Tech Sentinel
Flat isometric illustration of blue server towers ascending like a bar chart, joined by a molecule-style network and a keyhole shield.
industry

Standard Chartered's Group CISO on AI's Dual Role in Banking Security

Cezary Piekarski, group CISO at Standard Chartered, says AI is reshaping defensive operations and adversarial tactics simultaneously -- and that banking security leaders must think like business executives to keep pace.

By Tech Sentinel Newsroom · · 5 min read

Standard Chartered Group Chief Information Security Officer Cezary Piekarski said this week that artificial intelligence now shapes both sides of the threat landscape in global banking, accelerating defenses at scale while simultaneously giving adversaries faster, more sophisticated tools for fraud and intrusion.

The comments came in a video interview with Dark Reading published August 14, 2026, in which Piekarski discussed the CISO’s expanding strategic role, the business case for security leadership, and how financial institutions should position themselves as AI adoption accelerates across the industry. The interview lands as breach costs in the financial sector reached a 2025 average of $5.73 million globally, per the IBM Cost of a Data Breach Report, with Asia-Pacific incident frequency up 12 percent year-over-year.

From Technical to Strategic

Piekarski’s tenure at Standard Chartered reflects a pattern becoming standard at large global banks: the CISO role has migrated from infrastructure oversight to board-level risk communication. In prior public remarks, he described the imperative as designing “security controls as business enablers, rather than constraints,” and advocated embedding security officers directly within business units rather than operating them as a separate compliance function.

The organizational argument is practical. Security teams isolated from product development arrive late, apply controls as afterthoughts, and generate friction that business lines route around. Piekarski’s preferred model is secure-by-design architecture: controls built into platforms at the inception of a product cycle, not added once a product reaches deployment.

That framing also changes how CISOs make the case for resources. A team that can quantify how its controls shortened a product launch timeline, reduced audit findings, or enabled a new regulated service is selling a different product than one that pitches breach-cost scenarios. According to Piekarski, security executives who can make that translation fluently are no longer optional for institutions operating at global scale.

AI: Defensive Gains and a Larger Attack Surface

The practical AI discussion in the Dark Reading interview tracks closely with what Piekarski has said in other forums: machine learning-driven behavioral analysis and anomaly detection now handle volumes of transaction and access data that no human review process could cover. Fraud pattern recognition, identification of beaconing behavior through baseline profiling, and automated flagging of misdirected emails are among the operational applications financial institutions have deployed.

The warning Piekarski attaches to that progress is unambiguous. Adversaries “will try to exploit vulnerabilities in AI model and data pipelines while at the same time using AI themselves for faster more sophisticated attacks like deepfakes and social engineering,” he said. AI-enabled social engineering is not theoretical. Synthetic voice and deepfake video have already been used to impersonate executives and authorize fraudulent wire transfers at financial institutions. AI-accelerated reconnaissance compresses the time between a threat actor’s initial access and lateral movement, narrowing the detection window.

The institutional risk that Piekarski flags is that the same AI systems deployed to defend can become attack surfaces. Model poisoning, adversarial inputs designed to confuse classification systems, and attacks on the data pipelines feeding AI models are attack categories that did not meaningfully exist five years ago. Standard Chartered’s response, per his public remarks, is to pair AI deployment with “secure-by-design AI practices, validation, and testing” from the ground up.

Regulatory Pressure in Key Markets

Standard Chartered operates across more than 40 markets, with concentrated exposure in Asia, Africa, and the Middle East. That geographic footprint puts the bank under multiple regulatory frameworks simultaneously, several of which have tightened their AI and cyber requirements in recent cycles.

Singapore’s Monetary Authority of Singapore updated its Technology Risk Management Guidelines to require proactive threat-hunting, moving the compliance baseline from detection-and-response toward preemptive security postures. Hong Kong’s Hong Kong Monetary Authority has incorporated resilience against AI-enabled attacks into mandatory cyber stress testing requirements. Both regulators are asking institutions not just to show that AI is being used in security operations, but that the AI systems themselves have been assessed for exploitability.

That pressure aligns with where analyst projections place the market. Gartner forecasts that preemptive cybersecurity solutions will account for 50 percent of IT security spending by 2030, up from less than 5 percent in 2024. For security leaders, that trajectory reframes budget conversations: the comparison is no longer reactive breach response costs against prevention costs, but rather the efficiency and coverage gains from anticipatory security versus the compounding cost of incident-driven remediation.

Implications for Security Leaders

Piekarski’s interview draws a clear line from operational AI deployment through regulatory compliance to strategic organizational positioning. For security leaders at institutions navigating similar terrain, the practical takeaways are consistent across his public appearances:

Integrate security into business units early. Late-stage security review is structurally disadvantaged. Teams embedded in product and line-of-business functions catch design-level risks before they become remediation costs.

Govern AI deployments as attack surfaces, not just tools. Deploying AI for detection without assessing the AI system itself for adversarial exploitation creates a gap regulators are beginning to examine explicitly.

Build the business-enabler case. Board-level credibility for security investment tracks with how clearly the CISO can connect security posture to business outcomes: product velocity, audit readiness, customer trust, and regulatory standing.

Account for deepfake and synthetic media risk. AI-enabled social engineering targeting finance authorization workflows is an active threat category, not an emerging one. Detection and verification controls for high-value transactions should treat synthetic identity as a baseline assumption.

Monitor AI pipeline integrity, not just model outputs. Attacks on training data and inference pipelines may not produce obvious anomalies in real-time monitoring. Integrity controls upstream of model inference are part of the defensive surface.


Sources

Sources

  1. Mission-Driven Security: Inside a Global Bank's Defense — Dark Reading
  2. Security is an innovation enabler, not a constraint: Cezary Piekarski of Standard Chartered — The Digital Banker
  3. Rewiring banks' cyber defence from reactive to preemptive in 2026 — FutureCISO
#banking#ciso#artificial-intelligence#financial-sector #threat-intel
Subscribe

Tech Sentinel — in your inbox

Cybersecurity news: breaches, CVEs, ransomware, threat actors, and the patches that matter — delivered when there's something worth your inbox.

No spam. Unsubscribe anytime.

Related