At the Fintech in Security 2026 conference in Tashkent, participants of the 'Universe of Secure Payments' panel discussed the main cyber threats that will persist over the next twelve months. Experts noted that social engineering, phishing, and ransomware will remain the primary threats to businesses. Furthermore, the spread of artificial intelligence will allow attackers to refine their methods and lower the entry barrier for individuals with limited technical knowledge.
Representatives from various banks and cybersecurity centers participated in the discussion, including Bekhzod Dehkanov from Turon Bank's Information Security Service, Timur Emirsaliyev from Apex Bank, Alexander Zorin from Korzinka.uz, Zokhir Mirzaev from Asakabank, and Fayoz Bahadyrov, senior expert at the Central Bank's Cybersecurity Center CERT-CBU. The international cybersecurity expert Arkady Prokudin, representing Compliance Control & Rakasta, moderated the session.
Participants emphasized that the nature of many cyberattacks is changing slower than the technologies used to execute them. In particular, there is a growing use of multi-stage phishing schemes, including those distributed via Telegram. Artificial intelligence is becoming an additional tool for attackers, enabling people who previously lacked the necessary knowledge to create sufficiently complex malware.
Experts also warned that threats may become less visible: instead of one large-scale attack requiring extensive preparation, attackers are increasingly using numerous small incidents that are harder to detect. Meanwhile, AI is actively being applied by information system protection teams; one participant noted that a task that took 10 to 30 hours two years ago is now completed in less than 1.5 hours, and automation without AI is becoming practically impossible.
Nevertheless, companies are not yet ready to rely entirely on AI without additional control. Specialists continue to check software code created with the help of AI, although the industry is gradually moving towards a higher level of automation.
Cybersecurity Funding
The session was also dedicated to the issue of cybersecurity funding. Business representatives were advised to justify security expenses by assessing the cost of company or specific business unit downtime over a day, week, or month. A minimum benchmark for information security expenses was set at 10% of the corresponding amount. One speaker reported that security costs usually account for 10–15% of the IT department budget. An additional argument when discussing cybersecurity funding can be regulatory fines for security violations.
Experts strongly advised companies not to purchase security solutions solely because competitors use them. First and foremost, enterprises must independently identify their risks and then choose tools to minimize them. Among potential risks, participants cited dependence on key employees. If one specialist is responsible for a significant number of processes, the company must predetermine an action plan in case that employee leaves.
As a first step for businesses, especially those entering international markets, experts suggested conducting an audit of compliance with applicable standards. They noted that many such standards have significant overlaps and are based on a risk-based approach. However, as participants stressed, there is no universal solution that simultaneously ensures high speed, security, and low cost. For example, in the case of smartphone protection, a six- or eight-digit password is more secure than a four-digit one but less convenient to use, so businesses need to find a balance between convenience, level of protection, and cost.
Another problem for information security teams is implementing new solutions without disrupting existing services. To solve this, companies must train specialists and proactively explain the benefits of proposed changes to business units. The personnel issue was also mentioned: companies hire students and train them into specialists, but some employees leave for other employers after gaining experience. As an additional security measure, experts recommended regularly engaging external specialists to conduct penetration testing of their own products and systems.
