Banks will face a hard truth in 2026: Early security checks are no longer enough

The HQ of Barclays in Canary Wharf, London
Banks in Canary Wharf, London

As financial institutions in the US, UK, Australia and beyond continued their digital transformation journeys in 2025, software development has become faster, more integrated, and more vulnerable than ever before.

The traditional model of ‘shift-left’ security, which places protective measures at the beginning of the development lifecycle, has long been embraced by banks and fintech firms. But for Sydney, Australia-based Craig Nielsen, Vice President, APJ at GitLab, this won’t be enough in 2026.

“Security remains everyone’s responsibility, but shifting security up the stack allows for more oversight and consistency across the organisation,” said Nielsen. “Most importantly, these security efforts extend from the first line of code to production and beyond.”

With attack surfaces expanding and regulatory environments tightening across major financial markets, many institutions are realising that early-stage security checks don’t always survive the jump from development to deployment.

Craig Nielsen

As Nielsen puts it, the shift-up approach is about bridging that gap, extending protections all the way through runtime and into post-release.

That’s the strategy embraced by firms like Constantinople, a financial services startup that has embedded security and compliance into every phase of its software lifecycle.

Their team leverages a unified DevSecOps platform to deploy code 20 to 30 times per day, with security controls enforced and monitored continuously. The result is a consistent, scalable model of trust.

To replicate that kind of system-wide confidence, Nielsen encourages teams to start by building reusable, automated testing components.

“By introducing an abstraction layer between analysers and their pipeline implementations, results can be normalised before reaching development teams,” Nielsen shared.

“This centralises control over security rules and configurations, allowing updates, replacements, or additional analysers to be integrated seamlessly without causing disruptions or rework downstream.”

The benefits of this approach resonate strongly in regulated sectors like banking and insurance, where failure to patch or detect vulnerabilities can result in compliance violations, customer distrust, or operational disruption.

“Over time, this approach enables financial organisations to develop a more flexible and future-proof security framework that can evolve to meet changing requirements while maintaining a unified, organisation-wide security posture,” Nielsen explained.


“Shift-up security builds on the shift-left model by embedding security practices across the entire software development lifecycle.”

– Craig Nielsen

But a robust technical setup is not enough. Organisations also need guardrails that enforce security standards across the entire portfolio.

“These policies act as guardrails by providing a structured framework that ensures projects adhere to a consistent level of security while still allowing some flexibility to account for project needs or requirements,” he elaborated.

That begins with establishing clear thresholds for risk tolerance and embedding mandatory tasks like security scans into every project.

These policies not only strengthen defense, but also support alignment with global regulatory frameworks such as GDPR, PCI-DSS, and the relatively young Digital Operational Resilience Act (DORA) in the EU and UK.

Once foundational policies are in place, the next step is to layer in contextual controls. “If a SAST scanner detects a critical vulnerability, the developer must either resolve it or obtain approval from the security team before promoting the code,” Nielsen explained.

“Developers can continue without delay if no vulnerabilities are found or the risk tolerance threshold is met.”

This model enables teams to maintain velocity without compromising accountability, a balance that’s especially critical for banks juggling legacy systems, cloud migrations, and real-time service delivery.

“Shift-up security builds on the shift-left model by embedding security practices across the entire software development lifecycle,” said Nielsen.

“It reduces vulnerabilities, supports compliance with regional and global standards, and builds trust through scalable automation, universal policies, and context-aware controls.”

As financial institutions aim to stay competitive while navigating escalating cybersecurity threats and strict regulatory scrutiny, this “shift-up” mindset may prove essential to safeguarding trust and resilience at scale, Nielsen concluded.


COMING IN 2026



Why not become a QA Financial subscriber?

It’s entirely FREE

* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

REGISTER HERE TODAY


REGULATION & COMPLIANCE

Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.


READ MORE


WATCH NOW


QA FINANCIAL PODCASTS

Listen to Sudeepta Guchhait on Nasdaq’s new Mimic AI testing platform
QA Financial sits down with Sudeepta Guchhait, Senior Director of Product Framework & Quality Engineering at Nasdaq

——–

Listen to Wesley Scheffel and Robin Rain on Schroders’ DevOps strategy
We catch up with Wesley Scheffel, Head of Cloud Platform and Product Engineering at Schroders, and Robin Rain, Head of Cloud Platform Architecture

——–

Listen to Citi’s Jason Morris on Lightspeed and the future of continuous delivery
Jason Morris, Head of Developer Pipelines for Securities Markets and Banking at Citi, talks about Lightspeed