<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article">
 <front>
  <journal-meta>
   <journal-id journal-id-type="publisher-id">
    jcc
   </journal-id>
   <journal-title-group>
    <journal-title>
     Journal of Computer and Communications
    </journal-title>
   </journal-title-group>
   <issn pub-type="epub">
    2327-5219
   </issn>
   <issn publication-format="print">
    2327-5227
   </issn>
   <publisher>
    <publisher-name>
     Scientific Research Publishing
    </publisher-name>
   </publisher>
  </journal-meta>
  <article-meta>
   <article-id pub-id-type="doi">
    10.4236/jcc.2025.1311014
   </article-id>
   <article-id pub-id-type="publisher-id">
    jcc-147584
   </article-id>
   <article-categories>
    <subj-group subj-group-type="heading">
     <subject>
      Articles
     </subject>
    </subj-group>
    <subj-group subj-group-type="Discipline-v2">
     <subject>
      Computer Science 
     </subject>
     <subject>
       Communications
     </subject>
    </subj-group>
   </article-categories>
   <title-group>
    AI-Driven Cybersecurity Challenges in Bangladesh’s Banking Industry
   </title-group>
   <contrib-group>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Aslam
      </surname>
      <given-names>
       Khan
      </given-names>
     </name> 
     <xref ref-type="aff" rid="aff1"> 
      <sup>1</sup>
     </xref>
    </contrib>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Bikash Kumar Saha
      </surname>
      <given-names>
       Roy
      </given-names>
     </name> 
     <xref ref-type="aff" rid="aff2"> 
      <sup>2</sup>
     </xref>
    </contrib>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Aktaruzzaman
      </surname>
      <given-names>
       Sarker
      </given-names>
     </name> 
     <xref ref-type="aff" rid="aff2"> 
      <sup>2</sup>
     </xref>
    </contrib>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Syed Noman
      </surname>
      <given-names>
       Abedin
      </given-names>
     </name> 
     <xref ref-type="aff" rid="aff2"> 
      <sup>2</sup>
     </xref>
    </contrib>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Md. Mominul
      </surname>
      <given-names>
       Islam
      </given-names>
     </name> 
     <xref ref-type="aff" rid="aff2"> 
      <sup>2</sup>
     </xref>
    </contrib>
    <contrib contrib-type="author" xlink:type="simple">
     <name name-style="western">
      <surname>
       Moinul
      </surname>
      <given-names>
       Zaber
      </given-names>
     </name> 
     <xref ref-type="aff" rid="aff2"> 
      <sup>2</sup>
     </xref>
    </contrib>
   </contrib-group> 
   <aff id="aff1">
    <addr-line>
     aColangelo College of Business, Grand Canyon University, Phoenix, Arizona, USA
    </addr-line> 
   </aff> 
   <aff id="aff2">
    <addr-line>
     aDepartment of Computer Science and Engineering, World University of Bangladesh, Dhaka, Bangladesh
    </addr-line> 
   </aff> 
   <pub-date pub-type="epub">
    <day>
     05
    </day> 
    <month>
     11
    </month>
    <year>
     2025
    </year>
   </pub-date> 
   <volume>
    13
   </volume> 
   <issue>
    11
   </issue>
   <fpage>
    223
   </fpage>
   <lpage>
    235
   </lpage>
   <history>
    <date date-type="received">
     <day>
      24,
     </day>
     <month>
      September
     </month>
     <year>
      2025
     </year>
    </date>
    <date date-type="published">
     <day>
      24,
     </day>
     <month>
      September
     </month>
     <year>
      2025
     </year> 
    </date> 
    <date date-type="accepted">
     <day>
      24,
     </day>
     <month>
      November
     </month>
     <year>
      2025
     </year> 
    </date>
   </history>
   <permissions>
    <copyright-statement>
     © Copyright 2014 by authors and Scientific Research Publishing Inc. 
    </copyright-statement>
    <copyright-year>
     2014
    </copyright-year>
    <license>
     <license-p>
      This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/
     </license-p>
    </license>
   </permissions>
   <abstract>
    This report delves into the key challenges and opportunities that banks in Bangladesh face in adopting AI-powered cybersecurity measures. It highlights several critical issues, such as a lack of skilled cybersecurity personnel, insufficient employee training, limited use of AI in banking operations, and obstacles to AI adoption. These problems prevent banks from fully harnessing the potential of AI to tackle the growing complexity of cyber threats. To address these challenges, the report offers practical recommendations, including expanding cybersecurity teams with AI expertise, improving training programs for employees, broadening AI applications across various banking functions, optimizing existing AI systems, and adopting AI-specific compliance frameworks. The report also underscores the need for collaboration between banks, regulators, and tech providers to enhance regulatory support and access to advanced AI tools. Ultimately, it stresses the urgency for Bangladesh’s banking sector to address AI-driven cybersecurity threats and implement best practices to protect sensitive information, improve efficiency, and build resilience against evolving cyber risks.
