Member login
American Financial Services Association

Industry Expertise | Perfect Security Is a Myth: 3 Actions to Build AI Resilience

Industry Expertise | Perfect Security Is a Myth: 3 Actions to Build AI Resilience

“Industry Expertise” is sponsored content produced by AFSA’s Business Partners’ to provide thought leadership and best practices for AFSA member companies. For more information about this sponsored content opportunity, contact AFSA Membership.


Perfect Security Is a Myth: 3 Actions to Build AI Resilience
By: David Ralstin, Allied Solutions

As Cybersecurity Awareness Month approaches, the focus naturally turns to prevention: stronger controls, authentication, detection, and defenses. But as AI expands the number of tools, data flows, and dependencies organizations must govern, another question matters just as much: 

What happens when prevention is not enough? 

Recent research from Experian illustrates why this distinction matters. Its 2026 Automotive Dealer Fraud Threat Report found that 85% of dealers encountered suspected or confirmed fraud in the past year, 88% are concerned about rising fraud, and 75% say fraud has a measurable impact on their business. 

No financial institution or partner can eliminate every threat. The objective is not to prevent every incident, but to build the capability to respond when something gets through. 

Security asks: How do we prevent something from happening?
Resilience asks: How well will we operate when something does? 

The risk doesn’t stop at the firewall 

Financial institutions depend on technology providers, data providers, cloud platforms, and other third parties. A single provider may support multiple functions or depend on its own providers, creating dependency risk that can quickly affect multiple processes or customer touchpoints. 

Federal banking agencies’ guidance calls for risk-based third-party management, including due diligence, ongoing monitoring, and operational resilience. NIST’s Cybersecurity Framework 2.0 likewise emphasizes governance and cybersecurity supply chain risk. 

Third-party risk cannot be treated as a one-time assessment. Third-party resilience is part of enterprise resilience. A security questionnaire is a starting point; testing reveals how controls perform under pressure. 

3 actions to move from security to resilience  

  1. Map the Exposure

Identify where AI is already being used, including consumer LLMs and unapproved tools. Map what data enters those environments and where employees need safer alternatives. 

  1. Classify the Risk

Stop treating AI as one category. Triage use cases by the data they touch and potential impact, then establish clear lanes: 

  • Green: Public or low-sensitivity data, low-impact use cases 
  • Yellow: Internal use with defined controls 
  • Red: PII, financial, credit, underwriting, or other high-impact data in unapproved environments 

This gives employees a practical path forward instead of simply telling them what they can’t do. 

  1. Test the Guardrails

Governance only works if it holds up under pressure. Test vendor controls, data isolation, access restrictions, incident response, and recovery. Then take the conversation to leadership: How quickly can we contain an AI-related incident, and how safely can we keep the business moving? 

From security posture to resilience posture 

Cybersecurity controls remain foundational, but prevention is only part of the equation. Institutions need visibility into the systems, processes, providers, and dependencies that keep the organization operating. 

Ask what controls exist, how they have been tested, what happens when they fail, when the institution will know, and how critical operations continue. 

Perfect security may be impossible. Operational resilience is something organizations can build, test, and prove. 

By: David Ralstin, Allied Solutions 

October 2nd, 2026

Get The News You Need

Sign up for our daily newsletter to receive all the most important industry news and updates every weekday morning.

Recent Posts

Archives