Skip to content
Monday 31 August 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE · FR
MorningWire

European business, markets and politics

FTSE 100
10,824.26
+0.29%
DAX
26,258.11
-1.17%
CAC 40
8,334.50
-0.79%
STOXX 50
6,420.16
-1.01%
  • Europe
  • Markets
  • Business
  • Economy
  • Regulation
  • Politics
  • Opinion
More
GermanyFranceEU InstitutionsCompetitionPublic AffairsBankingTechnologyEnergy
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Regulation
  • Politics
  • Opinion
  • DE
Tuesday 13 December 2022 2:52 pm  |  Updated:  Tuesday 17 January 2023 3:17 pm

Over-confidence and under-investment: why banks are on the back foot against ransomware

For unlucky financial institutions, a ransomware attack can seem like a high stakes game of poker. They’re faced with an opponent who claims a winning hand – having potentially encrypted and stolen large volumes of data. But how strong is their hand really? Are they bluffing? Did the IT team manage to pull the plug before serious damage was done? And can data be restored from backup?

For those able to hold their nerve and gain rapid insight into the “blast radius” of an attack, it may be possible to manage the fallout without losing too much sleep. But that requires the kind of mature cybersecurity posture that many organisations lack. Unfortunately, businesses are often over-confident and under-invested in the kind of tools that can help to mitigate ransomware risk. And those risks are growing all the time.

An attractive target

UK lenders may thus far have been spared a devastating headline-grabbing ransomware breach. But their counterparts in the US have been hit time and again in recent years, both directly and via their suppliers. That’s led UK Finance to describe ransomware as one of the most “significant” cyber-threats around, with “serious economic, security and public safety consequences for the financial sector and the UK economy at large.”

Attacks combine the prospect of large-scale data theft and service outages, both of which could cause major financial and reputational damage to a victim organisation. The average global cost of a data breach in financial services now stands at nearly $6m (£5.2m), the second highest sector after healthcare. That, and the highly monetisable nature of the customer data that banks store, makes the industry an attractive target for ransomware actors.

Respondents to a recent global Trend Micro study seem to agree. Over three-quarters (79%) argue that financial services is a more popular target than other verticals, and 87% think they’ll be a target going forward. And they’re right. Some 72% of responding banks say they’ve already been compromised by ransomware over the past three years, with most experiencing data encryption and leaks, and operational outages. The latter took days or weeks to resolve, in most cases.

Case Study & Research

Read more

Champions Cup rugby team hacked in ransom attack with player data at risk

Rugby player in a pink uniform running with the ball, pursued by an opponent in a black jersey.

Confidence but no insight

Unfortunately, awareness of the high-level threat is not translating into effective action to mitigate it. Why? Because most (75%) of the financial services IT and business leaders we spoke to believe their organisation is already adequately protected. That kind of confidence is not replicated in any of the other sectors we studied.

On the one hand, it’s somewhat justified. After all, financial services firms spend a lot on cyber security. And they’re getting the basics right: adding controls to tackle phishing, vulnerability exploitation and compromise of remote working infrastructure – the top attack vectors for ransomware.

Yet on the other hand, they’re not focused on what matters. Determined ransomware actors will always find a way into corporate networks. The key is discovering them before they’ve had time to fully map the network, steal the data and encrypt it. This is the job of detection and response tools with a network (NDR), endpoint (EDR) and multi-layered (XDR) focus. Unfortunately, adoption of these tools stands at less than 50% of the financial services firms we polled. Perhaps as a result, few are able to detect hackers as they gain initial access to networks, or when they begin to wander laterally from IT asset to asset.

It’s not me it’s you

This kind of visibility is critical not only in the context of protecting the organisation itself, but also its extended supply chain. Over half (56%) of financial services firms say a supplier has been compromised by ransomware in the past, most of which were partners and subsidiaries. A similar number argue that their suppliers actually make them a more attractive target. Increasingly digital partners including managed service providers (MSPs) are being targeted as a means to infect downstream customers.

More concerning still, most of the banks we polled admit they have a “significant” number of suppliers that are SMBs, which typically have fewer resources to spend on cyber. Sharing threat intelligence with them could help to improve the security posture of the entire ecosystem, and yet many don’t. Could it be that they don’t have the information to share in the first place?

The bottom line is that ransomware is here to stay. To give themselves the best chance of avoiding a serious breach, financial services firms need to see more clearly inside their own networks. That will help them to contain risk before it spreads, and give business leaders the confidence to call their opponents’ bluff.

Read more

Stansted Airport owner hit with cyber attack as millions of customers’ data stolen

London Stansted Airport is part of the wider Manchester Airports Group (MAG).

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • Markets & Economics

Categories

  • Business
  • Banking
  • Tech

Trending Articles

  • Pensioners to hand over bank statements in government benefits crackdown

  • Jaguar reveals the Type 01’s screen-free interior

  • Jamie Carragher: HMRC petitions for Sky Sports star to be declared bankrupt

  • City firms mandate phone and face-to-face comms bootcamps for Gen Z lawyers

  • Jamie Vardy bags Bundesliga rights as he steps up streaming war with Neville and Lineker

More from Morning Wire

  • Champions Cup rugby team hacked in ransom attack with player data at risk

    Sport Business
    Rugby player in a pink uniform running with the ball, pursued by an opponent in a black jersey.
  • Stansted Airport owner hit with cyber attack as millions of customers’ data stolen

    Transport & Infrastructure
    London Stansted Airport is part of the wider Manchester Airports Group (MAG).
  • Can debt-ridden Morrisons become a Big Four supermarket again?

    Retail
    Green Instacart shopping cart outside a modern Morrisons supermarket entrance with large glass windows
  • As it happened: Stocks fall into red as oil fluctuates over Middle East developments

    FTSE 100 Live
    Large oil tanker navigating a strait under a cloudy sky, impacting oil prices and global trade.
  • Saba revives attack on Baillie Gifford trust

    Investing
    Baillie Giffords Edinburgh headquarters with SpaceX investor branding prominently displayed on the modern office building ...
  • Iranian hackers behind UK energy plant attack

    Energy
    UK industrial electricity prices are the highest in the G7 and 46 per cent above the average of the International Energy Agency.
  • Rehlko Defines What It Takes to Build AI-Ready Power Infrastructure as Data Center Energy Demands Evolve

    Business Wire
  • Wenger rubbishes Infantino sell-off plan as senior Fifa figures desert president

    Sport Business
    Arsène Wenger, FIFAs Chief of Global Football Development, in a suit and tie, looking serious.
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • EU Institutions
  • Europe

Business

  • Markets
  • Business
  • Economy
  • Regulation
  • Competition
  • Public Affairs

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook