Cybersecurity Is a Team Sport

How SIFMA, Our Members, and Partners Work Together to Keep Markets Running Through Any Disruption
Published on:
October 1, 2026

October is Cybersecurity Awareness Month, a timely reminder that the security of U.S. capital markets depends on the systems and networks that underpin it. For SIFMA and our members, cybersecurity is year-round work, done together with market infrastructure, government partners, and one another. That collaborative approach is more important than ever as emerging technologies reshape both the threats facing the financial sector and the tools available to defend against them.

Cybersecurity in the Age of Artificial Intelligence

Artificial intelligence (AI) is driving a fundamental transformation in the cybersecurity landscape, accelerating both defensive and offensive cyber activities, and creating new challenges for cybersecurity professionals. Nowhere is this more apparent than in vulnerability management and remediation, with vulnerabilities being identified at a scale and speed that were previously unimaginable. AI-assisted exploitation techniques are further exacerbating the threat, reducing both the technical expertise required to carry out a cyberattack and the time between vulnerability identification and exploitation. As a result, cyber defenders are confronted with larger numbers of vulnerabilities, more capable cyber attackers, and increasingly compressed timelines for remediation.

Many network defenders have taken to using AI in their security and resilience programs to enable defense “at computer speed.” Using AI in this manner can be very beneficial; however, the incorporation of AI into business processes presents its own novel cybersecurity risks that organizations should consider. This may include treating agentic AI as an “employee” for purposes of the organization’s insider threat programs, monitoring for the use of shadow AI by employees, and adding AI management to the list of items assessed during third party risk evaluations.

Most importantly, however, organizations must recommit to cybersecurity fundamentals, such as network segmentation, identity and access management, retirement of end-of-life technology, perimeter security, and defense-in-depth.

Testing the Plumbing of the Markets

Another place where cross-organizational collaboration is key to cyber resilience is testing and exercises. One noteworthy example contributing to the financial sector’s resilience is SIFMA’s annual Industry-Wide Business Continuity Test. During this annual test, firms send test orders and transactions from backup sites to exchanges, markets, and utilities to help ensure that the alternate systems will function in case of cyber incidents impacting primary systems. Last year’s test included roughly 100 securities firms and more than 80 market organizations who collectively tested approximately 1,100 communications connections from backup environments. This year’s test is scheduled for October 24, 2026.

SIFMA also helps market participants evaluate their cybersecurity response capabilities as part of its biennial Quantum Dawn exercise. The eighth edition of Quantum Dawn, held November 4–6, 2025, simulated a polycrisis scenario involving a Category 5 hurricane, a transatlantic undersea cable cut, a financial market infrastructure outage, and a zero-day cyberattack occurring simultaneously. With nearly 1,000 participants from over 100 institutions worldwide taking part, the exercise helped organizations assess their cyber resilience; better understand their telecommunications, cloud, and third-party cyber dependencies; and consider disconnection and reconnection protocols that are in place to reduce the likelihood that a cyber incident will cause systemic impacts. On this last point, SIFMA and the Financial Services Sector Coordinating Council (FSSCC) have published a Reconnection Framework to assist firms with safely reconnecting to the financial ecosystem after a cybersecurity incident has been contained and mitigated.

Coordinating When It Counts

Teamwork becomes even more important during an actual cyber incident, when timely information sharing and coordinated decision-making are essential.

No matter how good a job the financial sector does in preparing for cyberattacks, incidents will occur. How the sector coordinates amongst itself during an incident can make the difference between whether an incident is limited in scope or becomes systemic. During cyber incidents with the potential to cause market-wide impacts, SIFMA will activate our emergency crisis management command center and bring market participants together. By convening public and private representatives from across the sector to exchange information on incidents as they unfold, SIFMA helps facilitate a collective response from across the industry.

Preparing for Quantum Computing

While frontier AI may be the closest crocodile to the boat, financial institutions should also be taking steps to address the looming cybersecurity challenges that will result from quantum computing. The potential for quantum computing to render many existing encryption methods obsolete within the next five to ten years raises urgent questions regarding data protection, the risk of disruption to critical operations, and the resilience of an increasingly digitized financial ecosystem. To mitigate these risks, financial entities must transition to post-quantum cryptography (PQC). SIFMA and its members are supporting joint efforts being led by the FSSCC and Financial and Banking Information Infrastructure Committee to enhance the sector’s quantum readiness through the development and publication of materials on topics such as PQC sector alignment; third party and vendor readiness; and PQC for digital assets and emerging technologies.

Smart Policy Strengthens Security

Cybersecurity is greatly impacted by the rules that govern it. Done properly, national cybersecurity policy and regulation can enhance information sharing and strengthen resilience across sectors. Done poorly, it can divert limited resources in times of crisis or unintentionally create cyber risk. That is why SIFMA supports a common-sense, risk-based, and harmonized approach to cybersecurity policy and regulation.

Among SIFMA’s cybersecurity policy and regulatory priorities is the long-term authorization of the Cybersecurity Information Sharing Act of 2015 (CISA 2015). SIFMA members rely on protections offered by CISA 2015 to support the safe sharing of information on cyber threats and incidents. However, CISA 2015 is set to expire in December. Without the protections afforded by CISA 2015, private sector entities may be less willing to share information on cyber threats and intelligence, potentially slowing down the identification of cyber campaigns and inhibiting response activities at the same time AI is speeding up cyber threats.

The multitude of cyber incident reporting requirements that financial firms are subject to, each with their own unique reporting requirements, creates its own cybersecurity challenges. During a cyber incident, every additional reporting requirement competes for the same personnel, expertise, and time needed to investigate, contain, and remediate the threat. To better balance the benefits provided by incident reporting requirements with the costs incurred by reporting entities, SIFMA has advocated for various changes to existing and proposed cyber incident reporting requirements, including harmonization of the Cyber Incident Reporting for Critical Infrastructure Act requirements with other existing requirements, and the elimination of the cyber incident disclosure requirements contained in Item 106 of Securities and Exchange Commission Regulation S-K.

The Bottom Line

Frontier AI, quantum computing, and other emerging technologies are making cybersecurity both more complex and more important than ever. No single firm or government agency can protect the markets from every threat on its own. Through joint development of guidance and frameworks, regular testing, realistic exercises, and constructive engagement with policymakers, SIFMA and our members are helping ensure that U.S. capital markets remain secure, resilient, and trusted. Because cybersecurity is ultimately a team sport, and the strength of the financial system depends on how well that team works together.

Related Resource

Author

Todd Klessman

Todd Klessman

Managing Director, Financial Services Cyber & Technology, SIFMA

Details

More Content

  • Press Releases
    Oct 01, 2026

    SIFMA Statement on Confirmation of Labor Secretary Sonderling

  • Pennsylvania + Wall
    Sep 30, 2026

    Key Takeaways for Asset Managers from SIFMA’s Digital Assets Conference 2026

    Key takeaways for asset managers on tokenization, digital assets, regulation and investment trends from SIFMA’s 2026 Digital Assets Conference.
  • Pennsylvania + Wall
    Sep 29, 2026

    SIFMA Weighs In: How to Get E-Delivery Right

    SIFMA examines the SEC’s proposed Regulation E-Delivery and offers recommendations for a practical, secure framework that works for investors and firms.

Get the latest trends, stats, and research on financial markets and securities.