
Sector
Financial Services & Insurance
Banks, insurers and payment service providers form part of critical infrastructure (KRITIS) and are subject to one of the highest regulatory densities of any sector. The Digital Operational Resilience Act (DORA), applicable since January 2025, establishes a directly applicable EU framework for digital operational resilience — covering risk management, incident reporting, resilience testing and oversight of critical third-party ICT service providers. DORA, NIS2 and physical resilience are integrated into a coherent security architecture.
Overview
A Sector in Transition
The financial sector is the most densely regulated industry and simultaneously one of the preferred targets of threat actors. In Germany, the Federal Financial Supervisory Authority (BaFin) supervises approximately 9,400 entities — credit institutions, securities and asset management companies, payment and e-money institutions, and more than 200 primary insurers.[1] According to International Monetary Fund data, nearly one fifth of all global cyber incidents over the past twenty years affected the financial sector, with aggregate losses of approximately 12 billion US dollars.[2]
The more significant shift of recent years, however, lies not in the attacks themselves but in external dependency. Banks and insurers have largely ceased to operate their own IT. According to ECB banking supervision data, European institutions concentrate half of their outsourcing budget on just 30 providers; 82 per cent of outsourced critical functions are difficult or impossible to substitute.[3] In Germany, more than half of reporting-obligated entities state that they could no longer deliver their outsourced IT services in-house — and more than two thirds of those would find it virtually impossible to switch provider.[4] The sector's greatest operational risk has thus migrated externally, to a small number of cloud and IT providers whose failure can affect many institutions simultaneously.
The Threat Landscape
Documented incidents follow clearly recognisable patterns. The first is the supply chain. In May 2023, the group Cl0p exploited a zero-day vulnerability in the file-transfer software MOVEit; via the account-switching service provider Majorel, customers of Deutscher Bank, Postbank, ING and Comdirect were also affected — at German banks alone, this amounted to more than 144,000 records exfiltrated, while the banks' own systems were not directly compromised.[5] The same mechanism was evident in the attack on the British outsourcing provider Capita in March 2023: approximately 6.6 million personal data records were exfiltrated, the annual loss exceeded 106 million pounds, and in October 2025 the UK data protection authority imposed fines totalling 14 million pounds.[6] BaFin estimates that approximately two thirds of payment incident reports are attributable to third-party service providers.[7]
The second pattern is ransomware with systemic impact. In November 2023, LockBit struck the US subsidiary of the world's largest bank, ICBC, via an unpatched Citrix vulnerability. The consequence was not a data breach but a standstill in the engine room of the financial system: ICBC was unable to settle US Treasury transactions, settlement data was temporarily transported across Manhattan by USB drive and courier, and failed repo transactions reached 62.2 billion US dollars.[8] The IMF and rating agencies assessed the incident as one of the most severe cyber attacks on the financial industry to that point.
The third pattern is availability attacks and operational outages. Pro-Russian groups such as Killnet and NoName057(16) targeted German banks and authorities with DDoS attacks from January 2023 onwards under campaign names such as #GermanyRIP; according to ENISA data, 58 per cent of all DDoS incidents in the European financial space were directed at credit institutions.[9] Such attacks typically disrupt web presences and online banking only briefly, yet they consume resources and erode confidence. The faulty CrowdStrike update of July 2024 demonstrated that an outage requires no attacker at all: bank branches and payment services in multiple countries came to a standstill, losses for the banking sector alone are estimated at approximately 1.15 billion US dollars, and the Bundesbank explicitly cited the case as an example of third-party ICT and concentration risk.[10] Finally, there is the self-inflicted variant: the IT migration of 12 million Postbank customers to Deutsche Bank's systems caused severe disruptions in 2023 — some customers were unable to access their accounts for weeks. In September 2023, BaFin cited substantial impairments and appointed a special commissioner, an exceptional supervisory measure.[11]
The Regulatory Drivers
The overarching framework for all of this has been the Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, applicable since January 2025. As an EU regulation it applies directly, without national implementing legislation, and covers 21 categories of financial entities — from credit institutions through payment and crypto-asset services to insurers and occupational pension schemes. For the first time, third-party ICT service providers are directly subject to regulation.[12] DORA rests on five pillars: ICT risk management with ultimate accountability vested in the management body, structured incident reporting, regular resilience testing, third-party risk management, and a dedicated oversight framework for critical providers.[13]
Three areas warrant particular attention. Major incidents must be reported in stages: an initial notification within a matter of hours, an interim report within 72 hours, and a final report after one month, submitted in Germany to BaFin as the reporting hub.[14] For significant institutions, threat-led penetration testing (TLPT) based on the TIBER-EU framework is additionally required, with the first cycle to be completed by January 2028.[15] The greatest lever lies in the direct oversight of critical third-party ICT service providers: in November 2025, the European Supervisory Authorities designated the first 19 critical providers, including the major cloud hyperscalers, Deutsche Telekom, and data centre operators Equinix and Interxion. These providers may be subject to penalty payments of up to one per cent of average global daily turnover — applied on a daily basis for up to six months.[16]
DORA fits clearly within the broader regulatory framework. In the financial sector it operates as lex specialis relative to NIS2, exceeds the general directive in substantive scope, and has superseded the earlier BaFin circulars BAIT, VAIT, KAIT and ZAIT as the guiding framework.[17] The physical dimension is addressed by the KRITIS umbrella act, in force since March 2026: it governs the physical resilience of critical infrastructure (KRITIS) facilities, exempts the financial sector from certain core obligations on account of DORA, but retains the reporting requirement for physical disruptions.[18] Overarching all of this is a shift in accountability: both DORA and the umbrella act address senior management personally — operational resilience has thereby become a board-level responsibility rather than a purely technical matter.