   </abstract>
   <kwd-group> 
    <kwd>
     AI-Powered Cybersecurity
    </kwd> 
    <kwd>
      Banking Sector
    </kwd> 
    <kwd>
      Cybersecurity Personnel
    </kwd> 
    <kwd>
      AI Adoption
    </kwd> 
    <kwd>
      Regulatory Support
    </kwd>
   </kwd-group>
  </article-meta>
 </front>
 <body>
  <sec id="s1">
   <title>1. Introduction</title>
   <p>Artificial intelligence (AI) is reshaping industries worldwide, driving unprecedented levels of efficiency and innovation. Businesses are increasingly leveraging AI to streamline operations, enhance customer experiences, and unlock new opportunities <xref ref-type="bibr" rid="scirp.147584-1">
     [1]
    </xref>. However, this technological revolution also has a darker side: cybercriminals are harnessing AI to develop more sophisticated and harder-to-detect attack methods. From AI-powered malware that adapts to evade detection to deepfake scams that manipulate voices and images with alarming accuracy, the threat landscape is evolving rapidly <xref ref-type="bibr" rid="scirp.147584-2">
     [2]
    </xref>. Phishing attacks have become more convincing, while vulnerabilities in Internet of Things (IoT) devices are being exploited with increasing precision <xref ref-type="bibr" rid="scirp.147584-3">
     [3]
    </xref>. These advancements in cybercrime are not just theoretical; they are real, growing, and increasingly dangerous.</p>
   <p>For Bangladesh, these developments are particularly concerning, especially in the banking sector, which is undergoing rapid digital transformation. While the adoption of digital services has brought convenience and accessibility to millions, it has also exposed critical weaknesses. Many banks still rely on outdated systems and lack robust security infrastructure, making them vulnerable to cyberattacks <xref ref-type="bibr" rid="scirp.147584-4">
     [4]
    </xref>. Compounding the problem is a severe shortage of skilled cybersecurity professionals who can defend against advanced threats. The 2016 Bangladesh Bank heist, in which hackers stole USD 81 million by exploiting vulnerabilities in the bank’s systems, serves as a stark reminder of these risks <xref ref-type="bibr" rid="scirp.147584-5">
     [5]
    </xref>. Yet, years later, many financial institutions in the country remain underprepared to face today’s sophisticated cyber threats.</p>
   <p>To navigate this challenging landscape, Bangladesh’s banking sector must take decisive action. Upgrading outdated systems and investing in modern cybersecurity technologies is no longer optional; it is a necessity. Equally important is cultivating a pool of cybersecurity talent through training programs, partnerships with educational institutions, and attracting global experts. Stricter regulations must also be enforced to ensure that banks adhere to the highest security standards <xref ref-type="bibr" rid="scirp.147584-6">
     [6]
    </xref>. However, technology and regulations alone are not enough. Human factors play a critical role in cybersecurity, which is why banks must prioritize educating both employees and customers about digital security best practices <xref ref-type="bibr" rid="scirp.147584-7">
     [7]
    </xref>. From recognizing phishing attempts to safeguarding personal information, awareness can be a powerful defense.</p>
  </sec><sec id="s2">
   <title>2. Present Scenario</title>
   <p>Bangladesh’s banking sector plays a vital role in driving the country’s economic growth by supporting businesses, enabling financial inclusion, and serving millions of customers. In recent years, it has embraced rapid digital transformation, with mobile apps, online banking, and automated systems reshaping how people manage their finances. While these advancements offer speed and convenience, they have also exposed the sector to growing cybersecurity threats <xref ref-type="bibr" rid="scirp.147584-4">
     [4]
    </xref>.</p>
   <p>As banks rely more on digital platforms, they become prime targets for cybercriminals due to the vast amount of sensitive financial data they manage. A defining example was the 2016 Bangladesh Bank heist, when hackers stole USD 81 million by exploiting system weaknesses <xref ref-type="bibr" rid="scirp.147584-5">
     [5]
    </xref>. Such incidents highlight not only technical gaps but also how cyberattacks can erode public trust, a key pillar of digital banking. Today, threats like phishing, ransomware, and data breaches are becoming more frequent and sophisticated <xref ref-type="bibr" rid="scirp.147584-3">
     [3]
    </xref>.</p>
   <p>Although regulations exist to protect the sector, many banks still face challenges such as outdated systems, weak security measures, and a shortage of cybersecurity experts <xref ref-type="bibr" rid="scirp.147584-6">
     [6]
