An Adaptive Risk-Quantification and Zero-Trust Governance Framework for Safeguarding U.S. Digital Banking Infrastructure Against AI-Driven and Third-Party Cyber Threats
- Authors
-
-
Abilly Elly
Texas UniversityAuthor
-
- Keywords:
- Zero-Trust Architecture, Cyber Risk Quantification, AI-Driven Threats, Third-Party Risk Management, Digital Banking Security, Adaptive Governance
- Abstract
-
The rapid digitalization of U.S. banking infrastructure, accelerated by open banking mandates, cloud migration, and artificial intelligence integration, has fundamentally expanded the cyber-attack surface while introducing systemic vulnerabilities through third-party service provider concentration. Traditional perimeter-centric security models and static risk-assessment frameworks are structurally inadequate to counter AI-enabled threats that operate at machine speed and exploit interconnected financial ecosystems. This study addresses the critical gap in financially-aware, adaptive cybersecurity governance for banking institutions through design-based research that develops, simulates, and validates the Adaptive Zero-Trust Risk Governance (AZTRG) framework. The framework integrates three core components: a Conditional Value-at-Risk (CVaR) quantification engine for financial exposure modeling, an AI-enhanced behavioral identity scoring system for continuous trust evaluation, and a business-aligned micro-segmentation architecture for third-party risk containment. Monte Carlo simulation across 5,000 threat scenarios demonstrates that AZTRG achieves 89.4% automated threat containment within 47 seconds of detection, compared to 53.2% for baseline Zero-Trust implementations, while reducing mean financial exposure from successful attacks by 72.3%. The framework provides the first validated governance model that explicitly incorporates transactional semantics, dynamic risk tolerance, and regulatory compliance into Zero-Trust decision engines. For banking practitioners, AZTRG offers measurable improvements in resilience against correlated, AI-driven attacks; for policymakers, it establishes a replicable methodology for systemic risk supervision in an era of accelerating digital dependency.
- Downloads
- Published
- 07/30/2026
- Section
- Articles
- License
-
Copyright (c) 2026 Abilly Elly (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.
