The thousand-franc cyberattack: repricing risk
An executive briefing for senior leaders in financial services on what changes when AI-scale cyber attacks cost a few thousand francs. StratEdge × Surelio.ai
Co-hosted by StratEdge × Surelio.ai
The economics of being attacked have just changed.
A cyberattack used to require time, expertise, and coordination. Not anymore.
In April 2026, the UK AI Security Institute reported that Anthropic’s Claude Mythos executed a corporate-network intrusion end to end — a task that takes a skilled professional roughly twenty hours, now performed autonomously at a cost of a few thousand francs per attempt. Weeks later, OpenAI’s GPT-5.5 reached the same level of capability — and, unlike Mythos, is accessible through standard commercial channels.
AI attack capability is now fast, repeatable, and accessible. The cost of being attacked is not.
For Swiss and European financial institutions, average breach cost runs into millions of CHF or EUR — before any supervisory consequences under DORA, FINMA, or NIS2. The economic asymmetry is no longer abstract. It is industrial.
The cost of waiting is now measured in posture decay against a threat environment strengthening week by week. That is the business case for this session.
Four exposures that just changed curve.
Every one of the exposures below now sits on a different curve from six months ago.
Trust.
Protecting the confidence of clients, supervisors, and counterparties that the institution remains defensible.
Continuity.
Keeping critical services and transaction flows running, including across vendor and third-party dependencies — the explicit focus of DORA.
Accountability.
Evidencing operational resilience to supervisors, insurers, and stakeholders, to the standard DORA and FINMA now expect.
Financial exposure.
Sizing the full impact across financial, operational, organisational, and reputational dimensions.
What you will learn.
- 01
Where cyber disruption becomes material financial exposure, and what that now means under DORA and FINMA expectations.
- 02
Which defence and recovery assumptions silently fail under real pressure, and what to reassess before supervisors do.
- 03
What insurers, supervisors, and stakeholders will expect to see, and where the gaps most often emerge.
- 04
What leadership teams should align on in the next ninety days, to move from awareness to readiness.
Practical details.
- Date
- 4 June 2026
- Time
- 12:30–13:30 CET
- Format
- 60 minutes online, including live Q&A
- Hosted by
- StratEdge × Surelio.ai
- Registration
- Via Livestorm — link below
Registration is handled by Livestorm. You will receive a calendar invitation and the dial-in link by email after registering.
