Posts

Showing posts with the label financial services

When the Video Call Lies: Professor Kai London on Deepfakes and the New Face of Payment Fraud

Image
  By the Swiss Times Business Desk Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com A finance employee joins a video call with colleagues they recognise, receives an urgent instruction, and authorises a large payment. Every face on the call was fabricated. The money is gone. Once a hypothetical, this scenario has already cost organisations tens of millions — and it represents, says Professor Kai London , a senior CISO and board advisor, a fundamental shift in the nature of fraud. “AI has industrialised deception,” he says. “The controls that assume you can trust a familiar face or voice are now obsolete.” “For centuries, fraud prevention rested on recognising people and processes we trust. Generative AI has broken that assumption. In finance, that is not a curiosity — it is a live threat to the payment process itself.” Why finance is the target London explains that deepfake-enabled fraud gravitates to where the money moves fastest and ...

The Fractional CISO: Professor Kai London on How Mid-Market Financial Firms Get Board-Grade Security

Image
By the Swiss Times Business Desk Professor Kai London — CISO, cybersecurity & AI expert. Credit: professorkailondon.com Large banks employ chief information security officers with deep benches behind them. Mid-market financial firms — asset managers, boutique banks, insurers, fintechs, family offices — face the same regulators and the same attackers, but rarely the same resources. Into that gap has stepped a model whose demand has surged: the interim or fractional CISO. “You do not always need a permanent thirty-person security team,” says Professor Kai London , a senior CISO who takes on exactly these mandates. “Sometimes you need the right senior hands, for a defined period, to set the strategy, fix the worst gaps and leave behind something the board can run.” “The fractional CISO model exists because the risk and the regulation do not scale down for smaller firms — but the budget for a full-time executive team often does.” Same obligations, smaller shoulders London's startin...

Why Governance Wins Deals: Professor Kai London on Turning Cyber Evidence Into Revenue

Image
  By the Swiss Times Business Desk Professor Kai London — Founder & CEO, Quantum AI Systems Security. Credit: professorkailondon.com Cyber security is usually framed as a cost — a necessary drag on the business. Professor Kai London , a senior CISO and board advisor, thinks that framing is not just gloomy but wrong. “Demonstrable governance is one of the most under-appreciated revenue levers in a regulated business,” he says. “The organisations that can prove how they manage cyber and AI risk win the contracts, the partnerships and the markets that the others cannot even enter.” “In regulated industries, trust is the entry ticket. Governance you can evidence is how you buy that ticket — and it is increasingly the thing that decides who wins the deal.” The buyer's due diligence is the new battleground London points to a shift in how enterprise and institutional deals are won. Before a bank, insurer, government body or large corporate signs with a supplier, it runs security and r...

From Annual Audit to Continuous Assurance: Professor Kai London on the Future of Operational Resilience

Image
  By the Swiss Times Business Desk Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com For decades, financial institutions measured their security posture the way they measured their finances: once a year, in a formal audit that produced a snapshot and a certificate. That model, argues Professor Kai London , a senior CISO and board advisor, is quietly becoming obsolete. “An annual audit tells you whether you were secure on one day, months ago,” he says. “Attackers do not operate on your audit calendar. Resilience has to be continuous, or it is theatre.” “The shift under way is from point-in-time compliance to continuous assurance — from proving you were resilient last spring to proving you are resilient right now.” Why the snapshot fails London's critique is straightforward. Environments change daily — new systems, new suppliers, new access, new vulnerabilities. A control that passed an audit in January may have quietly drifted out of eff...

The Weakest Update in the Chain: Professor Kai London on Supply-Chain Risk in Finance

Image
  By the Swiss Times Business Desk Professor Kai London — CISO, cybersecurity & AI expert. Credit: professorkailondon.com The most dangerous vulnerability in a modern bank often sits outside the bank entirely. “Your security is now the weakest update in your supplier's pipeline, and the weakest login at your service provider,” says Professor Kai London , a senior CISO and board advisor. Supply-chain compromise, he argues, has become the defining cyber risk for financial services precisely because the sector runs on a shared, interconnected foundation of third-party technology. “You can outsource the work, but you cannot outsource the accountability. When a supplier is breached, it is your customers, your regulator and your board who feel it.” Why finance is uniquely exposed London points to the structure of modern banking: cloud platforms, payment processors, data providers, software vendors and managed services woven so tightly into operations that they are indistinguishable ...

NIS2 for Financial Services: Professor Kai London on Turning Compliance Into Competitive Advantage

Image
  By the Swiss Times Business Desk Professor Kai London — board advisor & interim CISO/CIO/CTO. Credit: professorkailondon.com For financial institutions, the tightening web of cyber regulation can feel like an ever-growing tax on doing business. Professor Kai London , a senior CISO and board advisor, urges leaders to see it differently. “Resilience regulation is not a tax,” he says. “It is a specification for the trust your customers already expect. The institutions that treat it as an operating standard, rather than a compliance chore, turn it into an advantage.” “Every serious financial institution is being asked the same question by regulators, partners and clients: can you keep running, and can you prove it? The ones who answer confidently will win the business the others cannot.” A converging rulebook London notes that financial firms increasingly sit at the intersection of several resilience regimes — sector-specific operational-resilience rules, the broader network-and-...

The AI Control Architecture: Professor Kai London on Governing AI in Regulated Finance

Image
  By the Swiss Times Business Desk Professor Kai London — CISO, cybersecurity & AI expert. Credit: professorkailondon.com Nowhere is the promise of artificial intelligence greater — or the tolerance for uncontrolled failure lower — than in banking and insurance. Fraud detection, credit decisions, anti-money-laundering, customer service and trading all now lean on models. And that, says Professor Kai London , a senior CISO and board advisor to financial institutions, is precisely why finance needs an architecture for governing AI, not just enthusiasm for deploying it. “In a bank, an ungoverned model is not an innovation. It is a liability waiting for a regulator,” he says. “Regulated finance is where the AI reckoning arrives first. The institutions that can prove how every model is owned, tested and controlled will move faster than the ones that merely claim to be innovative.” Why finance is the hardest test Financial services combine three pressures that make AI governance non-...

Combating the CISO Exodus: New ‘90-Day Command Framework’ Stabilizes Cyber Risk During Executive Transitions

New whitepaper from Professor Kieran Upadrasta offers boards a strategic lifeline as CISO tenure drops to an average of 18 months. LONDON, UK – January 21, 2026 – As the average tenure of Chief Information Security Officers falls to a critical low of 18–26 months, organizations are increasingly facing dangerous "leadership vacuums." Addressing this volatility, globally recognized cybersecurity strategist Professor Kieran Upadrasta has today released “Commanding the Crisis: An Interim CISO’s 90-Day Roadmap to Boardroom Confidence.” The whitepaper introduces a proprietary 90-Day Command Framework, a methodology designed to help interim leaders and Boards of Directors rapidly quantify risk, stabilize governance, and ensure regulatory compliance during the fragile period of executive transition. The Strategic Gap "When a CISO departs, they don't just take their laptop; they take the institutional memory of the organization's risk posture," said Professor Upadras...