    </xref>. These vulnerabilities make them ill-prepared for modern cyber risks. Strengthening cybersecurity is therefore not just a technical task; it is essential for safeguarding data, ensuring financial stability, and maintaining public trust <xref ref-type="bibr" rid="scirp.147584-7">
     [7]
    </xref>.</p>
   <p>This study explores the key cybersecurity challenges in Bangladesh’s banking sector, the factors that make it vulnerable, and their potential consequences. It also outlines practical solutions, including modernizing infrastructure, investing in advanced security technologies, and developing skilled cybersecurity talent through training and education. By taking a proactive and collaborative approach, the banking sector can create a safer digital environment that supports economic growth and builds customer confidence <xref ref-type="bibr" rid="scirp.147584-1">
     [1]
    </xref>.</p>
  </sec><sec id="s3">
   <title>3. Background</title>
   <p>AI has become a powerful yet complex force in cybersecurity. It helps defenders detect and respond to threats faster and more accurately through machine learning and automation, spotting suspicious patterns and neutralizing attacks in real time <xref ref-type="bibr" rid="scirp.147584-1">
     [1]
    </xref>. At the same time, cybercriminals are exploiting AI to create more advanced, targeted, and difficult-to-detect attacks. Deepfake scams, AI-driven phishing, and adaptive malware highlight how AI can be used to outsmart traditional defenses <xref ref-type="bibr" rid="scirp.147584-2">
     [2]
    </xref> <xref ref-type="bibr" rid="scirp.147584-3">
     [3]
    </xref>.</p>
   <p>This escalating battle between attackers and defenders poses serious risks for rapidly digitalizing countries like Bangladesh. While digital services have boosted connectivity and economic growth, they have also exposed critical security gaps. To strengthen defenses, the country introduced its National Cybersecurity Strategy in 2014, building a legal and collaborative framework for a safer digital ecosystem <xref ref-type="bibr" rid="scirp.147584-6">
     [6]
    </xref>. Progress has been made, but significant challenges persist.</p>
   <p>Many sectors, especially banking, healthcare, and government, still rely on outdated systems, making them vulnerable to modern attacks. Compounding this problem is a shortage of skilled cybersecurity professionals and uneven public awareness <xref ref-type="bibr" rid="scirp.147584-4">
     [4]
    </xref>. In 2022 alone, more than 63,000 cybercrime incidents were reported, reflecting the scale of the issue.</p>
   <p>Closing this gap requires investment in people, technology, and awareness. Expanding cybersecurity education, launching nationwide awareness campaigns, and deploying AI-based security solutions are essential steps. With Bangladesh’s cybersecurity market expected to grow to USD 368.8 million by 2029, the country has both a challenge and an opportunity to build resilience <xref ref-type="bibr" rid="scirp.147584-7">
     [7]
    </xref>.</p>
   <p>By modernizing infrastructure, developing talent, and fostering a culture of cybersecurity, Bangladesh can better protect its digital transformation. Though the threats are evolving, a proactive and united approach can secure the nation’s digital future.</p>
  </sec><sec id="s4">
   <title>4. Methodology</title>
   <p>To collect reliable insights for this study, a mixed qualitative approach was used, combining in-depth interviews with semi-structured questionnaires. Using purposive sampling, 40 participants, both IT and non-IT professionals from private and government banks, were selected to capture diverse perspectives on cybersecurity in Bangladesh’s banking sector <xref ref-type="bibr" rid="scirp.147584-8">
     [8]
    </xref>.</p>
   <p>The research covered institutions of different sizes and regions to reflect the broader banking landscape. Data collection spanned October to December 2024, allowing sufficient time for engagement and observation. Interviews provided rich qualitative narratives, revealing challenges such as outdated infrastructure, limited cybersecurity skills, and low awareness levels. Questionnaires ensured structured and comparable data across respondents, reinforcing interview findings <xref ref-type="bibr" rid="scirp.147584-9">
     [9]
    </xref>.</p>
   <p>This human-centered approach offered a holistic view of the sector’s cybersecurity landscape, emphasizing the urgency for modernization, capacity building, and stronger regulatory frameworks. By integrating multiple data sources, the study provides practical, context-specific recommendations for improving cybersecurity resilience in Bangladesh’s financial institutions <xref ref-type="bibr" rid="scirp.147584-10">
     [10]
    </xref>.</p>
  </sec><sec id="s5">
   <title>5. Result</title>
