Looking to be part of next year’s event?
Join our waiting list to stay informed—we’ll only reach out twice a year with key updates.
On 21 May 2026, leaders from across the financial sector gathered in Amsterdam for the Leaders in Finance Cybersecurity Event 2026. The discussions highlighted how cybersecurity has evolved from a technical issue into a strategic business and societal challenge. Speakers explored the impact of geopolitical tensions, AI-driven threats, cyber resilience, cloud dependencies, regulation, and the growing need for public-private cooperation.
This document summarizes the speeches, interviews, panels and cases at the event. It is not a verbatim transcript, but a paraphrased synopsis of the key points made. It has been prepared and published by Leaders in Finance. Please note that this summary was created with the help of AI tools. While care has been taken to ensure accuracy, the content may contain errors or omissions. For full clarity or specific details, please feel free to contact us at [email protected].

Marcia Luyten welcomed participants to the fourth Leaders in Finance Cybersecurity Event and highlighted how cybersecurity has evolved from an IT issue into a strategic concern for organisations, governments, and international alliances. She emphasized the growing sophistication of cybercrime, the impact of AI on both threats and defence, and the importance of public-private partnerships in strengthening cyber resilience. She also thanked the event partners and introduced the first keynote speaker, Mark, to discuss cyber resilience in a rapidly changing world.
Mark Barwinski (Global Cybersecurity Leader – former UBS & NSA) argued that organisations must rethink resilience in a world shaped by hybrid warfare, geopolitical instability, economic disruption, and rapid technological change. Drawing on experiences from the NSA and Afghanistan, he stressed that resilience is not primarily about technology or processes, but about people, leadership, and culture. His core message was that the era of lean, “just-in-time” operations is over. Organisations need more redundancy, greater investment in people, stronger public-private cooperation, and the ability to absorb shocks without breaking. He compared resilience to both a sumo wrestler, able to withstand impacts through built-in capacity, and cold-water swimmers, trained to remain calm under pressure. Three practical lessons stood out: create operational slack rather than optimising everything for efficiency, regularly train for crises through exercises and simulations, and build purpose-driven teams that trust one another. In the age of AI, he concluded, organisations cannot compete with machines on speed; their advantage lies in human leadership, adaptability, and resilience.


Bernold Nieuwesteeg (Cyber Security & Digital Sovereignty Expert) warned that Europe has become heavily dependent on American technology companies, making digital sovereignty a pressing strategic issue. Using examples from cloud infrastructure, government IT systems, and the financial sector, he argued that recent geopolitical developments have exposed the risks of relying on a small number of foreign providers. He compared Europe’s dependence on Big Tech to a “bad marriage” and stressed that resilience requires more diversity and less focus on efficiency alone. Just as monocultures are vulnerable in nature, relying on a single supplier creates risks for organisations and countries. His main recommendation was that organisations should assess where their data is stored, who controls access to it, and whether they can realistically switch providers if needed. He also called on governments to support European alternatives through procurement policies and regulation, arguing that reducing digital dependence requires both public and private action.
Hans de Vries (Chief Cybersecurity & Operations Officer, ENISA) provided a European perspective on cybersecurity resilience, explaining how EU member states coordinate in response to major cyber incidents and crises. While acknowledging concerns about digital sovereignty and dependency on foreign technology providers, he emphasized that Europe is already taking steps to strengthen its position through funding, procurement rules, joint exercises, and cross-border cooperation. A key theme was the importance of preparedness and coordination. De Vries described how cyber incidents increasingly cross national borders and require structured cooperation between governments, regulators, law enforcement, and the private sector. He highlighted initiatives such as Cyber Europe exercises and the EU Cyber Blueprint, which aim to ensure that countries can share information and respond collectively during crises. In the discussion, he argued that Europe often underinvests in resilience by prioritizing short-term cost savings over long-term security, citing the Maersk cyberattack as an example. He also noted that while cooperation with US counterparts continues, Europe should continue building its own capabilities. His overall message was pragmatic: progress is slow and sometimes bureaucratic, but Europe is steadily building the structures needed to manage increasingly complex cyber threats.


