As cyber threats evolve, AI-powered anomaly detection is becoming essential for helping payment firms identify threats early and strengthen resilience.
Cyber attackers are changing the way they operate.
Rather than launching noisy attacks against heavily defended servers, they’re increasingly looking for quieter routes into an organisation. A forgotten router. An internet-connected device. A piece of edge infrastructure that quietly blends into the background.
The Chinese state-backed campaign known as Volt Typhoon demonstrated just how effective that approach can be. Rather than relying on destructive malware, the attackers compromised connected edge devices and blended into normal network activity, allowing them to establish long-term access to critical infrastructure while remaining largely undetected.
It’s a lesson that extends well beyond government networks.
Modern payment estates consist of thousands of connected payment terminals, cash machines (ATMs), and self-service devices. Everyone represents another potential entry point. The challenge is no longer simply protecting those devices. It’s recognising when one quietly starts behaving differently from the rest.
For too long, the payments industry has equated cybersecurity with prevention. We’ve become exceptionally good at building walls around our infrastructure, but considerably less effective at recognising when an attacker is already inside them.
The next battleground isn’t prevention. It’s detection.
Security is becoming synonymous with resilience
The direction of regulation reflects this changing mindset.
PCI DSS v4.0, NIS2 and the Digital Operational Resilience Act (DORA) all reinforce the same principle. Cyber resilience depends on continuous monitoring, rapid detection, and effective response, not simply preventing attacks. Regulators are increasingly asking organisations to demonstrate they can identify, contain, and recover from incidents before they become operational failures.
None of these regulations explicitly mandates anomaly detection. What they do make clear is that resilience depends on continuous visibility. In my view, AI-powered anomaly detection is one of the most effective ways organisations can achieve that outcome without dramatically increasing operational overhead.
Every device has a story to tell
Cyber-attacks rarely announce themselves. They begin quietly.
A payment terminal starts communicating with an unfamiliar destination. Network traffic increases outside normal operating hours. A firmware update appears unexpectedly, or one device begins behaving differently from every other terminal in the estate.
Individually, these events may seem insignificant. Together, they tell a story. The challenge is recognising that story before it becomes a security incident, a compliance issue or an outage affecting customers.
AI-powered anomaly detection addresses this by learning what “normal” looks like across an estate. Rather than relying solely on predefined rules or known attack signatures, it identifies subtle behavioural changes that often signal problems long before conventional monitoring tools raise an alert.
AI isn’t valuable simply because it’s AI. Its real strength lies in recognising behavioural patterns across thousands of connected devices that no individual analyst could realistically identify unaided.
Detection should strengthen compliance, not just security
Detection is only half the challenge. Understanding whether unusual behaviour has compliance implications is equally important.
Modern anomaly detection platforms combine behavioural analytics with PCI DSS mapping, highlighting devices that have drifted from expected standards while producing audit-ready compliance reports. Instead of treating compliance as an annual exercise, organisations gain continuous visibility into their security posture and can resolve issues before they become audit findings.
This creates a shared understanding of risk across security, operations and compliance teams, allowing them to prioritise action before issues become business or regulatory problems.
From visibility to action
Managing a handful of payment devices is one thing. Managing tens of thousands across multiple countries is another entirely.
Modern anomaly detection platforms combine behavioural analytics, threat intelligence, PCI DSS mapping, risk scoring, and automated reporting to give security teams the context they need to focus on genuine threats rather than endless alerts.
Organisations already deploying AI-powered anomaly detection at scale are finding that its greatest value lies not in producing more alerts, but in helping security teams focus on the few events that genuinely matter. Combining continuous behavioural monitoring with compliance context allows large payment estates to become more manageable, while giving organisations greater confidence that emerging risks will be identified before they become operational or regulatory issues.
The industry needs to think differently
The lesson from Volt Typhoon is simple. Attackers are becoming quieter, more patient and increasingly willing to exploit the connected devices organisations are most likely to overlook.
For payment providers, that raises an uncomfortable question.
If one payment terminal quietly changed its behaviour tomorrow, how long would it take before anyone noticed?
For many organisations, the honest answer is probably longer than they’d like.

As payment estates continue to expand and operational resilience becomes a regulatory expectation rather than a competitive advantage, the industry needs to stop treating detection as an enhancement to existing security controls and start recognising it as a core security capability.
Prevention will always remain essential. It just can’t be the only strategy.
The payments industry has spent the last decade asking, “How do we stop attackers getting in?”
The next decade will belong to organisations asking a different question.
“How quickly do we know something isn’t right?”
In my view, that shift in mindset, more than any individual technology, will define the next generation of payment security.



