   <p>A targeted survey was carried out to examine the impact of AI-driven cybersecurity threats on Bangladesh’s banking sector. It involved 33 participants from seven major banks, including IT professionals, cybersecurity specialists, and senior banking officials. This diverse group provided a balanced perspective on technical vulnerabilities, evolving threat patterns, and organizational readiness. The survey focused on identifying AI-enhanced threats such as phishing, adaptive malware, and fraudulent transactions; evaluating banks’ preparedness and adoption of AI defenses; and exploring practical solutions like technology upgrades, increased investments, and stronger collaboration <xref ref-type="bibr" rid="scirp.147584-2">
     [2]
    </xref> <xref ref-type="bibr" rid="scirp.147584-3">
     [3]
    </xref>.</p>
   <p>The results highlighted significant gaps in awareness and preparedness. Only 52% of respondents demonstrated strong knowledge of AI-enabled threats, and just 40% of banks had adopted AI-powered detection tools. Larger institutions were more advanced in adopting AI defenses, while smaller banks lagged behind due to limited resources, leaving the sector unevenly protected. Regulatory frameworks also lacked clarity, and limited industry collaboration further weakened collective defense efforts <xref ref-type="bibr" rid="scirp.147584-7">
     [7]
    </xref>.</p>
   <p>To address these challenges, the study suggests a multi-layered approach: expanding AI-focused employee training, investing in real-time monitoring technologies, and encouraging banks to share threat intelligence and best practices. While AI offers powerful tools for detection and fraud prevention, issues like high costs, integration challenges, skills shortages, and ethical concerns must be addressed to ensure robust security <xref ref-type="bibr" rid="scirp.147584-10">
     [10]
    </xref>. A more collaborative, well-resourced ecosystem can help protect Bangladesh’s banking infrastructure and build long-term resilience.</p>
  </sec><sec id="s6">
   <title>6. Discussion</title>
   <p>The survey results reveal several pressing gaps that must be addressed to strengthen the banking sector’s adoption of AI-driven cybersecurity solutions. One of the most critical issues is the shortage of skilled cybersecurity professionals. Around 70% of banks have fewer than 50 employees dedicated to cybersecurity, resulting in overworked and understaffed teams <xref ref-type="bibr" rid="scirp.147584-11">
     [11]
    </xref>. This finding underscores the urgent need to invest in workforce development, including partnerships with universities and training institutions to build a sustainable talent pipeline.</p>
   <p>Although many employees are aware of AI-related threats, only a small proportion feel adequately prepared to respond to them. This reflects a gap between awareness and practical capability, which could be bridged through structured, hands-on training programs and continuous professional development <xref ref-type="bibr" rid="scirp.147584-12">
     [12]
    </xref>.</p>
   <p>Currently, AI tools are mainly deployed for fraud detection and risk management, but their potential remains underutilized in areas such as customer service automation and credit risk assessment. Furthermore, there is a perception that existing AI systems are not fully optimized, particularly when addressing operational inefficiencies, signaling the need for better integration and system refinement <xref ref-type="bibr" rid="scirp.147584-13">
     [13]
    </xref>.</p>
   <p>The reliance on outsourcing IT infrastructure adds another layer of risk, particularly concerning data security and vendor accountability. This highlights the importance of robust contractual safeguards and independent security audits to protect sensitive financial data <xref ref-type="bibr" rid="scirp.147584-2">
     [2]
    </xref>.</p>
   <p>Other key barriers to AI adoption include limited financial resources, a lack of skilled personnel, and ambiguous regulatory frameworks. Moreover, many employees are not actively engaged in AI implementation processes, indicating the need for broader organizational education and participation to foster a security-aware culture <xref ref-type="bibr" rid="scirp.147584-7">
     [7]
    </xref> <xref ref-type="bibr" rid="scirp.147584-14">
     [14]
    </xref>.</p>
   <p>Finally, adopting structured AI-specific compliance frameworks, such as the NIST AI Risk Management Framework, can support organizations in managing AI-related risks more effectively and responsibly <xref ref-type="bibr" rid="scirp.147584-15">
     [15]
    </xref>.</p>
  </sec><sec id="s7">
   <title>7. Challenges and Global Comparison</title>
   <p>The survey reveals several barriers to effective AI-driven cybersecurity in the banking sector:</p>
