Expert

Regulatory requirements and cyber threats - what lies ahead for the banking job market in the near future?

Banking in 2026 can be likened to a fortress under constant attack. On the one hand, it is being hit by a growing wave of cyberattacks, fueled by geopolitical tensions and hybrid warfare. On the other hand, the sector faces regulatory pressure from DORA, which requires financial institutions to demonstrate unprecedented resilience.

Table of contents

Banking in 2026 can be likened to a fortress under constant attack. On the one hand, it is being hit by a growing wave of cyberattacks, fueled by geopolitical tensions and hybrid warfare. On the other hand, the sector faces regulatory pressure from DORA, which requires financial institutions to demonstrate unprecedented resilience. Meanwhile, as hard data shows, the weakest point of this fortress is not technology, but a critical shortage of guards capable of defending it, qualified cybersecurity experts. 

According to data from the latest ISC2 Cybersecurity Workforce Study1, the global cybersecurity talent gap stands at a staggering 4.8 million experts. The latest update to this analysis – ISC2 Hiring Trends 20252 (published in mid-2025) – points to a significant shift, particularly acute for the banking sector: currently, 90% of managers prioritise practical IT experience over formal education. This creates a kind of “bottleneck”: banks need experienced practitioners to protect critical infrastructure, but the market cannot supply them. 

The implications of this situation are detailed in the Fortinet 2025 Cybersecurity Skills Gap Report3. Its findings show that 54% of IT leaders attribute incidents to a lack of cybersecurity skills and training, and as many as 86% of organisations reported a breach of this type in the past year. For financial institutions, this is particularly alarming. Given the requirements of the Digital Operational Resilience Act (DORA), the shortage of personnel in the banking sector will become a direct operational risk by 2025. 


Caught between DORA and escalating cyber threats - banks as a frontline target 

Cyberattacks targeting the banking sector are no longer merely “standard” cybercrime; today, they constitute one of the key instruments of modern hybrid warfare. DDoS attacks on payment systems are primarily intended to destabilise the economy. Advanced phishing and disinformation campaigns target customers, undermining fundamental trust in financial institutions. At the same time, ransomware targets banks as critical infrastructure, threatening to paralyse systems. 

This means that banks today need experts who can think in the adversary’s terms. Threat Intelligence Analysts, who combine technological expertise with an understanding of the broader geopolitical context, are gaining increasing attention. This enables them to anticipate potential attack vectors before they materialise. 

DORA: The end of the “technician” era 

At the same time, regulatory pressure is beginning to weigh heavily on financial institutions. The full implementation of the DORA (Digital Operational Resilience Act) not only redefines the sector’s operating principles but also fundamentally changes recruitment requirements. 

DORA requires banks to build comprehensive operational resilience and adopt a holistic approach to digital risk that encompasses the entire organisation. This marks the definitive end of the siloed model, in which cybersecurity operated exclusively as the IT department's domain. In the new regulatory environment, a security specialist must have an equally strong understanding of business processes, operational risk management, and compliance requirements. 

The market is increasingly seeking “unicorns.” We’re talking about specialists with hybrid competencies, such as Cyber Risk & Compliance Specialists, who combine advanced technical knowledge with proficiency in financial regulations, including DORA, KNF guidelines, and EBA regulations. This further limits the already modest pool of available experts. Today, it is not enough to be an outstanding engineer. A modern specialist should combine technical, legal, and strategic skills. 

Why are banks losing battles for talents? 

The problem is that the small group of experts who meet these criteria is in extremely high demand, and banks are rarely their first choice. A fierce battle for talent is underway, with financial institutions competing not only against global tech giants like Google and Microsoft but also against dynamic fintech companies. 

In this battle, banks generally fare poorly in terms of image. They are perceived as rigid organisations, full of procedures and burdened by bureaucracy, while the tech sector attracts talent with its flexibility, culture of innovation, and faster career paths. This is particularly true in the area of cloud technologies. Banks, which are often playing catch-up in their migration to the cloud, urgently need cloud security engineers, competing for them with companies that have operated in a cloud environment from the start. 

The Most In-Demand Roles in 2026 

Antal’s research indicates that the staffing shortage is not a general issue but affects clearly defined, niche specialisations. So which experts does the financial sector need most? According to forecasts, the top roles include: 

  • Cloud Security Engineer – an expert in securing cloud infrastructure, essential in the context of the ongoing migration of banking systems and the growing regulatory requirements resulting from DORA. 
  • Threat Intelligence Analyst – a specialist who analyses threat data, capable of predicting trends and responding to geopolitical and hybrid attacks. 
  • Cyber Risk & Compliance Specialist – the aforementioned hybrid role, combining IT, security, and legal expertise, which is key to the effective implementation and maintenance of DORA compliance. 
  • Incident Response Manager – a person responsible for responding quickly and effectively to incidents, minimising the impact of ransomware or DDoS attacks. 
  • Security Awareness Trainer – a specialist who builds a “human shield” by educating employees and customers, reducing the risk of phishing and other social engineering attacks. 

The recruitment paradox: hire quickly, but carefully 

The problem is that recruiting these five types of experts presents financial institutions with an almost unsolvable paradox. On the one hand, every month a key cybersecurity position remains vacant increases the real risk of an incident and requires immediate action. 

On the other hand, banks cannot afford to make a mistake - hiring someone who lacks the necessary competencies, and in extreme cases poses an internal threat, risks not only financial losses in the millions but, above all, a loss of reputation and customer trust. Balancing speed with caution has therefore become a daily recruitment challenge in the financial sector. 

A strategic partner, not just a CV provider 

Internal reskilling programs and partnerships with universities remain a valuable component of HR strategy, but they are long-term in nature and do not provide quick fixes for urgent skill gaps. In 2026, faced with such specific challenges, banks must stop viewing recruitment solely as an HR process and start treating it as a strategic pillar of strengthening security. 

The key lies in collaborating with specialised recruitment partners - those who are not merely CV providers but possess an international network of passive candidates and a deep understanding of this narrow niche where cybersecurity, finance, and rigorous compliance expertise intersect. 

It is precisely this kind of synergistic collaboration that can determine a bank’s operational stability in the digital world. 


 

Published: March 30, 2026 by Malwina Przewdzięk

Take care of your business development today.

Contact me and together we will find solutions that will help you achieve your goals.

Malwina Przewdzięk

Senior Consultant