When Theory Meets the Trading Floor

Designing an AI-powered cybersecurity platform for the financial sector is one thing. Deploying it where it actually matters, inside real banking systems, against real threat scenarios, with real regulatory obligations on the line, is another challenge entirely.

This is precisely where GFT’s contribution to the CyberAId project becomes critical. As the leader of Work Package 6 (Use Cases Integration, Validation and Evaluation), GFT is the bridge between the cutting-edge technologies developed by the consortium and the operational realities of the European financial sector. Our role is not simply to test software in a lab: it is to ensure that CyberAId’s integrated platform proves its value where the stakes are highest.

The Validation Challenge in Financial Cybersecurity

The financial sector is not a forgiving environment for cybersecurity solutions. Banks, investment managers, payment service providers and trading firms operate under strict regulatory frameworks (i.e. DORA, NIS2, MiFID II, GDPR) and face a threat landscape that is growing in both sophistication and frequency. According to data, cyberattacks on financial institutions have increased by 238% since 2020, with breaches costing an average of $6.08 million per incident.

Validating a cybersecurity platform in this environment requires more than a checklist. It requires co-creation: sitting alongside security teams, understanding their operational workflows, and designing test scenarios that reflect genuine threats. This is the philosophy that guides GFT’s approach in CyberAId.

Four Pilots, Four Real-World Contexts

At the heart of WP6 are four pilot deployments, each addressing a distinct financial sub-sector and a distinct set of cybersecurity challenges.

Pilot 1 tackles client impersonation detection in private banking and asset management. Smaller asset managers often relay client orders to larger custodian institutions via email, creating security gaps that sophisticated attackers exploit, deliberately keeping fraudulent instructions below standard verification thresholds to evade detection. The pilot implements federated learning across institutions to develop shared impersonation detection models without exposing sensitive client data, combining LLM-based content analysis with adaptive monitoring capabilities.

Pilot 2 addresses anti-money laundering (AML) detection for payment service providers, using advanced graph analytics, log correlation and LLM-enhanced alert investigation. Traditional rule-based AML systems generate excessive false positives (often exceeding 95%) while still missing sophisticated laundering techniques. CyberAId’s layered approach aims to cut false positives by more than half while improving detection of complex laundering patterns.

Pilot 3, run with a major European banking institution, focuses on multi-channel anomaly detection and AI-assisted incident response. The pilot brings together eBPF-enhanced network monitoring, real-time transaction analysis and generative AI decision support, targeting reductions of over 60% in false positive alerts and more than 50% in mean time to respond to incidents.

Pilot 4 protects the operations of a high-frequency and algorithmic trading firm, where the stakes include proprietary algorithm integrity, market data feed reliability and strict BaFin regulatory reporting. Even milliseconds matter here: the pilot targets less than 5 milliseconds of additional latency impact on trading operations, while achieving over 95% accuracy in detecting unauthorised access or manipulation.

GFT’s Role: Orchestrating Co-Creation

GFT’s experience in financial technology makes us well-placed to lead this validation effort. In CyberAId, we contribute across multiple workpackages (from security information modelling and digital forensics in WP5 to dissemination and ecosystem building in WP7) but it is in WP6 where our domain expertise most directly shapes the project’s outcomes.

Within CyberAId, GFT’s team is actively engaged in coordinating pilot co-creation and specification activities, contributing to the security information modelling underpinning the platform’s forensic capabilities, and building the bridges to the wider European cybersecurity ecosystem through cluster and association outreach. Across all these activities, the focus remains firmly on what CyberAId is designed to deliver: a platform that is technically sound, operationally credible and ready for adoption across the financial sector.

Co-creation in this context means involving pilot partners from day one — defining relevant attack scenarios, agreeing on data assets, mapping regulatory reporting requirements and iterating on platform configurations based on live feedback. It is a process that demands both technical depth and the ability to communicate clearly with diverse stakeholders, from security analysts and compliance officers to executive leadership.

From Blueprints to Operational Reality

The CyberAId platform is built on a sophisticated stack: open-source SIEM and XDR tools (Wazuh), LLM-based orchestration agents, digital twin environments for risk-free testing, privacy-preserving federated learning and quantum-resistant cryptography. The reference architecture and blueprints developed in WP2 provide the technical foundation. But it is in WP6 that these components are stress-tested against operational reality.

This validation process unfolds in two cycles. The first evaluates individual components against predefined benchmarks in simulated environments. The second deploys the integrated solution in real or near-live pilot environments, measuring performance against both technical KPIs (detection accuracy, response times, false positive rates) and business value indicators such as analyst satisfaction and regulatory compliance assurance.

The insights flowing back from pilots to the technical workpackages are just as important as the results themselves. When a detection threshold needs adjustment for the specific patterns of a trading platform, or when a regulatory reporting workflow needs adaptation for a particular jurisdiction, these lessons directly improve the platform for all future adopters.

Building Trust Across the Financial Sector

Ultimately, the goal of CyberAId is not just to produce a validated platform, it is to build trust. Trust that AI-driven cybersecurity tools can genuinely operate within the regulatory and operational constraints of the financial sector. Trust that LLM-based orchestration can augment, rather than replace, the judgment of experienced security professionals. And trust that the collective intelligence shared across institutions through federated learning strengthens everyone’s defences without compromising anyone’s data.

GFT is proud to be at the centre of this process, ensuring that what begins as a blueprint becomes, through rigorous co-creation and validation, a living reality for European financial institutions.