   <p>1. Cybersecurity Skills Gap: Around 70% of banks employ fewer than 50 cybersecurity staff, mirroring a global talent shortage and the need for targeted recruitment and training <xref ref-type="bibr" rid="scirp.147584-16">
     [16]
    </xref>.</p>
   <p>2. Low Confidence in AI Risk Response: Although 60% of employees are aware of AI threats, only 9.1% feel equipped to handle them. Globally, experts stress scenario-based training to boost confidence and skills <xref ref-type="bibr" rid="scirp.147584-17">
     [17]
    </xref> <xref ref-type="bibr" rid="scirp.147584-18">
     [18]
    </xref>.</p>
   <p>3. Limited AI Applications: AI use remains focused on fraud detection, while other areas like customer service and credit scoring are underutilized. Internationally, banks are expanding AI into broader operational domains <xref ref-type="bibr" rid="scirp.147584-19">
     [19]
    </xref> <xref ref-type="bibr" rid="scirp.147584-20">
     [20]
    </xref>.</p>
   <p>4. Effectiveness Gaps: Only 25% of respondents view AI as highly effective, pointing to optimization needs. Continuous monitoring and iterative improvements are key global practices <xref ref-type="bibr" rid="scirp.147584-21">
     [21]
    </xref>.</p>
   <p>5. Adoption Barriers: A lack of skilled staff (56.3%) and financial constraints (9.4%) slow AI adoption. A phased approach supported by regulatory clarity is recommended <xref ref-type="bibr" rid="scirp.147584-22">
     [22]
    </xref>.</p>
   <p>6. Weak AI Compliance: Few banks follow structured frameworks like the NIST AI RMF. Global institutions urge wider adoption for stronger governance <xref ref-type="bibr" rid="scirp.147584-23">
     [23]
    </xref>.</p>
   <p>7. Regulatory &amp; Technological Gaps: Unclear regulations (46.7%) and limited tools (56.7%) remain major obstacles. Clearer rules and better technology are global priorities <xref ref-type="bibr" rid="scirp.147584-20">
     [20]
    </xref>.</p>
   <p>8. Training Priority: A strong majority (73.3%) identify workforce training as essential. This aligns with the global consensus on building AI security skills through structured education <xref ref-type="bibr" rid="scirp.147584-16">
     [16]
    </xref>.</p>
  </sec><sec id="s8">
   <title>8. Analysis</title>
   <p>The respondents include professionals from the banking and IT sectors, with the following breakdown: IT security specialists (21.2%), cybersecurity analysts (18.2%), risk management professionals (27.3%), AI specialists (6.1%), and other professionals (39.4%) (<xref ref-type="fig" rid="fig1">
     Figure 1
    </xref>).</p>
   <fig id="fig1" position="float">
    <label>Figure 1</label>
    <caption>
     <title>
      <xref ref-type="bibr" rid="scirp.147584-"></xref>Figure 1. Responded role in cybersecurity.</title>
    </caption>
    <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/1733332-rId15.jpeg?20251127045142" />
   </fig>
   <p>
    <xref ref-type="fig" rid="fig2">
     Figure 2
    </xref>shows the distribution of cybersecurity personnel working in selected banks was identified as follows: 69.7% of banks have between 1 - 50 employees, 12.1% have 51 - 100 employees, 9.1% have 101 - 500 employees, and 9.1% have more than 500 employees.</p>
   <p>More than 60% of employees are aware of the increasing AI-based cybersecurity risks in the banking sector, whereas the ability to eliminate these risks is relatively low, at 9.1%. However, 30.3% of respondents believe that AI-driven threats are less significant than human-based threats (<xref ref-type="fig" rid="fig3">
     Figure 3
    </xref>).</p>
   <p>Various AI applications are used in the banking sector to detect, identify, and protect data from hackers. In Bangladesh, the following AI tools are utilized: 41.4% for fraud detection, 20.7% for credit scoring, 37.9% for customer service automation, 48.3% for risk management, and 20.7% for other purposes (<xref ref-type="fig" rid="fig4">
     Figure 4
    </xref>).</p>
   <fig id="fig2" position="float">
    <label>Figure 2</label>
    <caption>
     <title>
      <xref ref-type="bibr" rid="scirp.147584-"></xref>Figure 2. The number of cybersecurity personnel working in banks.</title>
    </caption>
    <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/1733332-rId16.jpeg?20251127045142" />
   </fig>
   <fig id="fig3" position="float">
    <label>Figure 3</label>
    <caption>
     <title>
      <xref ref-type="bibr" rid="scirp.147584-"></xref>Figure 3. Perception of AI-Dirven common threat.</title>
    </caption>
    <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/1733332-rId17.jpeg?20251127045142" />
   </fig>
   <fig id="fig4" position="float">
    <label>Figure 4</label>
    <caption>
     <title>
      <xref ref-type="bibr" rid="scirp.147584-"></xref>Figure 4. AI application used in the Banking sector presently.</title>
    </caption>
    <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/1733332-rId18.jpeg?20251127045142" />
