Latest Posts

Stay in Touch With Us

Got a story worth telling? Send it our way. We read every tip that lands in our inbox.

Livebriefs

  /  All News   /  DERIVSOURCE: AI-Powered Cyber Threats Raise Stakes for Derivatives Markets

DERIVSOURCE: AI-Powered Cyber Threats Raise Stakes for Derivatives Markets

  

Artificial intelligence is changing the cybersecurity threat facing derivatives firms, accelerating attacks and putting greater pressure on clearing firms, exchanges and other market participants to respond quickly when systems are compromised.

Aaron Charfoos

Speaking during FIA’s Cleared for Risk: Cyber, Privacy & AI Threats Facing the Derivatives Industry webinar on September 17, Aaron Charfoos and Michelle A. Reed, partners and co-chairs of the Data Privacy and Cybersecurity practice at Paul Hastings, examined how cyber threats are intersecting with clearing, third-party technology, regulation and the move toward 24/7 markets.

Charfoos said artificial intelligence is making familiar cyberattack techniques more effective, pointing to CrowdStrike data showing an 89% year-over-year increase in AI-enabled adversary operations: “Artificial intelligence is taking again kind of the old school cybersecurity hacking techniques and making them much much more dangerous.”

According to FIA, the time available to respond is also shrinking. According to data presented during the webinar, the average time for a threat actor to move beyond an initial intrusion and through an organization has fallen to about 29 minutes, while the fastest observed breakout was 27 seconds. CrowdStrike data presented by the speakers also showed that 82% of detections in 2025 were malware-free.

Source: FIA webinar slide

Charfoos said CrowdStrike had recently observed fully autonomous AI attacks in which, after the initial launch, AI moved through an enterprise, gathered information and sent it out without further human involvement. “That’s important because a lot of the old techniques that we had to look for, kind of data coming out and trying to disrupt people once it gets in, will need to be updated to try to stop these fully autonomous agents from moving around the enterprise,” he said.

Charfoos said cyber incidents can extend beyond the organization initially targeted because exchanges, clearinghouses, clearing members and end clients rely on shared infrastructure. “A single piece of ransomware doesn’t just affect one company; it affects multiple companies,” he said.

Michelle A. Reed

Both Charfoos and Reed pointed to the 2023 ransomware attack on ION Markets as an example of how a cyber incident at a third-party provider can spread across the derivatives ecosystem. ION provided middle- and back-office technology embedded in clearing workflows across multiple firms. Following the attack, some firms manually reconstructed trading records, while recovery took up to two weeks for some affected clearing firms.

According to FIA, the association held four conference calls on the first day of the disruption, while its industry calls grew to more than 700 participants by the end of the week. FIA subsequently established its Cyber Risk Taskforce to examine the incident and develop recommendations for strengthening resilience across cleared derivatives markets. “When you look at the interconnectedness of the market and how much overlap there is in technologies that are used, you are only as strong as your weakest link in the supply chain,” Reed said.

Market participants rely on outside providers for functions including market data, trade processing, reconciliation, collateral management and risk calculations. FIA’s taskforce has recommended standardizing third-party risk assessment questionnaires and calibrating oversight according to the service provided and the potential impact of a disruption.

Reed said firms also need to understand their notification obligations to exchanges when a cyber incident affects trading or communications, separate from regulatory reporting requirements. “All of these complexities of third-party vendor risk demonstrate that you have a lot of work to do in connection with evaluating your vendors, continuing to evaluate your vendors, and then ultimately communicating when you have a disruption,” she said.

24/7 trading adds another challenge

The push toward 24/7 derivatives trading introduces additional cybersecurity considerations, according to the speakers. FIA said in May 2025 that it did not support extending trading and clearing in CFTC-regulated derivatives markets to a 24/7 basis until operational, infrastructure, risk, compliance and regulatory issues had been “systematically identified, assessed, and resolved.”

Charfoos pointed to maintenance as one practical challenge. Existing cybersecurity programs often use scheduled downtime to install and test software patches, something that becomes more difficult when markets operate continuously. “If you close that maintenance window, you need to make sure that you have a very strong vulnerability patch management program in place that’s ready to go,” he said.

Charfoos said continuous trading would also put additional demands on security operations centers, with firms needing sufficient staffing across time zones and technology to handle the increased flow of information while markets remain active.

Meanwhile, recovery presents another issue, according to Charfoos: “If you do have an incident, if you’re lucky enough, it happens overnight, and you can get things fixed and back up, trading ready for the trading day again. 24/7, we don’t have the luxury of that window.”

Source: FIA

The speakers also emphasized how quickly incident-response decisions now need to be made. FIA’s framework divides the process into three stages: response, recovery and reconnection. The last can require firms to reconnect with exchanges, CCPs and service providers while addressing margin obligations, segregated customer funds, positions and counterparty exposures.

With the average breakout time measured in minutes, Reed said firms need to be prepared before an attack occurs. “That means that your response must be measured in minutes, not hours, not days, not weeks, but minutes,” she warned.

   

You don't have permission to register