Loading

FINANCIAL SERVICES CYBER RESILIENCE REPORT

Is your bank's recovery plan ready for today's threats, and the emerging ones still ahead? New research reveals what most financial services organizations are missing.
Report cover stack

The world changed. Recovery plans haven’t.

Material cyberattacks are becoming more frequent

70% of financial services organizations experienced one in the past 12 months, up from 57% the year before.

Attacks are also becoming more complex

AI and autonomous agents create new risks. A growing web of connected trading, payment, and third-party systems widens their reach.

Most recovery plans aren't built for this kind of pressure

They assume incidents are understood, dependencies are mapped, and recovery is predictable.

The 5th annual Cohesity Global Cyber Resilience Report, conducted by Vanson Bourne, surveyed more than 400 IT and security leaders in the financial services sector across 12 countries to reveal how those plans hold up under real pressure.

Outdated assumptions are still shaping recovery plans

Respondents who experienced a material cyberattack in the last 12 months

Assumption

83%

assume incidents can be fully contained before recovery begins.

containment icon
Reality

70%

saw the scope expand beyond their initial assessment.

Assumption

85%

assume dependencies are mapped clearly enough to sequence recovery accurately in advance.

dependencies icon
Reality

60%

found moderate to significant gaps in dependencies they hadn't accounted for.

Assumption

86%

assume once core systems are restored, business operations can safely resume.

operations icon
Reality

65%

experienced delays in resuming normal business operations, even after core systems were restored.

Minimum Viable Company (MVC):
defined in advance, not assumed

A Minimum Viable Company is the smallest set of financial and operational capabilities — core payments processing, transaction settlement, customer account access — a financial organization must keep running while broader recovery continues. It's a defined operating model about what matters most, decided before a crisis hits.

Venn diagram
Connector
22 percent
Only 18% have formally documented and tested an MVC.
66 percent
55% haven't validated that their MVC would perform as intended during a cyberattack.
78 percent
75% say their cyber recovery plan is more focused on restoring systems than maintaining critical customer-facing operations during recovery.

AI is the next frontier for cyber resilience in financial services

AI is becoming more capable and more embedded in trading, fraud detection, and customer-facing workflows. That's introducing risks recovery plans haven't yet accounted for, from the AI already in use today to the more capable models still to come.

0%

are not very confident they can verify AI model integrity after an incident.
Model Integrity AI icon

0%

are not well prepared to detect or contain unintended actions by AI agents or workflows.
AI workflow containment icon

0%

say their recovery plan would require moderate or significant changes to withstand cyberattacks accelerated by frontier AI models.
AI recovery plan icon
Read the full report

Financial Services Cyber Resilience Report

Thank you for your interest.

thankyou-hero-banner

Recovery has changed. Have the plans?

Explore findings by market and industry
Global
Australia
Coming soon
Brazil
Coming soon
France
Coming soon
Germany
Coming soon
India
Coming soon
Japan
Coming soon
Singapore
Coming soon
South Korea
Coming soon
United Arab Emirates
Coming soon
United Kingdom


Industry reports
Financial
Healthcare
Public Sector
Manufacturing
Coming soon
Retail
Coming soon
Telco
Coming soon
Energy, oil & gas
Coming soon
Commercial
Coming soon
Loading