   </fig>
   <p>Data analysis shows that 59.4% of respondents view AI as effective in tackling operational challenges, while 25% find it highly effective and 15.6% rate it as moderately effective (<xref ref-type="fig" rid="fig5">
     Figure 5
    </xref>). This reflects a generally positive perception of AI’s role in boosting operational efficiency.</p>
   <fig id="fig5" position="float">
    <label>Figure 5</label>
    <caption>
     <title>
      <xref ref-type="bibr" rid="scirp.147584-"></xref>Figure 5. Effectiveness of AI in overcoming operational challenges at the banking sector in Bangladesh.</title>
    </caption>
    <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/1733332-rId19.jpeg?20251127045142" />
   </fig>
   <p>Survey results indicate that 35.5% of respondents see AI reducing costs, another 35.5% cite improved operational efficiency, 16.1% value access to specialized expertise, and 12.9% highlight better focus on core business functions (<xref ref-type="fig" rid="fig6">
     Figure 6
    </xref>). Overall, AI adoption offers cost savings, efficiency gains, and enhanced strategic focus.</p>
   <fig id="fig6" position="float">
    <label>Figure 6</label>
    <caption>
     <title>
      <xref ref-type="bibr" rid="scirp.147584-"></xref>Figure 6. Benefits of IT assets outsourcing.</title>
    </caption>
    <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/1733332-rId20.jpeg?20251127045141" />
   </fig>
   <p>Banks in Bangladesh face several challenges with IT asset outsourcing. 40.6% of respondents cited data security and confidentiality risks, 28.1% noted service quality issues, 18.8% highlighted compliance challenges, and 12.5% pointed to limited control over assets (<xref ref-type="fig" rid="fig7">
     Figure 7
    </xref>). These findings emphasize the need for robust management frameworks to ensure security, performance, compliance, and oversight in outsourcing.</p>
   <fig id="fig7" position="float">
    <label>Figure 7</label>
    <caption>
     <title>
      <xref ref-type="bibr" rid="scirp.147584-"></xref>Figure 7. Key challenges of IT assets outsourcing management.</title>
    </caption>
    <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/1733332-rId21.jpeg?20251127045141" />
   </fig>
   <p>Implementing AI-driven cybersecurity in banks faces key challenges: 56.3% cite a shortage of skilled personnel, 9.4% note financial constraints, 15.6% highlight unclear regulations, and 12.5% point to rapidly evolving AI threats (<xref ref-type="fig" rid="fig8">
     Figure 8
    </xref>). Addressing these requires training, funding, regulatory clarity, and proactive threat management.</p>
   <fig id="fig8" position="float">
    <label>Figure 8</label>
    <caption>
     <title>
      <xref ref-type="bibr" rid="scirp.147584-"></xref>Figure 8. Challenges to implement AI cybersecurity measures.</title>
    </caption>
    <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/1733332-rId22.jpeg?20251127045141" />
   </fig>
   <p>The survey shows that 45.5% of banking staff are directly involved in AI implementation, contributing to system design, deployment, and management. However, 54.5% are not engaged, often due to limited skills or non-technical roles (<xref ref-type="fig" rid="fig9">
     Figure 9
    </xref>). This gap highlights the need for training, awareness programs, and strategies to involve more employees in AI initiatives.</p>
   <p>The survey shows varied adoption of cybersecurity frameworks in banks. 56.7% use ISO/IEC 27001 and 42001, 16.7% follow the NIST AI Risk Management Framework, 23.3% comply with GDPR, SOC, or HIPAA, and 33.3% use the SWIFT Customer Security Programme. Most banks (83.3%) adhere to Bangladesh Bank Guidelines V4.0 (<xref ref-type="fig" rid="fig10">
     Figure 10
    </xref>). While global and local standards are widely used, AI-specific risk strategies remain underutilized.</p>
   <fig id="fig9" position="float">
    <label>Figure 9</label>
    <caption>
     <title>
      <xref ref-type="bibr" rid="scirp.147584-"></xref>Figure 9. Direct involvement in an AI system.</title>
    </caption>
    <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/1733332-rId23.jpeg?20251127045141" />
   </fig>
   <fig id="fig10" position="float">
    <label>Figure 10</label>
    <caption>
     <title>
      <xref ref-type="bibr" rid="scirp.147584-"></xref>Figure 10. Applicable national &amp; international standards in the banking sector presently.</title>
    </caption>
    <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/1733332-rId24.jpeg?20251127045141" />
   </fig>
   <p>To enhance cybersecurity and resilience in Bangladesh’s banking sector, key measures include stronger regulatory support (46.7%), the adoption of advanced AI-powered tools (56.7%), increased investment in workforce training and skill development (73.3%), and fostering industry-wide collaboration (36.7%) to address evolving threats and drive innovation (<xref ref-type="fig" rid="fig11">
