Banks, insurers, and investment firms all face rising ransomware, AI-driven attacks, and supply chain risk, but the biggest gap is between documented security plans and what teams can actually do under pressure. Here's what every financial services leader needs to know.
Financial services has topped the list of most-targeted industries for cyberattacks for years. Not only is that pattern not changing, it's actually intensifying. This isn't a banks-only problem: insurers, investment firms, payment providers, and asset managers are all squarely in scope. What is changing is who gets hit, how fast attacks move, and how much distance has opened up between what institutions say they can do in a crisis and what their teams can deliver when one hits.
Cyberattacks on financial services: same attack types, bigger blast radius
The attack vectors hitting financial institutions today are the familiar ones: phishing, ransomware, DDoS, malware, and fraud. What's evolved isn't the playbook, it's the scale and speed behind it. The IMF warns that AI-driven cyber risk is becoming a genuine threat to financial stability, not just an operational nuisance for individual firms.
Key data points security leaders should know:
- Ransomware attacks against financial institutions rose roughly 30% in 2025, with early 2026 data suggesting the pace is accelerating further.
- Investment firms now account for over 41% of ransomware disclosures in the sector, a dramatic reversal from 2023 when banks were the primary target, a signal that attackers have moved well beyond traditional retail banking targets.
- Financial services breaches have been among the most costly of any industry for years.
- Financial services now has the second-highest average data breach cost of any industry globally at $5.56 million, behind only healthcare.
AI is the multiplier behind all of this. It's making threat actors faster, more convincing, and harder to detect, while financial institutions remain part of an interconnected data supply chain where one weak link creates ripple effects across the entire industry.
Why financial institutions are stuck in reactive cybersecurity mode
Only 24% of financial services firms are spending significantly more on proactive versus reactive security measures. That's a striking number for an industry that already knows it's a top target.
The root issue goes beyond a lack of frameworks or documentation, to an over-reliance on them. Incidents in the real world rarely fall neatly into one attack category, and no amount of framework alignment or paper-based readiness closes the gap between what the audit says a team can do and real performance.
There are efforts to address this discrepancy, industry-wide. Regulators are already pushing the industry toward continuous validation instead of point-in-time compliance:
- DORA (the EU's Digital Operational Resilience Act) requires financial entities to run regular resilience testing, including threat-led penetration testing for larger institutions.
- FedRAMP Revision 5 now mandates annual red team exercises in the US, setting expectations for adversarial testing beyond a standard penetration test.
Tabletop exercises and breach simulations, run frequently, tailored to the organization, with real feedback loops, are proving to be one of the most effective ways to surface internal vulnerabilities before an actual incident does it for you. We've seen IR teams update runbooks in real-time, discovering new opportunities for improvement while going through and exercise.
The cybersecurity blind spot in financial services: burnout and team conditions
Here's where the industry still underinvests: in the conditions under which security teams operate, and the culture they communicate, escalate and learn within.
- 83% of security professionals say burnout has directly contributed to a breach at their organization, and 39% say it's happened more than once.
- 75% of insider-caused incidents are non-malicious: fatigue, distraction, and errors made under pressure, not sabotage.
- 88% of the profession believes a blame culture exists in cybersecurity, and the UK's National Cyber Security Centre has formally identified fear of blame as a factor that blocks the flow of critical information during incidents.
That cultural deficit shows up in the data on visibility, too:79% of frontline managers say their organization was successfully attacked last year, compared to just 65% of executives who say the same. If leadership isn't getting an accurate picture of what's actually happening on the ground, it can't make the right calls when it matters.
The next cyber security threat in finance: AI-accelerated supply chain attacks
AI isn't creating an entirely new category of risk, it's widening the execution gap that already exists. AI-enabled attacks are up 89% year-over-year, meaning security teams are facing unfamiliar scenarios more often, and with less warning.
The supply chain dimension is the one to watch most closely. AI is making it dramatically easier for attackers to scan supplier networks for vulnerabilities and move quickly once they've found a foothold, and most financial institutions have limited direct experience defending against this specific pattern. The firms building that muscle now, through realistic, adversarial-style testing rather than static frameworks, will be in a materially stronger position as this trend accelerates.
How financial services firms can close the cybersecurity execution gap
The technology arms race in cybersecurity isn't going away, but for financial institutions, the more urgent fix is closer to home. Closing the gap between documented security posture and real-world team performance requires:
- Continuous, realistic validation. Not annual audits, but frequent, adversarial-style exercises.
- Psychological safety. Teams need to be able to escalate uncertainty without fear of blame.
- Aligned visibility. Leadership and frontline teams need to be looking at the same picture of risk.
Institutions that treat capability-building as an ongoing discipline, not a compliance checkbox, will be the ones equipped to handle whatever AI-accelerated threats come next.
Want to explore how to build security capability for financial services and insurance? Let's talk.
FAQ: cybersecurity in financial services
What's the biggest cybersecurity risk facing financial services in 2026? The biggest risk isn't a single attack type. It's the widening gap between documented security readiness and what teams can actually execute during a real incident, a gap that AI-accelerated attacks are making more costly by the day.
Why is financial services the most targeted industry for cyberattacks? Financial institutions sit at the center of a sensitive data supply chain, hold high-value assets, and are deeply interconnected with other firms, meaning a single vulnerability can ripple across the broader industry.
How does burnout affect cybersecurity outcomes? Burnout is directly linked to breaches: 83% of security professionals report that burnout contributed to an incident at their organization, and most insider-caused incidents stem from fatigue and human error rather than malicious intent.
What is DORA and why does it matter for cyber resilience? DORA (the Digital Operational Resilience Act) requires financial institutions across the EU to conduct regular resilience testing, reflecting a regulatory shift toward continuous validation of cyber readiness rather than one-time compliance checks.
How is AI changing cyberattacks on financial institutions? AI is acting as a force multiplier for attackers, making phishing, ransomware, and supply chain attacks faster, more personalized, and harder to detect, with AI-enabled attacks rising 89% year-over-year.