A new report has revealed an alarming increase in the exposure of sensitive data in endpoint devices in the financial services sector, rising from 23 per cent in 2025 to 40 per cent in 2026.
The figures come from endpoint security firm Absolute and its recently published State of Cyber Resilience in Financial Services report, which polled 1,000 cyber security leaders across the US and UK.
“For a sector whose crown jewels are customer financial data, account credentials, payment-instrument data, and trade information, this represents both direct customer-harm risk and regulatory exposure spanning GDPR, CCPA, PCI DSS, and sector-specific obligations,” Absolute said in its report.
“An exposed endpoint isn’t a theoretical risk. It’s a loaded incident waiting for detonation.”
Despite that rise in data exposure, the research illustrates a growing intolerance for data breaches among boards, with 66 per cent of chief information security officers (CISOs) reporting a zero-tolerance attitude towards security breaches, something the report calls “an operationally impossible standard that creates a structural accountability gap”.
Because of this expectation, more than half of security leaders in the sector expect that a serious incident could not only cost them their job but also expose them to personal liability.
Unsurprisingly, the report found that CISOs in the sector were largely more concerned about cyber risks than their peers in other industries. Sixty per cent were worried about cyber attacks causing downtime, compared to 53 per cent in other sectors, while 62 per cent were worried about supply chain risks, compared to 57 per cent elsewhere.
The only area where financial services CISOs were less concerned than their colleagues in other sectors was regarding compliance violations following an incident. This was a top concern for 52 per cent of CISOs in the sector, compared to 56 per cent in other industries.
The impact of ransomware incidents is a key concern for many CISOs in the sector, with more than half rating downtime as their top concern, followed by the impact of regulatory penalties. However, the most significant concern involved the question of whether or not to give in to a ransom demand.
“Ransom-payment decisions in financial services carry unique consequences: sanctions-screening obligations, financial-crime reporting, and the legal ambiguity of payments to sanctioned actors. Despite this, 58 per cent of financial services CISOs say their organisation would consider paying to end an incident – virtually identical to the all-sector rate of 58 per cent,” the report said.
“Awareness of the regulatory environment doesn’t override the operational pressure of a live incident. The implication is clear: ransomware playbooks must include pre-cleared payment-decision frameworks before an incident, not during it.”
You can read the full report here.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.