     Figure 11
    </xref>).</p>
   <fig id="fig11" position="float">
    <label>Figure 11</label>
    <caption>
     <title>
      <xref ref-type="bibr" rid="scirp.147584-"></xref>Figure 11. Additional measures recommended for AI security improvement.</title>
    </caption>
    <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/1733332-rId25.jpeg?20251127045142" />
   </fig>
   <p>As AI-driven threats continue to rise in the banking sector, staff members are calling for swift action in several key areas to address these challenges. The most pressing concerns include strengthening data protection (74.2%), ensuring model integrity (22.6%), improving threat detection and response (48.4%), and investing in workforce training (41.9%) to equip employees for the evolving landscape (<xref ref-type="fig" rid="fig12">
     Figure 12
    </xref>).</p>
   <fig id="fig12" position="float">
    <label>Figure 12</label>
    <caption>
     <title>
      <xref ref-type="bibr" rid="scirp.147584-"></xref>Figure 12. Immediate attention for securing an AI system in the banking sector of Bangladesh.</title>
    </caption>
    <graphic mimetype="image" position="float" xlink:type="simple" xlink:href="https://html.scirp.org/file/1733332-rId26.jpeg?20251127045142" />
   </fig>
  </sec><sec id="s9">
   <title>9. Recommendations</title>
   <p>Based on survey findings and global best practices, the following strategies can strengthen AI-driven cybersecurity in Bangladesh’s banking sector:</p>
   <p>1. Develop AI-Skilled Teams: Hire and train professionals in AI, machine learning, and data analytics, and collaborate with universities to address the talent gap <xref ref-type="bibr" rid="scirp.147584-10">
     [10]
    </xref>.</p>
   <p>2. Employee Training: Implement hands-on, scenario-based training to boost confidence in managing AI threats, using simulations and interactive learning <xref ref-type="bibr" rid="scirp.147584-16">
     [16]
    </xref>.</p>
   <p>3. Broaden AI Applications: Extend AI beyond security to areas like customer service, credit scoring, fraud detection, and compliance for greater efficiency <xref ref-type="bibr" rid="scirp.147584-4">
     [4]
    </xref>.</p>
   <p>4. Optimize AI Systems: Continuously refine AI models through audits, feedback loops, and partnerships with technology providers to stay ahead of evolving threats <xref ref-type="bibr" rid="scirp.147584-8">
     [8]
    </xref>.</p>
   <p>5. Strategic Investment: Use phased AI adoption, seek funding, and build partnerships to overcome financial and resource constraints, particularly for smaller banks <xref ref-type="bibr" rid="scirp.147584-14">
     [14]
    </xref>.</p>
   <p>6. AI Governance: Align policies with frameworks such as the NIST AI RMF to ensure secure, ethical, and compliant AI use <xref ref-type="bibr" rid="scirp.147584-17">
     [17]
    </xref>.</p>
   <p>7. Regulatory Collaboration: Work with regulators to clarify AI policies and invest in advanced cybersecurity tools to counter AI-enabled threats <xref ref-type="bibr" rid="scirp.147584-18">
     [18]
    </xref>.</p>
   <p>8. Promote Continuous Learning: Foster a culture of ongoing education to keep staff updated on AI technologies and cybersecurity risks <xref ref-type="bibr" rid="scirp.147584-19">
     [19]
    </xref>-<xref ref-type="bibr" rid="scirp.147584-22">
     [22]
    </xref>.</p>
  </sec><sec id="s10">
   <title>10. Conclusion</title>
   <p>Banks are increasingly vulnerable to AI-driven cyber threats due to a shortage of skilled professionals, limited employee training, and slow AI adoption. Rapidly evolving attacks such as AI-powered phishing, adaptive malware, and deepfake fraud leave many institutions, especially smaller banks, exposed, risking sensitive data and customer trust. To address this, banks must adopt a proactive approach by expanding AI-focused cybersecurity teams, providing comprehensive staff training, integrating AI across operations, strengthening regulatory frameworks, and fostering industry collaboration. Immediate action is essential to protect data, maintain public confidence, and build resilient defenses that enable the sector to thrive in a digital and interconnected world.</p>
  </sec>
 </body><back>
  <ref-list>
   <title>References</title>
   <ref id="scirp.147584-ref1">
    <label>1</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Zhang, Y., Wang, J. and Chen, L. (2023) The Transformative Power of AI in Business. Journal of Business Research, 154, 113–124.
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref2">
    <label>2</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     World Economic Forum (2023) Global Cybersecurity Outlook. WEF.
