BUSINESS • 5 min read

The real cyber security blind spot in finance is execution

Banks, insurers, and investment firms all face rising ransomware, AI-driven attacks, and supply chain risk, but the biggest gap is between documented security plans and what teams can actually do under pressure. Here's what every financial services leader needs to know.

Financial services has topped the list of most-targeted industries for cyberattacks for years. Not only is that pattern not changing, it's actually intensifying. This isn't a banks-only problem: insurers, investment firms, payment providers, and asset managers are all squarely in scope. What is changing is who gets hit, how fast attacks move, and how much distance has opened up between what institutions say they can do in a crisis and what their teams can deliver when one hits.

Cyberattacks on financial services: same attack types, bigger blast radius

The attack vectors hitting financial institutions today are the familiar ones: phishing, ransomware, DDoS, malware, and fraud. What's evolved isn't the playbook, it's the scale and speed behind it. The IMF warns that AI-driven cyber risk is becoming a genuine threat to financial stability, not just an operational nuisance for individual firms.

Key data points security leaders should know:

AI is the multiplier behind all of this. It's making threat actors faster, more convincing, and harder to detect, while financial institutions remain part of an interconnected data supply chain where one weak link creates ripple effects across the entire industry.

Why financial institutions are stuck in reactive cybersecurity mode

Only 24% of financial services firms are spending significantly more on proactive versus reactive security measures. That's a striking number for an industry that already knows it's a top target.

The root issue goes beyond a lack of frameworks or documentation, to an over-reliance on them. Incidents in the real world rarely fall neatly into one attack category, and no amount of framework alignment or paper-based readiness closes the gap between what the audit says a team can do and real performance.

There are efforts to address this discrepancy, industry-wide. Regulators are already pushing the industry toward continuous validation instead of point-in-time compliance:

  • DORA (the EU's Digital Operational Resilience Act) requires financial entities to run regular resilience testing, including threat-led penetration testing for larger institutions.
  • FedRAMP Revision 5 now mandates annual red team exercises in the US, setting expectations for adversarial testing beyond a standard penetration test.

Tabletop exercises and breach simulations, run frequently, tailored to the organization, with real feedback loops, are proving to be one of the most effective ways to surface internal vulnerabilities before an actual incident does it for you. We've seen IR teams update runbooks in real-time, discovering new opportunities for improvement while going through and exercise.

The cybersecurity blind spot in financial services: burnout and team conditions

Here's where the industry still underinvests: in the conditions under which security teams operate, and the culture they communicate, escalate and learn within.

That cultural deficit shows up in the data on visibility, too:79% of frontline managers say their organization was successfully attacked last year, compared to just 65% of executives who say the same. If leadership isn't getting an accurate picture of what's actually happening on the ground, it can't make the right calls when it matters.

The next cyber security threat in finance: AI-accelerated supply chain attacks

AI isn't creating an entirely new category of risk, it's widening the execution gap that already exists. AI-enabled attacks are up 89% year-over-year, meaning security teams are facing unfamiliar scenarios more often, and with less warning.

The supply chain dimension is the one to watch most closely. AI is making it dramatically easier for attackers to scan supplier networks for vulnerabilities and move quickly once they've found a foothold, and most financial institutions have limited direct experience defending against this specific pattern. The firms building that muscle now, through realistic, adversarial-style testing rather than static frameworks, will be in a materially stronger position as this trend accelerates.

How financial services firms can close the cybersecurity execution gap

The technology arms race in cybersecurity isn't going away, but for financial institutions, the more urgent fix is closer to home. Closing the gap between documented security posture and real-world team performance requires:

  1. Continuous, realistic validation. Not annual audits, but frequent, adversarial-style exercises.
  2. Psychological safety. Teams need to be able to escalate uncertainty without fear of blame.
  3. Aligned visibility. Leadership and frontline teams need to be looking at the same picture of risk.

Institutions that treat capability-building as an ongoing discipline, not a compliance checkbox, will be the ones equipped to handle whatever AI-accelerated threats come next.

Want to explore how to build security capability for financial services and insurance? Let's talk.

FAQ: cybersecurity in financial services

What's the biggest cybersecurity risk facing financial services in 2026? The biggest risk isn't a single attack type. It's the widening gap between documented security readiness and what teams can actually execute during a real incident, a gap that AI-accelerated attacks are making more costly by the day.

Why is financial services the most targeted industry for cyberattacks? Financial institutions sit at the center of a sensitive data supply chain, hold high-value assets, and are deeply interconnected with other firms, meaning a single vulnerability can ripple across the broader industry.

How does burnout affect cybersecurity outcomes? Burnout is directly linked to breaches: 83% of security professionals report that burnout contributed to an incident at their organization, and most insider-caused incidents stem from fatigue and human error rather than malicious intent.

What is DORA and why does it matter for cyber resilience? DORA (the Digital Operational Resilience Act) requires financial institutions across the EU to conduct regular resilience testing, reflecting a regulatory shift toward continuous validation of cyber readiness rather than one-time compliance checks.

How is AI changing cyberattacks on financial institutions? AI is acting as a force multiplier for attackers, making phishing, ransomware, and supply chain attacks faster, more personalized, and harder to detect, with AI-enabled attacks rising 89% year-over-year.

authorJoanna Duffy
Jul 22, 2026

Recommended

Get more insights, news, and assorted awesomeness around cyber training.

Join over 640 organisations upskilling their
workforce with TryHackMe