This blog outlines how financial institutions are addressing the systemic cyber risk posed by aging and end-of-life technology, as AI accelerates attack velocity, and the window for effective defense is shortening.
In July 2026, the European Central Bank (ECB) sent a letter to financial institutions mandating them to submit a clear plan by the end of October 2026 to address the escalating threats posed by frontier AI cyber models. The ECB identified modernization of legacy infrastructure as a central tenet of the plan. This is a necessary response to the new cyberthreat landscape where frontier AI models such as Mythos have drastically compressed the window between vulnerability discovery and exploitation. AI-enabled attacks turn even more dangerous because they hit systems that were already exposed.
Hardware and software that have reached end-of-life (EoL) and are no longer receiving security patches are a treasure trove for threat actors. Not only are they an open gate to get into organizations, but once inside, they enable attackers to move faster, dwell longer, and inhibit the ability of defenders to remove them. The fast arrival of frontier AI models has underlined the urgency of removing obsolete, unsupported devices from critical networks.
Globally, nearly half of business network infrastructure assets were already aging or obsolete at the start of this decade. Volt Typhoon, the state-sponsored group which targets unpatchable network infrastructure in critical infrastructure sectors, is a live example of what happens when critical systems run on EoL technology.
A converging EU position on the dangers of legacy technologyThe ECB’s letter is a recognition that critical infrastructure faces systemic exposure, at a moment when AI accelerates the speed of attack and shortens the window organizations have to respond.
The European Supervisory Authorities (ESAs) have issued a parallel statement on ICT risks from frontier AI models. They require entities to reduce the attack surface by “eliminating unnecessary exposures, enforcing segmentation, and decommissioning legacy systems”. They insist that these steps must evolve from basic hygiene measures like inventory management to evolve toward AI-driven attack surface management.
Building on their expertise and DORA’s comprehensive operational resilience provisions, the ECB and EU financial regulators independently identified decommissioning legacy systems as a frontline defense against AI-enabled attacks. EoL technology has shifted from an IT hygiene issue to a systemic risk; one the ESAs explicitly link to cascading failures across interconnected financial infrastructure.
The ECB approach: an example for other sectors and EU policyPolicy makers should look at the financial sector for building their action plans to treat this urgent issue at scale; an opportunity unfortunately overlooked by the current EU Cybersecurity and AI Action Plan.
The approach mandated by the ECB stands out for its sense of urgency, prioritization and focus. It demands immediate, direct action, and signals that other supervisory activities need to be delayed or adjusted to concentrate efforts on this urgent systemic risk.
The ECB and ESAs’ prioritize patch management, perimeter security, and third-party risk, which translate into specific actions for critical infrastructure that Europe should look to accelerate:
The scale of this problem beyond banking remains poorly understood. WPI Strategy’s report, Update Critical: Counting the Cost of Cybersecurity Risks from End-of-Life Technology on Critical National Infrastructure, commissioned by Cisco, showed the issue is growing but is under-researched, especially when it comes to weigh the cost of “technical debt” against the cost of replacement. The report’s recommendations track closely with what the ECB and ESAs are now asking of banks.
Scaling the solution to a fast-growing problemThe tools to scale this approach across Europe could be activated swiftly if policymakers chose to activate them:
Cisco’s Chief Security & Trust Officer Anthony Grieco recently announced changes to make secure configurations the default across Cisco offerings, and to proactively alert administrators when insecure choices are being made. This “security by default” principle is the type of action that reduces the burden on institutions racing to upgrade their resilience against AI cyber threats.
The ECB’s October 2026 deadline can work as a forcing function because it’s specific and near-term. Institutions that treat it as an isolated compliance exercise will miss the point and fail to address the underlying vulnerability. Those that use it to fix asset visibility, patch discipline, and architecture will be ahead. The issue of legacy technology, leading to dangerous technical debt, was always going to require resolution. The ECB has just given it a clear approach, vision and timeline.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | When AI agents swarm, can banks keep up? | 0 | 10.38 | 30-09-2026 |
| 2 | De-Risking the AI Banking Bubble with Better Telemetry | 0 | 9.78 | 08-09-2026 |
| 3 | Defending against AI-fueled social engineering | 0 | 12.07 | 01-09-2026 |
| 4 | Cyber criminals 'could use AI to raid bank accounts in just THREE MONTHS', security officials warn | 0 | 7.81 | 13-09-2026 |
| 5 | A timeline of developments in AI safety since the attack on Hugging Face | 0 | 8.26 | 01-10-2026 |
| 6 | The SOC Doesn't Need to Start Over with Every Alert | 0 | 8.65 | 25-09-2026 |
| 7 | AI Cybersecurity Threats: Intelligence vs. Authority | 0 | 6.33 | 29-09-2026 |
| 8 | Sicherheit: Können Unternehmen KI-Angriffe und Hacker künftig noch abwehren? | 0 | 13.11 | 29-09-2026 |
| 9 | Enhancing AI Agent Security: Implementing Guardrails Against Prompt Injection | 0 | 5.1 | 07-07-2026 |
| 10 | The US needs a real plan to defend its water systems | 0 | 8.15 | 05-10-2026 |