David Capezza (Chief Risk Officer Europe, Visa) discussed how the fraud landscape is changing and what this means for financial institutions. He noted that scams are becoming more sophisticated and increasingly take place before a payment is made, with criminals manipulating consumers through fake investment opportunities, impersonation, and other forms of social engineering. This makes protecting customer trust more important than ever. He also highlighted how customer behaviour online is changing, with automated agents and bots becoming a much larger part of internet traffic. For banks, merchants, and payment providers, this means rethinking how customers interact with digital services and how these interactions can be secured. Capezza argued that better and faster information sharing between banks, payment providers, regulators, and law enforcement is essential to combat large-scale fraud. He shared examples of Visa’s work to identify and disrupt scam networks, stressing that no single organisation can tackle these threats alone.
Ingrida Taurina (Cyber Security Policy, European Banking Federation) argued that one of the biggest challenges for banks today is not a lack of cybersecurity regulation, but the growing complexity of complying with it. Financial institutions must navigate overlapping frameworks such as DORA, the Cyber Resilience Act (CRA), GDPR, and NIS2, often resulting in duplicated reporting, documentation, and compliance efforts. A central theme was the need for greater alignment between DORA and the CRA. The European Banking Federation is pushing for work already carried out under DORA—such as risk management, audits, and incident reporting—to be recognised under the CRA as well, reducing unnecessary duplication. At the same time, she highlighted a positive aspect of the CRA: it can help banks gain better visibility into the cybersecurity practices of vendors and suppliers. Her overall message was that Europe should focus on simplifying and harmonising existing rules rather than creating additional layers of regulation.


Ricardo Ferreira (Field CISO, EMEA, Fortinet) explored the practical challenges of governing AI in financial institutions. While frameworks such as Singapore’s MindForge provide useful guidance, he argued that many current controls and guardrails are not yet mature enough to address risks associated with generative AI and autonomous AI agents. Research shows that AI systems can bypass safeguards, collude with other agents, or behave differently when they are no longer being monitored. His key message was that organisations should not rely solely on compliance checklists or governance frameworks. AI governance must be supported by deeper technical controls, strong data management, and continuous monitoring, as the technology is evolving faster than existing risk frameworks.
Deepak Rambhadjan (Sales Engineer, Rubrik) presented a case study of a financial institution that successfully recovered from a ransomware attack. The attackers gained access through compromised credentials, encrypted data, and attempted to disable backups. Because the organisation had immutable, air-gapped backups and a well-tested recovery process, it was able to restore critical systems within hours rather than weeks and did not have to pay a ransom. His central lesson was that resilience is no longer just about preventing attacks but about ensuring rapid recovery when attacks succeed. He urged organisations to test recovery procedures regularly, understand which systems are essential for business continuity, and verify that backups can survive a real attack.


Rudrani Djwalapersad (Partner – Cyber Security Financial Services, EY), Tom-Martijn Roelofs (MT member & CISO, ING), Marcel van Leent (Security Leader, ABN AMRO Clearing Bank) and Jack Krul (Deputy CISO, NN Group) discussed how financial institutions are responding to a rapidly changing threat landscape. While resilience programmes have matured considerably, the panel agreed that organisations remain too reactive and must become more anticipatory. Emerging risks such as AI-driven attacks, geopolitical tensions and cloud dependencies require a different mindset. Several themes emerged throughout the discussion. Cybersecurity increasingly depends on collaboration across institutions, suppliers and governments. AI will become both a threat and a defensive tool. Cloud sovereignty discussions are broadening into questions about dependency on the entire technology stack. Above all, the panel stressed that resilience is built through continuous testing, scenario exercises and learning from incidents. Their shared hope for the coming year was greater cooperation across the sector and a stronger collective ability to respond to future threats.
Natalia Savchuk (COO & CISO, PrivatBank) shared lessons from operating one of Ukraine’s largest banks during wartime. Since the start of the Russian invasion, the bank has faced an unprecedented combination of cyberattacks, physical threats, disinformation campaigns and operational disruption. In response, PrivatBank migrated its critical infrastructure to the cloud within weeks, strengthened resilience measures, and embedded cybersecurity into every aspect of operations. Her key message was that cyber resilience is ultimately about people. Technology, cloud infrastructure and security controls matter, but success depends on well-trained teams, decentralised decision-making and a strong sense of purpose. She outlined ten lessons from Ukraine’s experience, including the importance of immutable backups, supply chain scrutiny, AI-driven threat intelligence, crisis testing and operational resilience. For organisations seeking to increase their preparedness, her advice was straightforward: test realistic scenarios, empower teams to act, and treat cybersecurity as a core element of organisational survival.







Uniting the financial sector by discussing pressing topics and enhancing cooperation. That’s what we love to do at Leaders in Finance. By listening, learning, and connecting with others, we accelerate the sharing of ideas, thus powering (upcoming) leaders and organizations to shape the future of financial services.
Want to explore how we can benefit your organizational goals? We’re happy to meet and discuss opportunities. Each part of the Leaders in Finance Group has its unique approach. Want to explore how we can benefit your organizational goals? We’re happy to meet and discuss opportunities.
We’d love to keep you informed on the next iterations of this event. Please enter your details below, and we’ll keep you posted!
