Skip to content
Tuesday 21 July 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
City PM

European business, markets and politics

FTSE 100
10,585.91
+0.58%
DAX
25,011.35
+0.66%
CAC 40
8,363.14
+0.28%
STOXX 50
6,285.63
+0.94%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Tuesday 13 December 2022 2:52 pm  |  Updated:  Tuesday 17 January 2023 3:17 pm

Over-confidence and under-investment: why banks are on the back foot against ransomware

For unlucky financial institutions, a ransomware attack can seem like a high stakes game of poker. They’re faced with an opponent who claims a winning hand – having potentially encrypted and stolen large volumes of data. But how strong is their hand really? Are they bluffing? Did the IT team manage to pull the plug before serious damage was done? And can data be restored from backup?

For those able to hold their nerve and gain rapid insight into the “blast radius” of an attack, it may be possible to manage the fallout without losing too much sleep. But that requires the kind of mature cybersecurity posture that many organisations lack. Unfortunately, businesses are often over-confident and under-invested in the kind of tools that can help to mitigate ransomware risk. And those risks are growing all the time.

An attractive target

UK lenders may thus far have been spared a devastating headline-grabbing ransomware breach. But their counterparts in the US have been hit time and again in recent years, both directly and via their suppliers. That’s led UK Finance to describe ransomware as one of the most “significant” cyber-threats around, with “serious economic, security and public safety consequences for the financial sector and the UK economy at large.”

Attacks combine the prospect of large-scale data theft and service outages, both of which could cause major financial and reputational damage to a victim organisation. The average global cost of a data breach in financial services now stands at nearly $6m (£5.2m), the second highest sector after healthcare. That, and the highly monetisable nature of the customer data that banks store, makes the industry an attractive target for ransomware actors.

Respondents to a recent global Trend Micro study seem to agree. Over three-quarters (79%) argue that financial services is a more popular target than other verticals, and 87% think they’ll be a target going forward. And they’re right. Some 72% of responding banks say they’ve already been compromised by ransomware over the past three years, with most experiencing data encryption and leaks, and operational outages. The latter took days or weeks to resolve, in most cases.

Case Study & Research

Read more

Professional services firms the ‘flavour of the month’ for cyberattacks

The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”

Confidence but no insight

Unfortunately, awareness of the high-level threat is not translating into effective action to mitigate it. Why? Because most (75%) of the financial services IT and business leaders we spoke to believe their organisation is already adequately protected. That kind of confidence is not replicated in any of the other sectors we studied.

On the one hand, it’s somewhat justified. After all, financial services firms spend a lot on cyber security. And they’re getting the basics right: adding controls to tackle phishing, vulnerability exploitation and compromise of remote working infrastructure – the top attack vectors for ransomware.

Yet on the other hand, they’re not focused on what matters. Determined ransomware actors will always find a way into corporate networks. The key is discovering them before they’ve had time to fully map the network, steal the data and encrypt it. This is the job of detection and response tools with a network (NDR), endpoint (EDR) and multi-layered (XDR) focus. Unfortunately, adoption of these tools stands at less than 50% of the financial services firms we polled. Perhaps as a result, few are able to detect hackers as they gain initial access to networks, or when they begin to wander laterally from IT asset to asset.

It’s not me it’s you

This kind of visibility is critical not only in the context of protecting the organisation itself, but also its extended supply chain. Over half (56%) of financial services firms say a supplier has been compromised by ransomware in the past, most of which were partners and subsidiaries. A similar number argue that their suppliers actually make them a more attractive target. Increasingly digital partners including managed service providers (MSPs) are being targeted as a means to infect downstream customers.

More concerning still, most of the banks we polled admit they have a “significant” number of suppliers that are SMBs, which typically have fewer resources to spend on cyber. Sharing threat intelligence with them could help to improve the security posture of the entire ecosystem, and yet many don’t. Could it be that they don’t have the information to share in the first place?

The bottom line is that ransomware is here to stay. To give themselves the best chance of avoiding a serious breach, financial services firms need to see more clearly inside their own networks. That will help them to contain risk before it spreads, and give business leaders the confidence to call their opponents’ bluff.

Read more

Gambit Cyber Launches Vizier AI – An Autonomous Security Intelligence Workspace for Continuous Exposure Management

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • Markets & Economics

Categories

  • Business
  • Banking
  • Tech

Trending Articles

  • Revealed: KPMG and Deloitte offer bumper redundancy packages to slash headcount

  • Romesh Ranganathan makes it hard to defend the BBC

  • Exclusive: Rugby World Champions Cup set to be mothballed

  • John Healey becomes Chancellor as Andy Burnham names top Cabinet appointments

  • Rachel Reeves’ sister takes top legal role in Burnham’s Cabinet overhaul

More from City PM

  • Professional services firms the ‘flavour of the month’ for cyberattacks

    Prof Services
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • Gambit Cyber Launches Vizier AI – An Autonomous Security Intelligence Workspace for Continuous Exposure Management

    Business Wire
  • Comrade Trustee Services goes live with Smartstream’s Air, the AI reconciliation and data automation solution

    Business Wire
  • WP Engine Enhances Global Edge Security With Bot Management to Control AI-Driven Website Traffic

    Business Wire
  • London-listed healthcare services firm hit by cyberattack

    Markets
    Assura has been the subject of a ferocious bidding war for nearly six months
  • M&S to face shareholder grilling over cyber attack recovery

    Retail
    Marks and Spencer was one of three UK retailers to be targeted
  • RealPage Acquires Cherre, Creating a Trusted AI-Powered Intelligence Platform Across the Full Real Estate Capital Stack

    Business Wire
  • GSK says AI is reshaping drug pipeline as Nuvalent deal hits shares

    Tech
    GSK said total sales fell by two per cent in the third quarter
CityPM

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About City PM
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 City PM Ltd · Published by CityPM Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook