2026 FinTech Predictions: Insights from Matthew McCormack of Finastra
Finastra's CISO discusses how security and resilience are taking centre stage in financial services as key enablers of trust and dependability.
I spoke with Matthew McCormack, Chief Information Security Officer at Finastra, a global leader in financial services software. As a leader in cybersecurity and risk management, Matthew is responsible for overseeing Finastra's security strategy and frameworks, and for safeguarding sensitive financial data. His insights reflect the critical importance of security and resilience in an increasingly complex threat environment.
Over to you Matthew - my questions are in bold:
How are security and resilience taking centre stage in financial services?
For many years, security and resilience sat behind-the-scenes of financial services strategy. They were essential, but rarely visible or celebrated. In 2026, that reality has clearly changed. Security is no longer viewed as a background function. It has become one of the clearest signals of institutional strength, customer trust, and long‑term competitiveness.
This shift is not the result of hype or trend chasing. It reflects the reality financial institutions now operate in. Banks are moving faster than ever, adopting artificial intelligence, modernising core platforms, and opening their digital ecosystems to partners at scale. At the same time, the cost of failure has increased sharply. Outages, data breaches, or prolonged downtime now carry immediate operational and reputational consequences. In this environment, resilience is not just about recovering quickly. It is about building systems that customers and regulators can consistently rely on.
Insights from Finastra's Financial Services State of the Nation 2026 survey, which gathered perspectives from more than 1,500 financial services professionals across 11 global markets, highlights how deeply this mindset has taken hold. Four in ten institutions now place security investment at the top of their priority list, with spending expected to rise sharply in the year ahead. Security is no longer treated as a technical safeguard. It has become a strategic decision.
What's the impact of technology innovation?
What has changed is not the pace of innovation, but the level of responsibility attached to it. Technology decisions now sit at the intersection of trust, customer experience, and regulatory confidence.
Artificial intelligence illustrates this clearly. Almost every institution surveyed is already using AI in some form, and many describe it as central to how they detect fraud, assess risk, support customers and automate decisions. For many organisations, AI has become the intelligence layer connected data, channels, and services.
But AI only performs as well as the environment it operates in. Legacy systems, fragmented data, and inconsistent controls create risk at exactly the moment banks are becoming more dependent on automation. Modernisation is no longer an option. It is a prerequisite for safe innovation.
Institutions are focusing their efforts on digital transformation, cloud adoption, modern data platforms, and core banking renewal. Together, these capabilities strengthen resilience by making systems more scalable, more transparent, and easier to govern. Without them, even advanced tools struggle to deliver reliable outcomes.
Why is security investment so important in 2026?
As institutions modernise, the threat landscape expands alongside them. Attack surfaces are broader, ecosystems more connected, and AI introduces new risks if it is not governed carefully.
In response, security has emerged as the defining investment priority for 2026. Organisations anticipate an average 40% increase in security spending, reflecting a more mature view of its role. Security is no longer seen primarily as a cost or blocker. It is increasingly understood as the foundation of customer trust and operational continuity.
Over the past year, many institutions have strengthened their core defences. Advanced fraud detection, modern security monitoring, automated response capabilities, stronger authentication, and improved backup and recovery have become widely adopted. These investments point to a shift towards integrated security models that can respond quickly and consistently.
Attention is now turning towards the protection of digital connections. As open architecture and application programming interfaces become central to growth strategies, securing those gateways is critical. In a connected financial ecosystem, trust depends on the durability and integrity of every interaction.
How can institutions build resilience?
Technology investment is not enough. Many institutions continue to face skills shortages and budget pressure, which can slow progress. To address this, a growing number are working more closely with fintechs and specialist providers.
These partnerships are not simply about speed. They reflect an understanding that security, AI, and modernisation are tightly linked. No single organisation can master every domain, but the right collaborators can help institutions embed resilience into their operating model rather than layering it on later.
Can dependability be a differentiator?
The convergence of AI, modernisation, and security is reshaping how success is defined in financial services. The institutions that stand out will not be those that promise the most features of move the fastest. They will be the ones that deliver consistently, transparently, and securely.
Customers expect systems that work. Regulators expect systems that are resilient by design. In this environment, dependability becomes a competitive advantage.
As the industry looks beyond 2026, the message from the industry is unmistakable. Security and resilience are no longer supporting functions. They are the standards by which modern financial institutions will be judged, and the foundation on which sustainable innovation will be built.
Thank you Matthew! You can connect with Matthew on his LinkedIn Profile and find out more about the company at finastra.com.