As cyberthreats increasingly target the financial services sector, organisations face growing pressure to ensure resilience and prevent isolated incidents from escalating into systemic crises. Neil Roseman, CEO of Invicti, examines why continuous assurance, regulatory scrutiny and proactive cyber-risk management are now essential to safeguarding financial stability.

It’s hard to overstate the importance of the financial services sector to the global economy. It exists at the nexus point between consumers, businesses and governments, providing and managing the necessary capital to keep markets trading, transactions flowing and currency exchanging. As such, the stability of economies, societies and governments, is largely reliant on the health of this sector.
That also makes it a prime target for cybercriminals and other threat actors. According to data from the International Monetary Fund (IMF), one fifth of all cyberattacks directly target financial firms. While most of those attacks are mitigated, a successful attack here can cause chaos for the societies, economies and financial systems which they serve.
Indeed, there are already catalogued examples of cyberattacks which have threatened the health of financial systems – indeed, 2023 alone showed a number of examples in just two months. In November, a cyberattack on the Industrial and Commercial Bank of China’s (ICBC) US wing disrupted market clearance and even affected the US Treasury trading infrastructure. In December, an attack on Lesotho’s central bank meant that local banks simply couldn’t transact. Days after that attack, another ransomware attack on a US IT provider paralysed 60 US credit unions, plunging their daily operations into chaos. Many firms take security very seriously, the risks and potential damages are often too high to simply ignore.
How a cyber incident can become a systemic threat
IMF’s April 2024 Global Financial Stability Report discusses the ways in which a technology failure or breach at a financial services company could lead to systemic instability. It first notes that the mere lack of confidence post-incident could lead to a run on a bank, creating liquidity risks and solvency issues with a potential to spill over into broader markets.
Moreover, a cyber incident affecting a key financial institution or hub in the financial system – such as a clearing house – could also pose a systemic risk. In the case of, for example, a ransomware attack on a central bank, the aftereffects could spill out to affect other financial institutions, businesses and government bodies that depend on it.
The report concludes that the reliance of the sector on particular pieces of technology – such as trading software – and financial linkages – such as interbank market and settlement systems – could spread the effect of a cyber incident across a broader financial system. The report continues: “Major cyber incidents could thus adversely affect macroeconomic outcomes, for example, through a decline in the provision of credit or a disruption of payment systems.”
Regulators take notice
Regulators are now focusing on these risks as a matter of urgency. The best example of this so far is the Digital Operational Resilience Act (DORA) which came into effect in early 2025.
DORA will govern the European financial system, a central hub for global finance and compel them to take a number of steps to secure themselves.
To that end, DORA will make financial services companies perform operational resilience testing, regularly assessing ICT systems and procedures to examine their preparedness for an attack or incident, largely through vulnerability assessments and penetration tests. This is meant to demonstrate how well these financial services firms can respond to and recover from incidents in the case of an incident.
In the regulation’s text, authors put these measures into context, stating that a compromise on one of these institutions could ‘smooth the way for the propagation of localised vulnerabilities across the financial transmission channels and potentially trigger adverse consequences for the stability of the Union’s financial system, such as generating liquidity runs and an overall loss of confidence and trust in financial markets.’
A new kind of assurance
Assurance, then, should be at the forefront of everyone’s mind when it comes to thinking about cyber-risk in this sector. Looking ahead, financial services will be required to provide assurance to regulators and customers, ensuring their own security and clearly demonstrating it too.
The continuous scanning and assessment of the IT environment for vulnerabilities and bugs will help organisations in this sector ensure and prove that assurance. While penetration tests are an important part of demonstrating assurance, these generally happen every couple of months at most. The reality of IT in financial services is that these are often vast, multivariate environments with countless moving parts. Significant changes can happen within a day and periodic tests will not account for the potential vulnerabilities and breach points that open up in the space of 24 hours.
Instead, continuous scanning and vulnerability assessment should be considered the core element of assurance in financial services, tracking changes and spotting vulnerabilities as they emerge. This will also provide the data needed to understand trends in the environment over time – aiding cyber efforts in both near and far terms. That data will also provide a rich body of evidence of assurance to both regulators and consumers.
Assurance against these kinds of threats is something that will be expected by regulators and clients alike: A financial services company that can’t protect its ICT infrastructure or stay resilient in an age of growing cyber-risk will be punished by regulators as well as the stakeholders and markets it’s supposed to serve.
Assurance through continuous scanning and vulnerability assessment provides a way to make sure that a threat in one firm doesn’t become a systemic threat. Indeed, as cyber-risk grows, it may become the new price of doing business in the sector.

