FINRA's 2026 Financial Crimes and Cybersecurity Conference wrapped yesterday in New York — a two-day event that sold out its in-person seats weeks in advance. If your firm wasn't in the room, the throughline is worth catching up on: FINRA built the entire closing day around the idea that cyber intrusions, crypto-enabled crime, and traditional financial fraud have stopped being three separate problems. The final day opened with a plenary titled "The Evolving and Integrated Nature of the Threat: Cyber, Crypto and Financial Crime," and the sessions that followed all pointed the same direction.
That framing matters operationally. Firms that still run AML, cybersecurity incident response, and fraud/investor-protection as three siloed functions — different teams, different escalation paths, different vendors — are structurally behind the threat actors they're trying to catch, since those actors don't respect the same boundaries. A business email compromise attack today is as likely to end in a crypto off-ramp as a wire fraud; an account takeover is as likely to trigger an AML red flag as a cybersecurity incident.
What FINRA highlighted on the final day
- Its intelligence-sharing infrastructure is now a real channel, not a slide. A session on FINRA's "Intelligence Ecosystem" walked through the Financial Intelligence Fusion Center (FIFC) and Cyber & Operational Resilience (CORE) program, along with the specific products firms can pull from them — Threat Intelligence Products (TIPs) and Cyber Event Impact Assessments (CEIAs). If your firm isn't actively enrolled and using these, that's a gap worth closing.
- Third-party and vendor risk is the next systemic exposure point. A CISO Roundtable on cyber resilience focused less on firms' own infrastructure and more on cloud environments, SaaS applications, and critical vendor ecosystems — the parts of a firm's attack surface that live outside its own four walls.
- Senior investor protection got its own dedicated panel. "Fraud Doesn't Retire" covered transaction surveillance, trusted contact and disbursement hold rules, and the regulatory modernization FINRA has proposed in this space — the same proposal we covered in an earlier Insight.
- AI is scaling fraud as fast as it's scaling legitimate business. Sessions on "The Scale of Modern Fraud" and imposter scams described romance investment scams, coordinated impersonation attacks, and AI-enabled social engineering operating at volumes that weren't possible even two years ago — the flip side of the same generative AI tools reshaping how firms communicate with clients, a topic we covered in our recent piece on Rule 2210 modernization.
How Compliers Can Help
Building a financial crime program where AML, cybersecurity, and fraud detection actually talk to each other — rather than operating as separate checkboxes — is core to what we do. See our AML, 3120 & Branch Audits page for how we support integrated testing and supervisory programs like this.
What to do if you weren't in the room
A few practical questions worth asking this week: does your firm actually receive and use FINRA's FIFC/CORE threat intelligence, or does it sit unread? Do your cybersecurity WSPs address third-party and vendor risk specifically, not just your own systems? Are your trusted contact and disbursement hold procedures current, given the renewed regulatory attention on senior investor protection? And do your AML, cybersecurity, and fraud teams have a shared escalation path — or would a single incident touching all three take three separate investigations to piece together?