DrochaidHorizon3.ai
NodeZero/Industries/Financial Services
The state of play — Financial Services, 2026

Financial firms are targeted 300 times more often than other companies.

The ICBC ransomware event disrupted clearing of US Treasury trades, and the August 2025 Marquis Software compromise cascaded across 74 US banks and credit unions. Each started with a single unremediated weakness — an unpatched edge appliance at ICBC, a third-party vendor at Marquis.

14%
of all Australian notifiable data breaches came from the finance sector in H1 2025 — second only to health (18%), ahead of government (13%).
OAIC Notifiable Data Breaches Report, Jan–Jun 2025
67%
of financial services respondents cited "security gaps, known or unknown" as an operational root cause of their ransomware incidents; 66% cited poor-quality protection.
Sophos State of Ransomware in Financial Services 2025
USD $2.1B
in ransomware payments identified in Bank Secrecy Act data between 2022 and 2024.
FinCEN Financial Trend Analysis
The trend

Why Financial Services is in the crosshairs

Five shifts shaping the financial services threat environment — from customer fraud to systemic disruption, and from documentation to demonstration.

The attack volume is structural, not cyclical

Boston Consulting Group's 300x targeting-frequency stat captures something fundamental: financial services holds directly monetisable data (payment credentials, account access, tax and identity information) and is a gateway to wire-fraud attacks. This does not go away with a good quarter of defensive investment.

The pattern has shifted from customer fraud to systemic disruption

Colonial Pipeline taught one lesson about critical infrastructure; ICBC's November 2023 ransomware incident taught an equivalent one for finance. A single compromise disrupted clearing of US Treasury trades, forcing BNY Mellon to unplug ICBC from the Treasury market and requiring manual trade clearing via USB stick. DBRS Morningstar framed it as showing "the potential effect of a major disruption of the global payment system."

Third-party and partner-bank exposure dominates the threat picture

Marquis Software in August 2025 affected 74 US banks and credit unions through a SonicWall firewall vulnerability. Evolve Bank & Trust in 2024 exposed 7.6 million customers, with Affirm and Wise downstream. The breach of Infosys McCamish, a third-party plan administrator, prompted Bank of America customer notifications. The pattern: attack a specialist provider, compromise many institutions at once.

The root causes are the ones continuous validation is built to find

Sophos' 2025 finance sector data identifies the top operational root causes as "lack of or poor-quality protection" (66%) and "security gaps, known or unknown" (67%). Misconfigurations, exploitable attack paths, weak identity hygiene, exposed edge services — these are exactly what attack-based testing surfaces before a real adversary does.

Regulation is converging on the "prove it works" demand

APRA CPS 234 requires information security commensurate with threat level. CPS 230 operational resilience is now in force. CORIE exercises stress-test major entities. Europe's DORA is in force. The US SEC's 2023 cyber disclosure rules require material incidents to be reported within four business days. Every jurisdictional regulator is moving in the same direction — demonstration of effective controls, not just documentation of their existence.

On the record

What regulators and experts are saying

Because banks have invested so heavily in cybersecurity, most of them felt like something like this couldn't happen. This is the first time we've seen an attack like this that is disruptive of the Treasury market.
Allan Liska
Ransomware researcher, Recorded Future — on the ICBC incident
November 2023
Ransomware attacks primarily affected service providers (29%) and insurance organisations (17%), with impacts including financial loss (38%), data exposure (35%), and operational disruption (20%).
ENISA
Threat Landscape: Finance Sector, January 2023 to June 2024
February 2025
Failure to establish effective risk assessment processes prior to migrating significant information technology operations to the public cloud.
US Office of the Comptroller of the Currency
Enforcement action on Capital One
August 2020
What is now required

APRA CPS 230 is now in effect

Since 1 July 2025, APRA CPS 230 requires tested resilience of critical operations — and CPS 234 separately mandates systematic testing of information security controls, with board accountability

APRA-regulated entities — banks, credit unions, building societies, general and life insurers, private health insurers, and superannuation trustees — must comply with Prudential Standard CPS 234 (Information Security). CPS 234 is a principles-based standard requiring controls commensurate with the size and extent of threats to information assets. It explicitly mandates systematic testing of control effectiveness. Entities that store, process, or transmit cardholder data must also comply with PCI DSS v4.0.1, which has 12 principal requirements — all future-dated requirements became mandatory on 31 March 2025. CPS 230 (Operational Risk Management) extends APRA requirements to material service providers, with pre-existing contracts required to comply by the earlier of their next renewal date or 1 July 2026.

Frameworks that apply
APRA CPS 234 — Information Security

Principles-based standard with 8 requirement areas. Applies to all APRA-regulated entities (~1,150 entities overseeing $9.8 trillion in assets).

PCI DSS v4.0.1

Applies to financial services entities that store, process, or transmit cardholder data. All future-dated v4.0.1 requirements became mandatory 31 March 2025.

Also in effect

A cascade of new obligations

Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.

APRA CPS 230 — Operational resilience

1 Jul 2025

Stress testing of critical functions including cyber-attack scenarios. Recovery time objectives must be validated. Board attestation on resilience required with testing evidence.

Cyber Security Act 2024

30 May 2025

Mandatory ransomware payment reporting within 72 hours for entities over $3M turnover. Financial services entities are prime targets. NodeZero identifies ransomware attack vectors before attackers exploit them.

Privacy Act statutory tort

10 Jun 2025

Private right of action for serious privacy invasions from June 2025. Financial services entities handling sensitive financial and health information face direct litigation risk. Enhanced OAIC enforcement powers with penalties up to $50M.

PCI DSS v4.0.1 — All requirements mandatory

31 Mar 2025

All 51 future-dated requirements became mandatory on 31 March 2025. Six-monthly segmentation testing for service providers (annual for merchants) and annual penetration testing now fully enforced.

Platform credentials

The only autonomous pentesting platform that is:

CPS 234 / 230
Control-by-control
APRA testing evidence
Essential Eight
Mapped ML1–3
ASD baseline
Gartner Peer Insights
4.7 / 5
Customers' Choice (Oct 2025)
310,332
Pentests run
7,013 orgs
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Prove your compliance posture before your next APRA assessment

See how NodeZero maps to CPS 234, CPS 230, and PCI DSS in your environment