Eine Frau und ein Mann arbeiten in einem IT-Raum und besprechen sich vor einem Bildschirm.

Cybersecurity and AI

IT security and resilience in the age of AI

Artificial intelligence is one of the major issues of our time. On the one hand, it holds the promise of making complex workflows and multi-layered processes more efficient and systematic. On the other hand, it also brings greater challenges: the same technology is available to attackers. Regulatory requirements and the risk of cyber threats – which have taken on a new urgency with AI – demand consistent and sophisticated security strategies. Key factors here are control over data flows and compliance with data protection and security standards. In addition to prevention and defence, the focus today is increasingly on ensuring that systems remain operational under stress and can be restored in the event of an emergency.

The situation report published by the Federal Office for Information Security (BSI) in November 2025 illustrates how this threat landscape is changing: the situation remains tense; phishing, fraud and identity theft continue to be among the key threats. AI has an impact in two ways. It lowers the barrier to carrying out deception attacks. Fraudulent messages are linguistically flawless and tailored to the individual, whilst voices and video footage can be replicated to look deceptively real as so-called ‘deepfakes’. On the other hand, however, AI also supports fraud prevention by analysing transactions in real time, identifying vulnerabilities more quickly, detecting anomalies and new fraud patterns, and thus improving prevention systems and risk assessment.

A regulatory framework for this is provided, amongst other things, by DORA, MaRisk and the EU AI Regulation (AI Act), which sets out risk-based requirements for the development, deployment and use of AI systems. These requirements place considerable demands on banks, but also have transformative potential, as they enable the establishment of robust structures, resilient processes and effective control mechanisms. Cyber resilience is not achieved through individual technologies alone, but through a robust architecture, transparency and clear lines of responsibility.

Digital sovereignty, data protection and information security

The Savings Banks Finance Group’s AI strategy is being further developed under the leadership of the DSGV, in collaboration with the savings banks, the DSV Group and Finanz Informatik (FI). The DSV Group develops AI solutions, is responsible for content and quality assurance, and brings in external technology partners. Finanz Informatik focuses on the secure integration of AI into the central IT infrastructure and the operation of its own AI platforms.

Through its data centres, FI operates a significant part of the network’s digital infrastructure. Its AI solutions focus on digital sovereignty, the protection of customer data and information security. The AI models used for this purpose are operated within the company’s own infrastructure and do not require a connection to public cloud services.

This is evident in the AI assistant S-KIPilot (SKIP), which was developed for the day-to-day operations of the savings banks, is integrated into Outlook and other applications, and accesses internal knowledge systems – ranging from regulatory frameworks to core banking, customer and advisory data. Institution-specific data is segregated in accordance with client requirements; in addition, S-KIPilot can access authorised knowledge sources from within the network.

For the Savings Banks Finance Group, a key objective is to be able to use digital infrastructures securely and independently. The data centres operated by Finanz Informatik, their secure systems and AI applications form an important building block in ensuring IT security and resilience, even in the age of AI. However, this does not mean the task is complete: attack methods and technologies are constantly evolving. IT security and resilience therefore remain an ongoing challenge.