Cybertech Europe 2026-IT Industry Official Media Partner

New study: Nordic AI-powered financial companies hit hardest by security incidents

Marshall Erwin, Chief Security Officer at Fastly, with Fastly's official white logo and graphical cybersecurity environment Marshall Erwin, Chief Security Officer at Fastly, with Fastly's official white logo and graphical cybersecurity environment
Marshall Erwin, Head of Security at Fastly. Press image with Fastly's official logo.

Nordic financial companies that invest heavily in artificial intelligence are more exposed to security incidents than businesses that do not describe themselves as AI-driven. According to Fastly's new security study, 44 percent of financial companies in the Nordics report that AI was directly utilized in their most recent incident.

AI is rapidly being used in more and more business processes, from analytics and customer service to risk assessment and automated decision-making. This development creates great opportunities for the financial sector, but at the same time changes the technical environment and attack surface of organizations. Fastly's fourth annual Global Security Research Report shows that security work often does not develop at the same pace as AI use.

Nordic financial companies report highest AI exposure

In the Nordic financial sector, 44 percent of respondents say that AI was directly used in the most recent security incident. This is the highest percentage among all industries in the Nordic part of the study and clearly above the Nordic average of 29 percent.

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

AI played a contributing role in 65 percent of recent incidents in Nordic finance. In 44 percent of cases, the technology was directly exploited, while 21 percent stated that AI use had created security gaps or blind spots that contributed to the incident.

The difference is also visible between different types of organizations. Among Nordic AI-first companies, 42 percent say that the use of AI contributed to a lack of transparency or security gaps in the most recent incident. The corresponding share among Nordic companies that are not AI-first is 21 percent.

Rapid AI development is changing the security infrastructure

Marshall Erwin, chief security officer at Fastly, emphasizes that organizations don't need to slow down innovation. The challenge is instead to modernize security at the same pace as AI transforms the infrastructure, workflows, and data that businesses need to protect.

For these companies, it's not about slowing down innovation, but about developing security at the same pace as AI investments.

Marshall Erwin, Head of Security at Fastly

Fastly’s global results point in the same direction. AI-first organizations need an average of 6.8 months to fully recover from a security incident, compared to 3.9 months for other companies. This corresponds to approximately 80 days longer recovery time. Incidents are also reported to cost AI-first businesses 135 percent more.

Shadow AI creates blind spots in the financial sector

A key risk is so-called shadow AI, where employees use AI tools without formal approval, governance or security review. In Nordic finance, 21 percent of respondents say that more than half of employees use AI tools without approval or oversight. This is the highest proportion among the financial markets included in the survey.

When security teams lack a complete picture of which models, services, and data sources are being used, it becomes more difficult to control permissions, information flows, and dependencies. Sensitive data can be processed outside the organization’s established protections, while new AI agents gain extensive access to systems and data.

More than half identify as AI-first

The exposure is reinforced by the high adoption rate. In total, 54 percent of Nordic financial companies formally describe themselves as AI-first. This is the highest proportion among the industries surveyed and well above the Nordic average of 39 percent.

The study also shows that 62 percent of Nordic financial institutions experience at least one recurring incident within three months of a breach. The findings underscore the need to not only stop the initial attack, but also understand the root cause, revoke compromised privileges, and monitor changes across the entire environment.

Security needs to follow AI throughout its lifecycle

For financial companies, the results mean that AI governance must be integrated into the regular work with cybersecurity. This includes taking inventory of approved and unapproved tools, introducing clear rules for data management, and monitoring both human and machine identities.

  • Map AI services, models, agents, and associated data sources.
  • Restrict permissions according to the principle of least access.
  • Monitor APIs, web applications, and AI-related traffic.
  • Introduce policies and training that reduce the use of shadow AI.
  • Update incident plans for AI-specific risks and recurring breaches.

About the survey

Fastly's Global Security Research Report is based on responses from 2,000 IT decision-makers with responsibility or influence over cybersecurity in large enterprises. Participants represent multiple industries in North, Central and South America, Europe, Asia-Pacific and Japan. Sapio Research conducted the interviews online in the fourth quarter of 2025.

About Fastly

Fastly develops a global edge cloud platform with services for delivering, securing, and operating web applications and APIs. The company's security portfolio includes web application and API protection, DDoS protection, and bot management.

Sources and further reading

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT