Financial firms are targeted 300 times more often than other companies.
The ICBC ransomware event disrupted clearing of US Treasury trades, and the August 2025 Marquis Software compromise cascaded across 74 US banks and credit unions. Each started with a single unremediated weakness — an unpatched edge appliance at ICBC, a third-party vendor at Marquis.
Why Financial Services is in the crosshairs
Five shifts shaping the financial services threat environment — from customer fraud to systemic disruption, and from documentation to demonstration.
The attack volume is structural, not cyclical
Boston Consulting Group's 300x targeting-frequency stat captures something fundamental: financial services holds directly monetisable data (payment credentials, account access, tax and identity information) and is a gateway to wire-fraud attacks. This does not go away with a good quarter of defensive investment.
The pattern has shifted from customer fraud to systemic disruption
Colonial Pipeline taught one lesson about critical infrastructure; ICBC's November 2023 ransomware incident taught an equivalent one for finance. A single compromise disrupted clearing of US Treasury trades, forcing BNY Mellon to unplug ICBC from the Treasury market and requiring manual trade clearing via USB stick. DBRS Morningstar framed it as showing "the potential effect of a major disruption of the global payment system."
Third-party and partner-bank exposure dominates the threat picture
Marquis Software in August 2025 affected 74 US banks and credit unions through a SonicWall firewall vulnerability. Evolve Bank & Trust in 2024 exposed 7.6 million customers, with Affirm and Wise downstream. The breach of Infosys McCamish, a third-party plan administrator, prompted Bank of America customer notifications. The pattern: attack a specialist provider, compromise many institutions at once.
The root causes are the ones continuous validation is built to find
Sophos' 2025 finance sector data identifies the top operational root causes as "lack of or poor-quality protection" (66%) and "security gaps, known or unknown" (67%). Misconfigurations, exploitable attack paths, weak identity hygiene, exposed edge services — these are exactly what attack-based testing surfaces before a real adversary does.
Regulation is converging on the "prove it works" demand
APRA CPS 234 requires information security commensurate with threat level. CPS 230 operational resilience is now in force. CORIE exercises stress-test major entities. Europe's DORA is in force. The US SEC's 2023 cyber disclosure rules require material incidents to be reported within four business days. Every jurisdictional regulator is moving in the same direction — demonstration of effective controls, not just documentation of their existence.
What regulators and experts are saying
Because banks have invested so heavily in cybersecurity, most of them felt like something like this couldn't happen. This is the first time we've seen an attack like this that is disruptive of the Treasury market.
Ransomware attacks primarily affected service providers (29%) and insurance organisations (17%), with impacts including financial loss (38%), data exposure (35%), and operational disruption (20%).
Failure to establish effective risk assessment processes prior to migrating significant information technology operations to the public cloud.
APRA CPS 230 is now in effect
Since 1 July 2025, APRA CPS 230 requires tested resilience of critical operations — and CPS 234 separately mandates systematic testing of information security controls, with board accountability
APRA-regulated entities — banks, credit unions, building societies, general and life insurers, private health insurers, and superannuation trustees — must comply with Prudential Standard CPS 234 (Information Security). CPS 234 is a principles-based standard requiring controls commensurate with the size and extent of threats to information assets. It explicitly mandates systematic testing of control effectiveness. Entities that store, process, or transmit cardholder data must also comply with PCI DSS v4.0.1, which has 12 principal requirements — all future-dated requirements became mandatory on 31 March 2025. CPS 230 (Operational Risk Management) extends APRA requirements to material service providers, with pre-existing contracts required to comply by the earlier of their next renewal date or 1 July 2026.
Principles-based standard with 8 requirement areas. Applies to all APRA-regulated entities (~1,150 entities overseeing $9.8 trillion in assets).
Applies to financial services entities that store, process, or transmit cardholder data. All future-dated v4.0.1 requirements became mandatory 31 March 2025.
Widely adopted as the baseline security framework by Australian financial institutions. APRA references ASD guidance in CPS 234 expectations.
Where NodeZero appliesMany APRA-regulated entities maintain ISO 27001 certification as complementary evidence for CPS 234 compliance.
Where NodeZero appliesRequired for financial services organisations providing technology or managed services to other regulated entities.
Where NodeZero appliesFinancial institutions handle significant volumes of personal and sensitive financial information subject to the Australian Privacy Principles.
Where NodeZero appliesMandatory ransomware payment reporting applies over $3M turnover; SOCI-regulated assets carry separate incident notification obligations.
Where NodeZero appliesA cascade of new obligations
Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.
APRA CPS 230 — Operational resilience
1 Jul 2025Stress testing of critical functions including cyber-attack scenarios. Recovery time objectives must be validated. Board attestation on resilience required with testing evidence.
Cyber Security Act 2024
30 May 2025Mandatory ransomware payment reporting within 72 hours for entities over $3M turnover. Financial services entities are prime targets. NodeZero identifies ransomware attack vectors before attackers exploit them.
Privacy Act statutory tort
10 Jun 2025Private right of action for serious privacy invasions from June 2025. Financial services entities handling sensitive financial and health information face direct litigation risk. Enhanced OAIC enforcement powers with penalties up to $50M.
PCI DSS v4.0.1 — All requirements mandatory
31 Mar 2025All 51 future-dated requirements became mandatory on 31 March 2025. Six-monthly segmentation testing for service providers (annual for merchants) and annual penetration testing now fully enforced.
Find your organisation
See how the changes affect you specifically
Banks & ADIs
Big 4, regional banks, and authorised deposit-taking institutions. APRA CPS 234 mandatory compliance with board attestation on security control effectiveness.
View details →Insurers & superannuation
General insurers, life insurers, and superannuation trustees. Same APRA CPS 234 requirements as banks, with beneficiary breach notification obligations.
View details →Payments & fintech
Payment processors, neobanks, and fintech companies. PCI DSS v4.0.1 is fully mandatory with all 51 future-dated requirements now in effect.
View details →The only autonomous pentesting platform that is:
Prove your compliance posture before your next APRA assessment
See how NodeZero maps to CPS 234, CPS 230, and PCI DSS in your environment


