# Building a system that supports detection, triage and response in the security operations centre inside a bank

Source: https://www.bankingnewsai.com/agentic-banking/build/cybersecurity
Last updated: Sep 17, 2026

Security is the one area where regulators are urging speed: the ECB, New York's DFS and the OCC have all said AI-enabled attackers are faster, and expect AI-enabled defence in return. The pattern is routing and parallelization on live telemetry: enrich an alert from many sources at once, classify, propose a response, and let a person approve any containment action that could disrupt the business. AI-generated code and configuration go through human review before deployment, which DFS has said in so many words.

## The brief (default answers)

| Choice | Answer |
| --- | --- |
| Who is affected | Staff only |
| Reversibility | With cost |
| Stakes | Material |
| Knowledge | Live system state |
| Verifiability | By a rule or a test |
| Steps | Partly |
| Jurisdiction | United States |
| Delivery route | Through a cloud platform |

- **Pattern:** Workflow — Several model calls orchestrated by your code, in a sequence or a graph you designed.
- **Tier:** 2, Tier 2: act with approval — Material but recoverable. The model may prepare and, within limits, act, with a person approving anything that leaves the bank or touches a customer.
- **Workflow shapes:** Routing
- **Human involvement:** The model prepares and may act within limits; a person approves anything that reaches a customer or cannot be undone.
- **Knowledge:** Tool calls to the system of record for anything live. Never retrieval for a balance, a case status or a limit.

## Decomposition

| Step | Owner | Note |
| --- | --- | --- |
| Enrich the alert | system | Parallel tool calls to logs, identity, endpoint and threat intelligence. |
| Classify and summarise | model | Severity, likely technique, affected assets, with sources. |
| Propose containment | model | A ranked set of actions with expected impact. |
| Approve and execute | human | Containment that could disrupt service needs a person; low-impact actions by rule. |
| Draft the incident record | model | From the trace; reviewed before it becomes the record. |

## Control layer weights (0–4)

| Layer | Weight |
| --- | --- |
| governance | 1 |
| identity | 1 |
| actions | 0.9 |
| data | 0.7 |
| models | 1 |
| runtime | 0.8 |
| observability | 0.7 |
| oversight | 0.6 |

## Documents that apply

- [ECB 'Dear CEO' letter on AI-enabled cybersecurity threats (SSM-2026-0301)](https://www.bankingnewsai.com/ai-regulation/documents/ecb-letter-ai-enabled-cybersecurity-threats-2026) — AI models that find and exploit vulnerabilities; action plans due Oct 31, 2026.
- [DFS Frontier AI Models Industry Letter (May 2026)](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-industry-letter-2026-05-21-frontier-ai-models) — Human review of AI-generated code before deployment; shorter patch cycles.
- [23 NYCRR Part 500](https://www.bankingnewsai.com/ai-regulation/documents/ny-dfs-23-nycrr-part-500) — The New York cybersecurity regulation AI guidance hangs on.
- [ESA Statement on ICT risks from frontier AI models (JC 2026 25)](https://www.bankingnewsai.com/ai-regulation/documents/esas-jc-2026-25-frontier-ai-statement) — EU supervisors on ICT risk from frontier models.
- [Treasury AI cybersecurity risks report (Mar 2024)](https://www.bankingnewsai.com/ai-regulation/documents/treasury-ai-cybersecurity-risks-report-2024) — Treasury's map of AI-specific cyber risk for the sector.
- [SR 26-2](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-26-2) — US model risk management as revised in April 2026.
- [SR 23-4](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-23-4) — US third-party risk management, including the model provider.
- [SB 26-189](https://www.bankingnewsai.com/ai-regulation/documents/co-sb26-189) — Colorado: notice, explanation and human review for consequential automated decisions from Jan 1, 2027.
- [BCBS Third-Party Risk Principles (Dec 2025)](https://www.bankingnewsai.com/ai-regulation/documents/bcbs-third-party-risk-principles-2025) — Nth-party supply chains and concentration on cloud providers.
- [BCBS ICT Risk Management Report (June 2026)](https://www.bankingnewsai.com/ai-regulation/documents/bcbs-ict-risk-management-range-of-practices-2026) — How supervisors look at ICT and cloud dependencies.
- [OCC Bulletin 2026-13](https://www.bankingnewsai.com/ai-regulation/documents/occ-bulletin-2026-13) — For a national bank, the OCC's copy of the 2026 model-risk guidance.
- [NIST AI RMF 1.0](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1) — The voluntary Govern, Map, Measure, Manage frame for everything model-risk guidance leaves out.

## Evals

- A golden dataset of at least 150 real cases with expected outputs, including adversarial inputs: wrong documents, unusual formats, prompts that try to change the task.
- Code-based checks on every output: schema conformance, required fields, reconciliations against the system of record. Threshold: 99% or better before launch, every run in production.
- Trace evals per step, not only end to end: which step fails, how often, at what cost, so a prompt or model change can be judged step by step.
- The same suite reruns on every prompt change, model version change and retrieval change; a regression blocks the release. That is what ongoing monitoring and outcomes analysis mean in model-risk terms.

## Human gates

- Per-action approval by a competent reviewer for anything customer-facing or irreversible; sampled review for the rest.
- Validation proportionate to materiality, with monitoring for drift on inputs and outputs.
- An escalation route to a person that the customer can reach in one step.
- Monthly review of the evals and the exception log by the accountable owner.

## What an examiner will ask

- Where is this system in your inventory, what tier did you assign, and who signed it off?
- What counts as a model here, and what does your validation cover for the parts that are not?
- Show me the data lineage behind the retrieval set and the training or tuning data.
- What can the system do without a person, and where is that written down?
- How do you know it is still working: which evals run, how often, and what happened the last time one failed?
- What did you do about the vendor: due diligence, contract, exit plan, concentration?
- Walk me through one wrong output from production and what the customer, if any, saw.
- Who can switch it off, and has that been tested?

## What the board should hear

- What it does: supports detection, triage and response in the security operations centre; the model prepares and may act within limits; a person approves anything that reaches a customer or cannot be undone.
- Pattern: workflow (routing); tier 2: act with approval.
- Rules it answers to: 4 documents across US, each linked in the brief.
- How we know it works: a golden dataset, automated checks on every release, and human review at the level the tier demands.
- What could go wrong and who answers: the accountable owner, the kill switch, the escalation route.

## Pitfalls

- Automated containment with no envelope, taking down a payment system.
- AI-generated detections or patches deployed without review.
- Telemetry fed to a model outside the bank's data boundary.

Change any answer on the interactive map: https://www.bankingnewsai.com/agentic-banking/build/cybersecurity

---

Canonical page: https://www.bankingnewsai.com/agentic-banking/build/cybersecurity
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (19 authorities, 166 documents) and AI-strategy profiles of the 100 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
