Cyber risks in the financial sector
The digitization of the industry is advancing rapidly and threats are constantly evolving: complex threats must be countered with an equally complex and continuous security model.
„Fear of cyberattacks is growing in the financial sector" – this was the recent headline in the Handelsblatt newspaper. And with good reason: the "money" sector is one of the most vulnerable worldwide among the industries most affected by cyberattacks, penetration testing is at the heart of the defense tactics employed by banks and financial service providers.
Threat level: Red alert
Between January 2023 and June 2024, the European Union Agency for Cybersecurity recorded 488 cyberattacks on the financial sector. In 46 percent of cases, credit institutions were affected. A wide variety of surveys and reports provide similarly alarming data on the growing cyber threat in the financial world. According to the European Central Bank, cyber incidents reported by major banks doubled between 2022 and 2024, and a Statista survey conducted this year found that 80 percent of banks and insurers in German-speaking countries had been the target of at least one cyberattack in the last two years. For 2030, 64 percent of the companies surveyed even consider cyberattacks to be the biggest general challenge for the financial sector, ahead of digitalization and deterioration in credit quality.
Behind these figures lie specific, highly effective attack scenarios: ransomware attacks on core banking systems or critical service providers, crypto theft from wallet or custody solutions, targeted manipulation of payment processes, for example in the SWIFT environment, or credential and identity attacks on user accounts. For banks, it is not only crucial whether an attack is fundamentally possible, but also how quickly it can be detected and contained. Key figures such as mean time to detect (MTTD) and mean time to respond (MTTR) are central risk factors for realistically assessing the actual damage potential of an attack. This is because long detection or response times can quickly turn a limited security incident into an event that threatens the very existence of a company.
Defense: comprehensive penetration testing
Penetration testing involves identifying and exploiting vulnerabilities in a system in order to assess its security. Essentially, it involves thinking like an attacker in order to simulate real cyberattacks on IT infrastructures, applications, or cloud environments before their vulnerabilities are exploited.
Highly networked systems and the complex web of financial institutions, third-party providers, and customers themselves offer banks and financial service providers more than enough targets for attack, and the cross-industry trend toward the use of software-based penetration tests must be viewed in a particularly nuanced way for this sector. The risk analysis of 13 technologies relevant to the financial sector in a recent report by the German Federal Office for Information Security (BSI) is eye-opening here – and illustrates why regulatory authorities worldwide are turning to intelligent penetration testing that combines human expertise with automation. These requirements are reflected in regulations such as TIBER-EU, BAIT, MaRisk, DORA, the EBA Guidelines, and ISO/IEC 27001, which address not only technical vulnerabilities but also processes and detection and response capabilities.
Limitations of software-based penetration testing
A selective or even automated testing strategy is no longer sufficient. This is because software-based penetration tests such as SAST/DAST tools (automated vulnerability scanners) can only check systems at a specific point in time and cannot fully reflect the current threat situation. The IT landscape in banks is too dynamic for this.
Their scope of testing is also limited. Although they can identify standard vulnerabilities quickly and repetitively, they fail when it comes to complex attack vectors, configuration problems in cloud setups, and supply chain risks. API-based attacks in particular—such as the misuse of authentication or authorization logic—are only detected to a very limited extent by scanners.
Modern threats such as AI-assisted phishing, MFA fatigue attacks, token theft, or cloud IAM misconfigurations also elude purely automated analysis. The example of a typical attack path that a scanner would not detect illustrates the problem: An attacker compromises a user account via AI phishing, deliberately provokes MFA fatigue, gains access to a cloud portal, uses a misconfigured IAM role there to escalate privileges, and then accesses sensitive payment or customer data via internal APIs. The individual components may be uncritical in isolation. However, their combination is highly dangerous.
Another key shortcoming of software-based tools is that they cannot check whether an attack would be detected by security monitoring and effectively handled by the incident response team. But it is precisely this capability that is crucial for the operational cyber resilience of a financial institution.
Instead: Focus on threat-oriented testing
Modern penetration testing models focus on threat-oriented or threat intelligence-based testing, which maps real attack TTPs (tactics, techniques, procedures). This requires human control and assessment skills.
In "threat-led red teaming," experts acting as "ethical hackers" simulate targeted cyberattacks on systems, processes, and employees under realistic conditions. This enables a robust assessment of the defense capabilities of banks and financial service providers, reveals undetected attack paths, and strengthens cybersecurity strategy through prioritized, actionable measures. In "purple teaming," attackers (red team) and defenders (blue team) work together in real time to measurably improve detection and response capabilities in particular.
Practical consequences for financial institutions
Software-based penetration tests have their place, but they must be embedded in an intelligent, risk-based, and continuous testing program. Automated tools enable efficient routine checks. However, regular threat-oriented tests are essential for critical, customer- or system-relevant functions. This is the only way to build sustainable cyber resilience—technically, organizationally, and regulatorily resilient.


