BAFT (Bankers Association for Finance and Trade) 2026 Europe Forum Review.

Published on

Insights

Operational Resilience and concerns about the impact of Quantum Computing to the fore.

The first half of the 2020s was marred by multiple crises and shocks, a pattern that has continued into 2026. Today, Transaction Banks are once again having their Operational Resilience tested by escalating tensions in the Middle East, cyber-crime, and the anticipated arrival of Quantum Computing.

Simon Shepherd, Managing Director, MYRIAD Group Technologies Limited (MGTL), moderated a fireside chat at BAFT Europe in London, and reflects on some of the top talking points from the wider event.

The GCC crisis puts the onus on Operational Resilience

With hundreds of ballistic missiles and drones raining down on the GCC countries, Banks in the region have dusted off their contingency plans, instructed staff to work remotely, and suspended all international travel, broadly mirroring the steps they took during Covid.

Clients report that disruption to service levels in the region has been minimal, if non-existent, underlining just how much effort Banks are putting into their Operational Resilience.

The Industry’s automation efforts have played a big role here – facilitating faster incident detection, better auditability and business continuity. For automation to be as effective as possible, Simon said the Industry needs ready access to high quality, structured data – something that should become easier over time as more Banks adopt the ISO 20022 standard.

A Network Manager at BAFT Europe highlighted that Banks are becoming increasingly proactive – and less reactive – when responding to extreme risk or market events. So volatile have things become, they continued, that Banks are now creating risk models which assume a baseline level of serious macro and geopolitical uncertainty.

Banks also have greater visibility into the supply chain risks facing their Networks. Those Networks – both primary and secondary/contingency Networks – need detailed mapping as a first step such that when needed, visibility and transparency is instantaneous which underpins rapid, informed decision-making.

The Network Manager said Providers want to know exactly where their Cash Correspondent Banks are carrying out critical operations and if any of these core activities have been outsourced, and if so, to whom. This allows Network Managers to identify potential weaknesses in their supply chains before a crisis materialises.

With so much going on in the world, Simon said that regulators are almost certainly going to be probing Banks about their Operational Resilience planning and procedures.

Noting that it has been one year since the EU’s Digital Operational Resilience Act (DORA) went live, Simon added Regulators will want Banks to demonstrate that they have appropriate safeguards in place when overseeing critical Third-Party ICT Providers. Typically, anniversaries of this type of regulation are when regulatory scrutiny steps up, and this is when audit trails and compliance functions really demonstrate their value.

Cyber Risks take precedence

Cyber-crime is becoming an increasingly potent threat and putting an enormous strain on Banks and their Operational Resilience teams.

Attendees at BAFT Europe warned that current events in the Middle East could trigger a wave of cyber-attacks against Global Banks and urged people to be vigilant. This echoes advice from the UK’s National Cyber-Security Centre (NCSC), which recommended Organisations “adjust (their) cyber-security posture” due to the fast-evolving nature of the conflict.[1]

As more Banks embed Artificial Intelligence (AI) tools into their operations, e.g. Customer support, risk and fraud monitoring, etc., new cyber risks will emerge. Experts warn that Banks could be vulnerable to prompt injections, data poisoning and model inversion attacks if their AI guardrails are found wanting.

In light of this ever-evolving landscape, Simon took the opportunity to re-emphasise the established hierarchy of Data Strategy, then Cyber Strategy and (only) then AI Strategy. Tackling AI without having Data and Cyber strategies properly formulated threatens potentially very unhappy outcomes.

The good news, however, is that most Financial Institutions are taking cyber-security seriously, with 62% of Risk Officers telling a recent EY study that it is their next biggest near-term risk – putting it second only to credit risk.[2] 

Cyber-attacks are responsible for a lot of business interruptions at Firms, but they are not the only cause. Minor technical faults, such as configuration errors or badly executed software updates, have been known to spark mass outages, as anyone from CrowdStrike will testify.

Payments are not immune from this sort of disruption either – in 2024, a glitch at Swift resulted in the Bank of England’s CHAPS service briefly going offline.

During BAFT, the Network Manager observed that the number of payment outages at Banks appears to be trending upwards, a temporary teething issue as Firms transition away from their legacy payment infrastructure towards ISO 20022.

Quantum Computing – A new frontier for Operational Resilience

Future-proofing Operational Resilience as new threats emerge is a strategic priority for Banks. That said, with so many unknowns about the origin of these emerging threats and the plethora of possible attack vectors, how Banks are positioned to deal with these developments must be under constant review.

Quantum Computing, still a theoretical field of computer science that deploys Quantum physics to solve highly complex problems in a matter of hours or even minutes,[3] could become one of the biggest challenges yet to face the Financial Services Industry, according to BAFT speakers.

Projected to become mainstream in or around the early 2030s, Quantum Computing could open up a Pandora’s Box of cyber-security risks for the Industry, noted Simon.

This is because Quantum Computing has extraordinary decryption capabilities, meaning it can decode previously encrypted data at Banks (or any Business), including secure communications, digital signatures, identity verification checks, or even information stored on Blockchain.

There is growing speculation that some hostile actors are purposefully harvesting vast troves of sensitive encrypted data gleaned from cyber-attacks, so that one day they can decrypt it using Quantum technology. Steal now and unlock later is a growing concern for the Industry.

Quantum Computing – for now – remains a theoretical concept. Despite this, Banks should – at the very least – be identifying where and how their proprietary data is being stored and protected, before assessing its sensitivity.

Once this information has been mapped out properly, Firms will be better positioned to develop solutions to keep their data safe in a Quantum Computing enabled world.


[1] NCSC – Alert – NCSC advises UK organisations to take action following conflict in the Middle East

[2] EY – February 24, 2026 – Three strategic priorities for banking CROs in 2026

[3] IBM – What is Quantum Computing?