Site icon Finance Derivative

RETHINKING RESILIENCE IN THE AGE OF INDUSTRIALISED CYBERCRIME

Cyber security and personal data protection are concepts. In search of innovative technology. Biometrics for Facial Recognition Recognition of faces.

By Ashley Crawford, Senior Risk Solutions Executive at SAS. 

Financial crime is in a new phase. What was once dominated by individual fraudsters and opportunistic cyberattacks has evolved into a sophisticated criminal ecosystem. Across financial services, we’re seeing organised networks, commercialised tools and geopolitical pressures combine to create a more complex and rapidly evolving threat landscape.

This represents more than an increase in cyber risk. It is a structural shift in how threats emerge, scale and adapt. Criminal organisations are operating with levels of coordination and specialisation that increasingly resemble legitimate enterprises, creating new challenges for banks, payment providers and insurers responsible for protecting customers, maintaining operational resilience and preserving trust.

Recent research from IBM showed the global average cost of a data breach reached around $5 million, highlighting the significant financial impact that cyber incidents can have on organisations. But, the consequences extend well beyond the immediate cost of an attack, affecting customer confidence, regulatory obligations, operational continuity and long-term resilience.

The changing nature of cybercrime can be seen across industries. Attacks affecting major organisations, like Jaguar Land Rover and Marks & Spencer in 2025, demonstrate how coordinated cybercriminal groups are increasingly able to disrupt operations, compromise sensitive information and exploit weaknesses across interconnected supply chains. 

For financial services, these incidents provide a clear warning: the same tactics and vulnerabilities can be used against banks, payment providers and the wider financial ecosystem.

The industrialisation of financial crime

One of the defining characteristics of today’s threat landscape is the emergence of highly organised criminal operating models. Increasingly, security researchers have identified collaborative environments often referred to as “hacker houses”, where specialist actors share infrastructure, exchange intelligence and coordinate attacks at speed.

Rather than relying on individual expertise, these groups divide responsibilities across reconnaissance, social engineering, malware development, credential theft and monetisation. They continuously refine their methods, learning from both successful and unsuccessful attacks and rapidly sharing those lessons across criminal networks.

We’re seeing these collaborative models enable criminals to innovate faster than ever before, making attacks increasingly difficult to predict using traditional approaches. The ability to share tools, intelligence and successful tactics allows criminal groups to operate with a level of agility that mirrors legitimate technology-driven organisations.

This industrialisation enables attacks to be launched with greater speed, precision and scale than many traditional security and fraud controls were designed to handle.

The rise of cybercrime as a business model 

Cybercrime has also become increasingly commercialised. We’re seeing Crime-as-a-Service (CaaS) marketplaces allowing less sophisticated actors to purchase or rent advanced attack capabilities, lowering the barrier to entry while dramatically expanding the number of potential attackers. 

Artificial intelligence is further accelerating this trend, enabling criminals to automate reconnaissance, enhance phishing campaigns and improve the speed with which attacks can be adapted.

Geopolitical tensions add another dimension. State-sponsored actors and financially motivated criminal groups are increasingly operating in parallel, creating a more complex environment where attacks may be driven by financial gain, strategic disruption or both.

From what we’re seeing across the market, Chief Risk Officers are having to balance traditional fraud prevention with a much broader focus on cyber resilience, operational continuity and enterprise-wide risk. The challenge is no longer simply preventing fraud; it is building an organisation capable of adapting to threats that continuously evolve.

Why legacy approaches are struggling

Many financial institutions continue to rely on fragmented risk controls built around deterministic rules and separate fraud and cybersecurity functions. While these approaches remain valuable, they were designed for a threat environment where attacks evolved relatively slowly.

In our experience, we often see fraud, cybersecurity and operational risk managed through separate processes and technologies. While each function may be highly effective in its own right, disconnected data and decision-making can make it harder to identify coordinated threats that cut across the organisation.

Today’s adversaries operate differently. 

Criminal groups iterate rapidly, adjusting tactics in response to defensive measures and exploiting the inevitable delay between a new attack emerging and rules being updated. A phishing campaign that proves ineffective can be modified within minutes. A successful attack against one organisation quickly becomes intelligence that can be reused across many others.

This creates an asymmetry that challenges traditional approaches. Static controls, siloed monitoring and reactive rule updates struggle to keep pace with adversaries that continuously adapt.

We’re increasingly seeing criminal groups move faster than organisations can update static rules, creating opportunities to exploit gaps before traditional controls respond.

The issue is not simply speed. Fraud, cybersecurity, payments risk and operational resilience are often managed independently, despite increasingly sharing common indicators and attack vectors. Without a connected view of enterprise risk, organisations may miss patterns that only become visible when data is brought together across multiple functions.

Building an intelligence-led risk capability

As financial crime becomes more industrialised, the response must evolve accordingly.

What we’re seeing from leading financial institutions is a shift towards combining data from across the organisation, analysing activity in real time and making consistent, explainable decisions at scale. This means moving beyond isolated controls towards an integrated risk architecture that connects fraud prevention, cybersecurity, anti-money laundering, payments monitoring and operational resilience.

Behavioural analytics and machine learning play an important role by identifying subtle anomalies that traditional rules may overlook, such as unusual payment behaviour, anomalous customer interactions or coordinated bot activity across multiple channels. Rather than replacing human expertise, these technologies help risk teams prioritise investigations and respond more quickly to emerging threats.

Modern risk platforms enable organisations to bring together data, analytics and decisioning capabilities, helping teams identify emerging patterns earlier and respond at the speed required by today’s threat landscape.

We’re also seeing governance become a much greater priority. As organisations increasingly rely on AI and advanced analytics, robust oversight becomes essential. Strong model governance, including disciplined ModelOps practices, helps ensure analytical models remain accurate, transparent and compliant throughout their lifecycle, reducing model drift while supporting evolving regulatory expectations.

For financial institutions, trust depends not only on making accurate decisions, but on making decisions that are consistent, auditable and well governed. 

Resilience as a strategic capability

As financial crime continues to evolve, resilience must become a strategic capability rather than a technical function. By connecting data, analytics and decision-making across fraud, cybersecurity and operational risk, institutions can move from reactive defence to proactive risk management. 

The future of financial crime prevention will belong to organisations that can adapt as quickly as the threats they face – combining intelligence, technology and governance to protect customers and maintain trust. 

Exit mobile version