Identity Blast Radius: Professor Kai London on Containing the Next Banking Breach

 By the Swiss Times Business Desk

Professor Kai London, Founder and CEO of Quantum AI Systems Security and UCL researcher
Professor Kai London — Founder & CEO, Quantum AI Systems Security. Credit: professorkailondon.com

When a bank suffers a serious breach, the post-mortem almost always lands on the same word: identity. “In modern financial breaches, the decisive failure is rarely exotic malware,” says Professor Kai London, a senior CISO who advises financial institutions. “It is an identity — human or machine — that logged in when it should have been challenged, and could then reach far more than it ever should have.” His prescription centres on a single, board-friendly idea: manage the blast radius.

“You will not prevent every intrusion. But you can decide, in advance, how far any single compromised identity is allowed to spread. In banking, that decision is the difference between an incident and a catastrophe.”

The crown-jewel problem

Banks run on a dense web of identities: employees, contractors, customers, service accounts, APIs and, increasingly, AI agents. London's first move is to identify which of those identities could do catastrophic damage — the “crown jewels” with reach into core systems, payment rails and customer data. “Most institutions have a surprisingly small number of identities that could, if compromised, take the whole thing down,” he says. “Those are the ones to obsess over first.”

Calculating the blast radius

For each critical identity, London asks a simple question with complex implications: if this account is compromised, what can it reach? The answer — the blast radius — is a measure of concentrated risk. Over-privileged accounts, standing access that is never revoked, and flat networks that let a single compromise roam freely all inflate it. “The goal is to shrink the blast radius of your most dangerous identities to the smallest possible footprint,” he says, “so that even a successful attack is contained.”

Conditional access: verify every login in context

Containment begins at the door. London advocates conditional access that evaluates the full context of every login — device health, location, behaviour, risk signals — rather than trusting a password. Phishing-resistant multi-factor authentication on privileged accounts, just-in-time elevation instead of permanent admin rights, and continuous verification all raise the cost of abusing a stolen credential. “A password tells you someone once knew a secret,” he says. “Conditional access asks whether this login, right now, deserves trust.”

Detect the compromise after the login

Because malicious logins look legitimate, London places heavy emphasis on detecting anomalous behaviour after authentication — an account suddenly reaching new systems, moving laterally, or exfiltrating data at unusual volumes. In banking, where speed of response is everything, he stresses rehearsing the containment: knowing, in advance, how to isolate a compromised identity in minutes. “The first hour decides the outcome,” he says. “Institutions that have practised the response contain the damage; those that improvise wear it.”

The machine and AI-agent frontier

London warns that the fastest-growing identity risk in finance is non-human. Service accounts and API keys have long been over-privileged and under-watched; now AI agents are joining them, able to act autonomously and at scale. “Every AI agent a bank deploys is a new identity with real reach,” he says. “It needs the same discipline as a privileged human user — strong authentication, least privilege, monitoring and a way to shut it down — before it touches anything that moves money.”

Proof for the regulator

Finally, London ties identity control back to accountability. Regulators increasingly expect institutions to demonstrate — not merely assert — that access to critical systems is controlled and monitored. “The examiner's question is becoming ‘show me who can reach your core systems, under what conditions, with what evidence,’” he says. “An institution that can produce that answer is in a fundamentally stronger position than one that cannot.”

For a banking sector where a single unchallenged login can cascade into a market-moving event, London's counsel is disciplined and clear: find the identities that could hurt you most, shrink what they can reach, verify every login in context, and rehearse the containment. The next breach may be inevitable. Its blast radius is a choice.


About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with more than 25 years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing, and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim or fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.

Popular posts from this blog

Combating the CISO Exodus: New ‘90-Day Command Framework’ Stabilizes Cyber Risk During Executive Transitions

From Annual Audit to Continuous Assurance: Professor Kai London on the Future of Operational Resilience

Why Governance Wins Deals: Professor Kai London on Turning Cyber Evidence Into Revenue