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref3">
    <label>3</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Taddeo, M. and Floridi, L. (2018) How AI Can Be a Force for Good. Science, 361, 751-752. &gt;https://doi.org/10.1126/science.aat5991
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref4">
    <label>4</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Sharma, P., Kaushik, N. and Tripathi, R. (2022) AI-Enabled Cyber Threats and IoT Vulnerabilities. IEEE Access, 10, 98743–98756.
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref5">
    <label>5</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Rahman, M. and Islam, S. (2021) Cybersecurity Challenges in the Banking Sector of Bangladesh. Journal of Financial Crime, 28, 1250-1265.
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref6">
    <label>6</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     PwC (2022) Global Digital Trust Insights. &gt;https://www.pwc.es/es/publicaciones/digital/global-digital-trust-2022.pdf 
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref7">
    <label>7</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     National Institute of Standards and Technology (NIST) (2023) AI Risk Management Framework (AI RMF 1.0). &gt;https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf 
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref8">
    <label>8</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Nguyen, T., Ngo, L.V. and Ruël, H. (2022) Developing Human Capabilities for AI Security: The Role of Training and Learning Culture. Computers&amp;Security, 117, Article 102704.
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref9">
    <label>9</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Mikalef, P., Krogstie, J., Pappas, I.O. and Pavlou, P. (2021) Exploring the Relationship between AI Capabilities and Firm Performance: The Mediating Role of Digital Transformation. Information&amp;Management, 58, Article 103434.
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref10">
    <label>10</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     McKinsey&amp;Company (2022) Global AI Adoption Survey. McKinsey.
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref11">
    <label>11</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Kshetri, N. (2021) Cybersecurity and the Changing Threat Landscape. Computer Law&amp;Security Review, 43, 1-10.
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref12">
    <label>12</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Sundaramurthy, S.K., Ravichandran, N., Inaganti, A.C. and Muppalaneni, R. (2022) AI-Powered Operational Resilience: Building Secure, Scalable, and Intelligent Enterprises. Artificial Intelligence and Machine Learning Review, 3, 1-10. &gt;https://scipublication.com/index.php/AIMLR/article/view/135 
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref13">
    <label>13</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Hubbard, D.W. and Seiersen, R. (2016). How to Measure Anything in Cybersecurity Risk. Wiley. &gt;https://doi.org/10.1002/9781119162315 
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref14">
    <label>14</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Hastings, N.B., Young, M. and O’Neill, P. (2023) Building Cybersecurity Talent: Strategies for Sustainable Workforce Development. Journal of Cybersecurity Policy and Management, 8, 45-63.
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref15">
    <label>15</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Haque, G.M.M., Akula, D.K., Mohammed, Y.S., Syed, A. and Arafat, Y. (2025) Cybersecurity Risk Management in the Age of Digital Transformation: A Systematic Literature Review. Emerging Frontiers Library for the American Journal of Engineering and Technology, 7, 126-150. &gt;http://emergingsociety.org/index.php/efltajet/article/view/255 
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref16">
    <label>16</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Deloitte (2023) AI and Risk Management. Deloitte Insights. &gt;https://www.deloitte.com/content/dam/assets-shared/legacy/docs/perspectives/2022/deloitte-gx-ai-and-risk-management.pdf 
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref17">
    <label>17</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Creswell, J.W. and Plano Clark, V.L. (2018) Designing and Conducting Mixed Methods Research. 3rd Edition, Sage Publications.
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref18">
    <label>18</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Brynjolfsson, E. and McAfee, A. (2017) Machine, Platform, Crowd: Harnessing Our Digital Future. W.W. Norton&amp;Company.
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref19">
    <label>19</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Braun, V. and Clarke, V. (2006) Using Thematic Analysis in Psychology. Qualitative Research in Psychology, 3, 77-101. &gt;https://doi.org/10.1191/1478088706qp063oa
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref20">
    <label>20</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Bank of England (2023) AI in Financial Services: Opportunities and Risks. BoE.
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref21">
    <label>21</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Bank for International Settlements (2023) AI Governance in Financial Institutions. BIS.
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref22">
    <label>22</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Bangladesh Telecommunication Regulatory Commission (BTRC) (2023) Cybersecurity Status and Guidelines in Bangladesh. BTRC.
    </mixed-citation>
   </ref>
   <ref id="scirp.147584-ref23">
    <label>23</label>
    <mixed-citation publication-type="other" xlink:type="simple">
     Zetter, K. (2016) That Insane, $81M Bangladesh Bank Heist? Here’s What We Know. WIRED. &gt;https://www.wired.com/2016/05/insane-81m-bangladesh-bank-heist-heres-know/
    </mixed-citation>
   </ref>
  </ref-list>
 </back>
</article>