Financial Services Data Exposure Doubles as Cyber Attack Recovery Costs Hit $2.4M
By Ali Paterson · 9 September 2026

Data exposure on financial services devices has surged to 40% over the last year, marking the sharpest increase of any industry. For fintech professionals, this represents a critical operational risk as recovery costs average $2.41 million per incident. The rise in exposure is compounded by widening gaps in software patching and mounting regulatory pressure.
What was announced
Absolute Security released "The State of Cyber Resilience in Financial Services" report, based on a survey of 1,000 security leaders across the United Kingdom and the United States. The findings highlight a dangerous trend: Windows 10 patching in the sector now lags by an average of 105 days, a significant 74-day increase compared to the previous year. This delay creates a massive window of opportunity for cybercriminals to exploit known vulnerabilities at a time when machine-speed attacks are becoming the norm.
The report notes that while 79% of Chief Information Security Officers (CISOs) in finance have a cyber resilience strategy in place—outpacing the 68% average across other sectors—significant internal and external pressures remain. Approximately 66% of boards expect their security teams to guarantee zero breaches, an impossible standard given the current threat landscape. Furthermore, while 96% of CISOs feel confident they can recover from a ransomware attack, only 41% have the capability to restore all devices remotely if a fleet-wide attack occurred tomorrow. This lack of remote recovery capability is a major factor in the high cost of downtime.
Regulatory penalties are now cited as the second-largest impact of a ransomware attack, trailing only operational downtime. This is driven by frameworks like the SEC’s cybersecurity-disclosure rules and the EU’s Digital Operational Resilience Act (DORA). Despite these risks and the potential for legal consequences, 58% of financial CISOs admitted they would consider paying a ransom to resolve an incident.
"Cybercriminals don’t care about defence strategies when they can easily access a weakly secured computer because it’s out of patch. Security leaders at finance firms are under huge pressure from the regulator, boards and customers to keep their data safe, and that’s only become trickier with the volume and scale of machine-speed attacks. Manual patching and recovery isn’t fast enough anymore."
Andy Ward, Senior Vice President & GM - International at Absolute Software.
The companies involved
Absolute Security, which has also operated under the name Absolute Software, is a specialist in endpoint resilience and self-healing security. The company provides visibility and control over devices, applications, and data, regardless of whether a device is on or off the corporate network. Its technology is designed to ensure that security agents remain healthy and effective, addressing the "drift" that often occurs when software fails or is disabled by malicious actors.
The report also references the regulatory environment shaped by the Securities and Exchange Commission (SEC). As the primary federal regulator of the U.S. securities markets, the SEC has increasingly focused on the transparency of cyber incidents, requiring public companies to disclose material breaches. Similarly, the European Union (EU) has introduced the Digital Operational Resilience Act (DORA), which mandates strict ICT risk-management requirements for financial entities operating within its jurisdiction. These bodies represent the tightening oversight that now defines the operational landscape for modern fintech firms and traditional banks alike, making cyber resilience a matter of legal compliance as much as technical defense.
What FF News has reported before
FF News has frequently covered the evolving regulatory and operational landscape overseen by the SEC. Recent reporting includes GigaStar Launches First SEC-Registered ATS for Creator Economy Digital Securities, highlighting how new platforms are navigating federal registration. We have also tracked the intersection of public policy and corporate governance in Corgi Insurance Appoints McArn Bennett to Lead Federal Public Policy and Corporate Affairs. Additionally, our coverage of market infrastructure includes LEIFRAS ADSs Set to Benefit from Nasdaq 23-Hour Extended Trading Schedule and 24X Completes First Crypto Spot Trade with Standard Chartered and Cumberland DRW, both of which underscore the increasing complexity and connectivity of the digital financial ecosystem.
What this means
The widening gap between board expectations and technical reality is reaching a breaking point in the financial sector. While boards demand "zero breaches," the 105-day patching lag suggests that the basic hygiene of financial IT infrastructure is actually deteriorating. This puts immense pressure on CISOs, who are caught between "machine-speed attacks" and rigid regulatory frameworks like DORA. The fact that over half of CISOs would still consider paying a ransom indicates that, despite the rhetoric of resilience, many firms still view their internal recovery capabilities as inadequate. The industry is moving toward a model where autonomous, self-healing systems are no longer a luxury but a necessity for survival in a high-stakes regulatory environment.
Companies in this story: Absolute Security, SEC, EU
People in this story: Andy Ward