A blunt 77% of financial services security leaders in APAC say they have a full picture of their API estate. Only 27% know which of those APIs return sensitive data. That gap is where attackers live now. And as AI accelerates both attack scale and API proliferation, the gap is widening fast.
Akamai's latest State of the Internet Security report lands at a moment when Australian and New Zealand regulators have already started pulling on the same thread. The APRA letter on AI risk landed on 30 April 2026. The ASIC open letter on frontier AI followed on 8 May 2026. The RBNZ Financial Stability Report arrived in mid-May with the same warning. The message to boards across the Tasman is now unified: existing controls are about to be tested more often, at greater scale, and under greater pressure.
Financial services is now the most targeted industry globally for Layer 3 and 4 DDoS attacks. The median duration of those attacks has increased by 738% since 2024. Volumetric DDoS attacks against the sector grew in scale by 236% between 2024 and 2025. Advanced bot activity surged 147% in late 2025, and in one Akamai case study, 96% of a financial site's total traffic was identified as malicious scraping bots.
The takeaway for ANZ financial services is straightforward. The threat is global, the targeting is sector-specific, and the volume is rising.
APAC is now the most targeted region for Layer 7 DDoS attacks against financial services, for the fourth consecutive year. 52% of all global Layer 7 attacks against the sector in 2025 hit APAC institutions. That was 314 billion attacks across the region in one year, more than double the next closest region.
Australia and New Zealand sit firmly inside that envelope.
The gap between knowing what you have and knowing what matters is the single most consequential finding in the Akamai report for ANZ financial services governance.
Source: Akamai 2026 API Security Impact Study.
Where do you actually stand?
APRA wrote to industry on AI governance on 30 April 2026. ASIC issued 26-092MR on 8 May 2026. The ASD Essential Eight remains the baseline requirement for government suppliers and insurers. An independent readiness assessment gives you a documented position against the obligation that actually binds you. Two to four weeks. Founder reviewed. Every time.
The single most useful data point in the Akamai report, from a governance perspective, is the gap between API inventory and sensitive data visibility.
That is the visibility gap. It is not a technology problem. It is a knowing-what-you-have problem.
Globally, 96% of financial services organisations reported at least one API security incident in the past 12 months. That is the highest rate of any industry. If you do not know which of your APIs touch sensitive data, you cannot meaningfully protect them, monitor them, or report on them. You also cannot answer the information security questions in APRA CPS 234, or the third-party and fourth-party visibility questions in APRA CPS 230, which came into force on 1 July 2025.
First, AI is making attacks more effective. Akamai recorded an average of 2.5 billion AI-related bot requests per day across its network, nearly doubling in the second half of 2025. AI-driven bots now mimic browser behaviour with near-perfect accuracy.
Second, AI is expanding the API attack surface inside financial institutions themselves. Akamai uses the term "vibe coding" to describe AI-assisted development that ships working code faster than security teams can review it. The result: shadow APIs and zombie APIs reach production without documentation, monitoring, or proper authentication.
"Do you know where AI is being used inside your business, and do you know what would happen if one of those systems was compromised or manipulated? If you can't answer that, you're not ready to govern it."
Matt Miller, Co-Founder and CEO, Insicon Cyber
APRA's 30 April 2026 letter made AI risk a board-level matter for every authorised deposit-taking institution, insurer, and superannuation trustee. The letter named the attack vectors explicitly: prompt injection, data leakage, insecure integrations, AI-generated code, exploit injection, and the manipulation of autonomous AI agents.
ASIC's 8 May 2026 open letter pushed the same urgency from a different angle. Strengthen cyber resilience fundamentals now. Patch faster. Validate controls. Adopt layered, defence-in-depth architectures that assume breach.
The RBNZ Financial Stability Report (May 2026) reinforced the trans-Tasman picture. Emerging frontier AI models could materially amplify cyber risks. Concentration risk in third-party AI providers is now treated as a financial stability concern.
You cannot govern what you cannot see. Start with discovery: every API, including shadow and zombie APIs. Map which APIs return sensitive data. Then test the AI systems themselves against prompt injection, data leakage, and the OWASP Top 10 for LLM Applications.
ISO/IEC 42001:2023 is the management system standard for AI. It maps to the APRA letter's governance expectations almost line for line. The governance discipline that certification requires is the goal.
Point-in-time assurance is not fit for probabilistic models that learn, adapt, and degrade. APRA said so directly. The expectation is continuous validation. That is a managed compliance function, not an annual audit.
Insicon Cyber is an ANZ-based cybersecurity advisory and managed services firm. Founded in 2013, we are ISO 27001 certified, headquartered in North Sydney, and operate across both Australia and New Zealand. Three capabilities matter most: AI Security and Governance, ISO 42001 implementation, and Managed Compliance.
The Akamai research makes the threat picture unambiguous. The APRA, ASIC and RBNZ positions make the regulatory picture unambiguous. The only remaining variable is whether you do it before the next incident, or after.