Where the Critical Risks Lie
The most challenging risks rarely reside within a single domain. They arise at the interfaces — where cybersecurity, outsourcing, physical security and ongoing operations converge and are in practice frequently managed in separate accountability silos. In the financial sector, the greatest leverage lies in third-party and concentration risk. The consolidation of dependencies on a small number of cloud, IT and infrastructure providers generates efficiency alongside systemic vulnerability: MOVEit demonstrated that a single compromised provider can affect hundreds of institutions simultaneously; CrowdStrike showed that a single error propagates globally. This is precisely where DORA intervenes, through contractual requirements, exit strategies and concentration analyses — yet translating these into a sustainable security architecture remains the responsibility of each institution.
Closely related is the availability of critical functions, above all payment services. Systems such as SEPA, TARGET2 and SWIFT are systemically critical; the ICBC incident illustrated how rapidly the failure of a settlement chain propagates to the market. Additional risks extend beyond IT itself: the physical resilience of the data centres on which the sector depends falls outside DORA's scope and must be addressed separately within the resilience framework — it is no coincidence that data centre operators Equinix and Interxion appear on the list of critical providers. On the horizon stands quantum computing: with regard to "Harvest Now, Decrypt Later" — data captured today and decrypted at a later stage — BaFin has warned of the threat to current encryption methods and points to the first post-quantum standards. Technically, the countermeasure across all of these risks is Defence in Depth: layered, mutually independent protective controls following the onion-shell principle, consistent network segmentation, and the Zero Trust paradigm — no automatic trust extension, whether for users, connections or service providers. Standards such as ISO/IEC 27001 establish the professional framework and serve as a baseline; they give concrete form to what DORA requires, but do not substitute for the security architecture that holds cyber, outsourcing and physical security together.
Sources
[1] BaFin: ~9,432 supervised entities, >200 primary insurers (2025) — BaFin Risiken im Fokus 2025
[2] IMF: ~1/5 of all global cyber incidents over the past 20 years in the financial sector, losses ~12 bn USD — BaFin Risiken aus Cyber-Vorfällen 2025
[3] ECB banking supervision: 50% of outsourcing budget concentrated on 30 providers, 82% of critical functions difficult/impossible to substitute (Feb. 2025) — ECB Banking Supervision
[4] BaFin: >50% cannot deliver outsourced IT in-house, >2/3 of those find switching provider virtually impossible — BaFin Risiken im Fokus 2025
[5] MOVEit/Cl0p (May 2023): Deutsche Bank, Postbank, ING, Comdirect affected via Majorel, >144,000 records at German banks — S&P Global Ratings · Anwalt-Leverkusen.de
[6] Capita Ransomware (March 2023): ~6.6 million records, annual loss >£106.6 million, ICO fines £14 million (Oct. 2025) — The Record · Wikipedia
[7] BaFin: ~2/3 of payment incident reports attributable to service providers — BaFin Risiken aus Cyber-Vorfällen 2025
[8] ICBC LockBit (Nov. 2023): CitrixBleed vulnerability, US Treasury settlement disrupted, failed repo trades 62.2 bn USD, USB-drive transmission — Reuters · BankInfoSecurity
[9] Killnet/NoName057(16) DDoS #GermanyRIP (from Jan. 2023); ENISA: 58% of all DDoS incidents targeting credit institutions — BSI Ukraine-Krise · ENISA Finance Threat Landscape 2024 (PDF)
[10] CrowdStrike (July 2024): global IT outage, banking sector losses ~1.15 bn USD, Bundesbank: cited as example of third-party ICT/concentration risk — OrboGraph · Bundesbank Monatsbericht Sept. 2024
[11] Postbank IT migration (2023): 12 million customers, weeks-long disruptions, BaFin consumer notice Sept. 2023 + special commissioner — BaFin Verbrauchermitteilung · BaFin Sonderbeauftragter
[12] DORA Regulation (EU) 2022/2554, applicable from 17 January 2025, 21 categories of financial entities, third-party ICT service providers directly regulated — EUR-Lex
[13] The five pillars of DORA (risk management, incident reporting, resilience testing, third-party risk, oversight framework) — AWARE7 DORA-Leitfaden
[14] DORA reporting deadlines: initial notification 4h/24h, interim report 72h, final report 1 month, BaFin as reporting hub — BaFin Risiken aus Cyber-Vorfällen 2025
[15] DORA TLPT (Art. 26–27) based on TIBER-EU, first cycle to be completed by 17 January 2028 — DORA Regulation Blog (TLPT)
[16] ESAs designate 19 critical third-party ICT service providers (18 November 2025): including AWS, Microsoft, Google, IBM, Oracle, Deutsche Telekom, Equinix, Interxion; penalty payments up to 1% of global daily turnover — EIOPA · BaFin Überwachungsrahmen
[17] DORA as lex specialis relative to NIS2; superseding BAIT/VAIT/KAIT/ZAIT — USD AG DORA-News · openkritis.de
[18] KRITIS umbrella act (in force March 2026): physical resilience, financial sector partially exempted under §4(2), reporting obligation §12 retained; management accountability — BBK · openkritis.de

