and board reporting.
This is particularly relevant when sensitive communications and documents move outside the organisation. Supplier inboxes, external platforms and partner environments may not have the same level of protection as the financial institution itself.
Traditional controls may stop at the enterprise boundary, but the risk does not. A compromised third-party account can give an attacker access to legitimate conversations, internal relationships and transaction context.
Building resilience therefore requires greater visibility into how sensitive information is accessed and used after it leaves the organisation.
Highly targeted cyberattacks once required significant time, expertise and manual effort. Attackers had to study communications, understand business relationships and imitate writing styles.
AI is making those capabilities available to a much wider criminal ecosystem.
Threat actors can use AI tools to analyse compromised communications, identify key individuals, understand approval processes and create convincing impersonation attempts based on genuine business context.
This changes the defensive priority. Blocking the final fraudulent message remains essential, but by that point the attacker may already have completed the reconnaissance needed to build it.
Financial institutions should therefore consider whether they can identify the preparation phase of an attack. For example, is a compromised external account monitoring a sensitive discussion? Has a confidential document been accessed unexpectedly? Is an attacker gathering context around a payment or approval process?
In the age of DarkAI, resilience means detecting and interrupting the attacker before the final lure is delivered.
Cyber threat intelligence has traditionally focused on what has already happened: known infrastructure, indicators of compromise and attacker techniques observed in previous incidents.
That remains essential, but financial-services security teams increasingly need intelligence that helps them understand what may happen next.
This requires combining technical indicators with broader context, including the people involved, the content being accessed, the timing of activity and any links to known threat actors.
Attribution is especially important. Once suspicious activity is connected to a specific account, actor or criminal group, other events that initially appeared harmless may become more meaningful.
This is where cyber threat intelligence can support active threat hunting rather than only retrospective reporting. The goal is to identify patterns that expose an attack while it is still being assembled.
These discussions reflect a wider industry shift from reactive detection and response towards more preemptive approaches to cybersecurity. The objective is to identify reconnaissance, exposure and attacker behaviour early enough to interrupt an attack before it reaches the execution stage.
For financial institutions, this does not necessarily mean replacing existing security infrastructure. It means addressing the visibility gaps that arise when communications, documents and transaction information move beyond the enterprise and into third-party environments.
The key question is no longer only how quickly an organisation can respond to an incident. It is how early it can identify malicious intent, detect reconnaissance and act before the attacker has enough context to strike.
RPost explores these themes further in its FS-ISAC Expert Webinar, including how compromised third-party environments may be used to prepare targeted financial attacks and how reconnaissance signals can support earlier threat identification.
July 28, 2026
July 24, 2026
July 07, 2026
June 25, 2026
June 25, 2026