FINRA's 2026 Financial Crimes and Cybersecurity Conference wrapped yesterday in New York — a two-day event that sold out its in-person seats weeks in advance. If your firm wasn't in the room, the throughline is worth catching up on: FINRA built the entire closing day around the idea that cyber intrusions, crypto-enabled crime, and traditional financial fraud have stopped being three separate problems. The final day opened with a plenary titled "The Evolving and Integrated Nature of the Threat: Cyber, Crypto and Financial Crime," and the sessions that followed all pointed the same direction.

That framing matters operationally. Firms that still run AML, cybersecurity incident response, and fraud/investor-protection as three siloed functions — different teams, different escalation paths, different vendors — are structurally behind the threat actors they're trying to catch, since those actors don't respect the same boundaries. A business email compromise attack today is as likely to end in a crypto off-ramp as a wire fraud; an account takeover is as likely to trigger an AML red flag as a cybersecurity incident.

What FINRA highlighted on the final day

How Compliers Can Help

Building a financial crime program where AML, cybersecurity, and fraud detection actually talk to each other — rather than operating as separate checkboxes — is core to what we do. See our AML, 3120 & Branch Audits page for how we support integrated testing and supervisory programs like this.

What to do if you weren't in the room

A few practical questions worth asking this week: does your firm actually receive and use FINRA's FIFC/CORE threat intelligence, or does it sit unread? Do your cybersecurity WSPs address third-party and vendor risk specifically, not just your own systems? Are your trusted contact and disbursement hold procedures current, given the renewed regulatory attention on senior investor protection? And do your AML, cybersecurity, and fraud teams have a shared escalation path — or would a single incident touching all three take three separate investigations to piece together?

This article is based on the published agenda for FINRA's 2026 Financial Crimes and Cybersecurity Conference, held August 10-11, 2026 in New York, NY (finra.org/events-training/conferences-events/2026-financial-crimes-cybersecurity-conference). Session content is summarized from publicly available session descriptions; Compliers did not attend in person. This summary is provided for general informational purposes and is not legal advice.