What is cyber risk and why is it systemic now?
Cyber risk in finance has shifted from organizational to systemic because vendor concentration creates correlated failure modes that no single bank can mitigate alone. The July 2024 CrowdStrike incident demonstrated how a single faulty update can produce sector-wide outages. The average data breach in financial services cost 6.08 million dollars in 2024, 22 percent above the global average.
In this article
The short answer
Cyber risk used to be an institution-by-institution concern: each bank ran its own perimeter defense, incident response and recovery procedures. The implicit model was that an attack on one bank harmed only that bank.
That model has aged poorly. Modern banks share cloud providers, identity systems, security software, payment networks and core banking vendors. A successful intrusion or even a benign software update at one critical vendor can degrade many institutions simultaneously. The attack surface has consolidated faster than the defense surface.
Regulators have responded with operational resilience frameworks. The EU’s DORA regulation, in force since January 2025, the Bank of England’s Operational Resilience Policy Statement, and the Federal Reserve’s third-party risk guidance all push the same message: cyber risk is now a financial stability concern.
→ New to financial stability frameworks? Financial education hub
What the data shows
The economic cost of cyber incidents in finance is among the most quantified categories in operational risk research.
Key figures (IBM Cost of a Data Breach Report 2024, FSB, 2024):
- The global average data breach cost reached $4.88 million in 2024, up 10% year over year, the largest jump since the pandemic
- Financial services breach costs averaged $6.08 million, 22% above the global average and second only to healthcare ($9.77 million)
- Stolen or compromised credentials were the most common initial attack vector at 16% of all breaches
- Credential-based breaches took 292 days on average to identify and contain — the longest of any vector
- Mega-breaches involving 50 million records or more averaged $375 million in costs
- Per-record breach costs reached $150 in 2024, up 9% since 2020
The exception that nuances the headline: organizations using AI and automation extensively in security workflows incurred $2.2 million less in average breach costs than those without — a meaningful asymmetry that compounds the AI-vendor concentration paradox identified in financial services.
→ Dataset: Financial conditions index
Why it happens — the macro mechanism
Cyber risk became systemic through three reinforcing channels.
Channel 1 — Vendor concentration. Financial institutions increasingly rely on a small set of cloud providers (AWS, Azure, Google Cloud), identity vendors, security software vendors (CrowdStrike, Palo Alto, Microsoft Defender) and core banking platforms. The July 2024 CrowdStrike incident illustrated the stakes: a faulty configuration update propagated through Falcon’s automatic deployment system caused widespread outages across financial services, airlines, healthcare and government within hours. No state actor was involved; routine software pushed by a trusted vendor was sufficient to trigger the largest IT outage in history. The attack vector is now the vendor, not the perimeter.
Channel 2 — Supply chain extension. The most underdiscussed feature is that even institutions with rigorous security postures inherit the weakest link in their supply chain. SolarWinds (2020), Kaseya (2021) and MOVEit (2023) all showed that intrusions at IT management or file-transfer vendors can compromise hundreds of downstream institutions before any of them detects the breach. Banks cannot audit the entire dependency tree in practice; they can only require attestations and contractual remediation.
Channel 3 — Asymmetric attacker economics. Ransomware-as-a-service lowered the entry cost for attackers while AI-assisted social engineering raised the success rate of credential phishing. The defender side faces talent shortages, with more than half of breached organizations in 2024 reporting severe security staffing shortages. The cost-of-attack curve fell while the cost-of-defense curve rose.
Synthesis by regime: in the pre-2015 regime, cyber incidents at one institution rarely propagated to others, and supervisors treated cyber as operational risk; in the 2017-2020 regime, the WannaCry, NotPetya and SolarWinds incidents made supply chain risk visible but operational frameworks lagged; in the post-2024 regime, with DORA in force, the CrowdStrike incident as a reference point and AI-driven attack scaling becoming credible, cyber risk is formally treated as a financial stability variable by major central banks.
The bank’s perimeter no longer ends at the bank; it extends through every vendor it shares with the rest of the sector.
→ Framework: Financial innovation and systemic risk
What it means for different economic actors
Banks face rising compliance costs (DORA, Operational Resilience), persistent attacker pressure and increased regulatory scrutiny of third-party concentration. The defensive moat is no longer purely technical; it includes vendor diversification and incident response readiness.
Cyber insurance markets have repriced sharply since 2020. Premiums rose substantially in 2021-2022, capacity tightened, and exclusions for systemic events (state-sponsored attacks, major outages) became more common. Underwriting now requires demonstrated security maturity rather than checkbox compliance.
Regulators are converging on operational resilience as a supervisory category co-equal with capital and liquidity. DORA in the EU, the Bank of England’s framework, and Federal Reserve guidance all require firms to identify critical functions, set impact tolerances, and demonstrate ability to recover within those tolerances.
A common error is treating cyber as a pure IT problem. The 2024 CrowdStrike incident showed it is now a treasury, board and supervisory problem.
Practical observation
What the data suggests for understanding systemic cyber risk:
- Question to ask yourself: What concentrated vendor in my financial supply chain represents the single largest correlated failure risk, and what would happen if it experienced a CrowdStrike-style event?
- Data to monitor: Concentration metrics in cloud providers and security software (a few firms now serve a majority of large banks; the level of concentration matters more than its rate of change at this stage)
- Historical parallel: The July 2024 CrowdStrike outage hit roughly 8.5 million Windows endpoints and triggered an estimated $5 billion in losses for Fortune 500 firms — a benchmark for what a single-vendor disruption can produce
- What the literature documents: The IBM Cost of a Data Breach Report (annual), the Financial Stability Board’s 2023 cyber lexicon, and the EU DORA technical standards provide the current quantitative and regulatory baseline
This is descriptive information to help you frame your own analysis. Eco3min does not provide investment advice.
Go deeper
📊 Full study: Artificial intelligence as systemic financial risk
📁 Datasets: Financial conditions index · US bank lending standards
📖 Related analysis: Markets without signal — dispersion and risk
Related questions
Frequently asked questions
How was the July 2024 CrowdStrike incident different from earlier cyber incidents?
Most major incidents involve malicious intrusion: SolarWinds, NotPetya, the 2014 Sony breach. The CrowdStrike outage of July 19, 2024 was different — no attacker was involved. A defective update to the Falcon endpoint protection software, automatically pushed to clients, caused Windows machines to fail to boot. The incident demonstrated that the vendor itself is now a single point of failure independent of any malicious actor, which changes the supervisory calculus on third-party risk.
What is operational resilience and how does it differ from cyber risk?
Operational resilience is the broader regulatory framework that treats cyber as one component alongside infrastructure failures, vendor outages, and process breakdowns. The EU DORA regulation (Digital Operational Resilience Act), in force since January 2025, requires financial firms to map critical functions, identify ICT third-party dependencies, run resilience testing, and report major incidents. The framework forces institutions to think in terms of continued service delivery rather than just defensive controls.
Why does cyber insurance not fully solve the problem?
Cyber insurance can cover direct losses but does not cover all systemic events. Major insurers introduced “war exclusions” after the NotPetya litigation showed that state-sponsored attacks could be classified as acts of war. Coverage limits, deductibles and exclusions for known vulnerabilities have all tightened since 2021. Insurance is part of the response but cannot substitute for primary controls or vendor diversification.
Last updated — 30 July 2026
Disclaimer – Financial Information: The analyses, commentary, and content published on eco3min.fr are provided for informational and educational purposes only. They do not constitute investment advice or a solicitation to buy or sell financial instruments. Past performance is not indicative of future results. All investment decisions involve risk and are the sole responsibility of the reader.
