Doctorcrypto About RSS Subscribe
Doctorcrypto
Home › Latest › Banks Have Minutes, Not Weeks, to Fix Flaws as AI Speeds Up Attacks: BIS
Latest

Banks Have Minutes, Not Weeks, to Fix Flaws as AI Speeds Up Attacks: BIS

By Diego Whitfield · · 2 min read

The Bank for International Settlements has warned that artificial intelligence is compressing the window banks have to respond to cyber threats from weeks to mere minutes, rendering traditional patching schedules dangerously obsolete.

AI Rewrites the Attack Clock

According to the BIS, the pace at which attackers can identify and exploit software vulnerabilities has accelerated sharply thanks to AI tools that automate reconnaissance and weaponize flaws almost instantly. Where security teams once had days or weeks to test and deploy fixes, that buffer has all but vanished.

The institution, often described as the central bank for central banks, argues that routine maintenance cycles built around convenience and predictability no longer match the speed of modern threats. The mismatch leaves financial institutions exposed during the gap between a flaw being discovered and a patch being applied.

The luxury of waiting for a scheduled maintenance window may be the very thing that lets attackers in.

Rethinking Downtime and Defense

To close that gap, the BIS points to guidance encouraging banks to embrace planned downtime when urgent fixes are required, rather than deferring critical updates to avoid disrupting services. The message is that short, deliberate interruptions are preferable to prolonged exposure.

The shift represents a cultural change for an industry that has historically prioritized uninterrupted uptime. Financial firms now face pressure to build systems and internal processes capable of absorbing rapid, sometimes unscheduled, security interventions.

For the broader digital economy, including crypto platforms that share infrastructure and threat surfaces with traditional finance, the warning underscores how AI is reshaping the balance between defenders and attackers.

  • Attackers can now exploit vulnerabilities in minutes rather than weeks
  • Routine patching schedules are increasingly viewed as inadequate
  • Banks are urged to accept planned downtime for urgent fixes

The BIS framing suggests that resilience, not just prevention, will define which institutions withstand the next generation of AI-driven attacks.

Was this useful?👍 Yes👎 No