FF News Logo
Sunday, October 05, 2025
ITC Vegas

Information Security including cyber is number one operational risk concern in Financial Services, says ORX

Information Security (including Cyber), has topped a league table of operational risk concerns for global banks and insurers. Followed by Third Party risk and Technology, all three top risks reflect continuing digital transformation in financial institutions, which is heavily impacting these scores. Information security has topped the survey for the last four years, but this year indications are that it is now being managed more effectively.

The findings were published in a report from ORX, the world’s largest operational risk association who work with over 125 banks and insurers globally.

According to the report – Top Risk Review June 2023 – Information Security risk, driven by cyber threats, continues to challenge the industry. Events have shown that it only takes one successful attempt to potentially disrupt an entire organisation and cause widespread financial and reputational damage. However, the good news is that 87% of participants said their organisation is managing the risk effectively and are continuously investing in cybersecurity controls and capabilities.

This year’s report results also reflect the explosive rise of generative AI, bringing artificial intelligence to the forefront of agendas. Opportunities include improved decision-making and process optimisation but conversely, AI and generative AI have the potential to adversely impact a wide range of risk types, notably Information Security (incl. Cyber), Data Management, Technology, Model, Transaction Processing & Execution, Regulatory Compliance and Conduct risk.

Luke Carrivick, ORX’s Executive Director explains:

“I’m not surprised that information security remains the top concern for our members, as digitalisation permeates all areas of operational functions. What is encouraging is the increased confidence in managing and mitigating these risks as they arise and reflects the industry’s improving handle on tackling cyber and other digital threats. Stability is also reflected by 60% of respondents expecting their scores to stay the same in the next six months.

“The prevalence of AI is definitely one to watch and we’ll be spotlighting this in the coming months in our Cyber-specific service as a key area of focus for operational risk.”

Third Party risk ranks in second place as oversight challenges continue. With third party arrangements becoming increasingly instrumental in critical business services, supplier risk management is a priority and if not monitored or managed effectively, could lead to significant vulnerabilities.

  Top Risk Review (Nov 2021) Top Risk Review (May 2022) Top Risk Review (Nov 2022) Top Risk Review 

(June 2023)

1st Information Security (including Cyber) Information Security (including Cyber) Information Security (including Cyber) Information Security (including Cyber)
2nd Technology Third Party Third Party Third Party
3rd Third Party Technology Technology  

Technology

4th Regulatory Compliance Data Management Data Management Data Management
5th External Fraud  People People Regulatory Compliance

Figure 1: The top five ranked risks from the last four Top Risk Review surveys 

Responses also suggest that skills shortages and retention challenges persist, but with a sharp drop from 5th to 11th position, people risk concerns may be starting to ease. Moving from 11th to 6th position since the last review, External Fraud has seen the greatest upward movement of all 16 risks. While availability of advanced technology may be acting as a common enabler, difficult economic conditions were listed as a key driver.

Luke Carrivick adds:

“Benchmarking is an area that our members have been asking for as part of their risk measurement initiatives, and so for the first time since launching the Top Risk Review, participants will receive a personal benchmark highlighting how their responses compare to the industry’s. We can now include average vs individual scores and insights on how their scores compared to the rest of the participant group.”

Top Risk Review June 2023 | ORX

People In This Post

Companies In This Post

  1. The European Central Bank Selects Almaviva and Fabrick for Digital Euro Project Read more
  2. EXCLUSIVE: “The Advantage of Ancient Errors” – Tony Fish in ‘Discover Sibos 2025’ Read more
  3. EXCLUSIVE: “Game Changer” – Andy Lyons, Freemarket in ‘The Fintech Magazine’ Read more
  4. Binance Launches The Blockchain 100 Award to Honor Top Creators Driving Blockchain Innovation Read more
  5. MAPFRE AM Appoints Ismael García Puente as the New Deputy Director of Investment Strategy Read more
Gitex Global