This policy brief is based on ECB Working Paper No. 3222, “Disciplining Digital Risk: Evidence from Cyber Stress Tests.” The views expressed in this article are those of the authors and do not necessarily reflect those of the European Central Bank (ECB), the International Monetary Fund (IMF) or the Bank for International Settlements (BIS).
Abstract
Cybersecurity has become a central concern for financial stability. Because cyber resilience produces positive externalities across interconnected financial institutions, individual banks may underinvest in cybersecurity relative to the social optimum. We examine whether qualitative supervisory scrutiny, implemented without capital charges or public disclosure, can correct this distortion. Using confidential ECB supervisory data on 109 euro-area Significant Institutions over 2019–2024, we identify a subset of “laggard” banks that systematically underinvested in cybersecurity relative to their cyber-risk profile prior to the 2024 ECB Cyber Resilience Stress Test (CyRST) and exploit the March 2023 announcement as a quasi-natural experiment. In a difference-in-differences design, we find that laggard banks raised cybersecurity investment by approximately 81% relative to non-laggard peers following the announcement, with no detectable pre-trends. The response is concentrated among the most severe laggards and among those facing more intensive supervisory scrutiny, consistent with a scrutiny channel operating independently of capital or market-discipline channels. Beyond investment, laggard banks reduced external ICT dependencies, retained specialist cyber staff, and reconfigured cyber-insurance coverage. The findings suggest that targeted, non-capital-based supervisory scrutiny can discipline operational risk-taking in domains characterised by large externalities are large and where traditional regulatory tools are relatively blunt.
Cyber risk no longer sits in the tail of the distribution of operational risks that banks face. As ECB Supervisory Board member Anneli Tuominen recently observed, “risks we previously thought of as belonging to a ‘tail’ scenario have now become part of the baseline.” The number of cyber incidents reported by banks to the ECB rose sharply through 2024, while cybersecurity is now cited as the main concern of three-quarters of chief risk officers in global banking, with geopolitical tensions identified as a key driver. Banks rank second only to governments among the most frequent targets of state-sponsored cyberattacks worldwide. Supervisors have also warned that advances in artificial intelligence may further amplify cyber vulnerabilities by lowering the cost and sophistication threshold for large-scale attacks.1 Open digitalised financial systems have become attractive vectors for adversarial state and non-state actors precisely because banks sit at the centre of payments, deposits, and credit allocation. The Draghi report on European competitiveness underscores the structural backdrop: the EU relies heavily on non-EU providers for digital infrastructure and cloud services. In this environment, cybersecurity has ceased to be a back-office operational issue and has become a core financial stability concern (Draghi et al, 2024; Tuominen, 2026).
Cyber risk has moved decisively to the centre of the financial stability conversation. Incidents involving payment infrastructures, cloud providers, and individual banks have shown that operational disruptions propagate quickly across interconnected institutions and can, under certain conditions, trigger funding-market stress (Duffie and Younger, 2019; Eisenbach et al., 2022; Crosignani et al., 2023). Cyber risk differs from many traditional operational risks in one important respect: a vulnerability at one institution can become the entry point for disruptions affecting many institutions simultaneously.
This generates a classic public-good problem. Cybersecurity investment yields private operational benefits, but it also produces network externalities for the broader system. Because banks internalise only part of these system-wide benefits, the privately optimal level of investment remains below the socially optimal level (Kashyap and Wetherilt, 2019; Aldasoro et al., 2023; Anand et al., 2024).
Standard prudential tools, namely capital requirements and market disclosure, are poorly suited to address this distortion. Cyber resilience is hard to quantify, fast-moving, and not naturally mappable into risk-weighted assets. Disclosure raises its own concerns: revealing bank-level vulnerabilities can be counterproductive in a domain where adversaries actively probe for weaknesses. The question is therefore whether supervisory scrutiny itself, implemented without capital consequences and without disclosure, can shift bank behaviour. The ECB’s 2024 Cyber Resilience Stress Test (CyRST) was designed in a way that allows us to answer this question cleanly.
The CyRST is a novel supervisory exercise designed to assess banks’ ability to detect, respond to, and recover from a sophisticated cyberattack scenario. Its institutional design has three features that, taken together, make it well suited to identifying the scrutiny channel as distinct from other regulatory mechanisms:
The timeline (Figure 1) supports identification. The exercise was first publicly signalled on March 9, 2023, in a widely reported interview by the then Chair of the Supervisory Board, with the formal launch on January 3, 2024 and the high-level public summary on July 26, 2024. We use the March 2023 announcement as the treatment date and conservatively omit 2022 from the analysis to address anticipation concerns.
Figure 1. Timeline of the ECB 2024 Cyber Resilience Stress Test

A core challenge in this literature is that underinvestment is unobservable: a small bank with low cyber spending may be appropriately calibrated to its risk profile, while a large complex bank with the same nominal spending may be severely under-resourced. We therefore identify laggards through a two-step procedure, using only pre-treatment data (2020–2021): (I) We regress cybersecurity investment on a rich set of bank-specific characteristics (cyber-risk profile, operational complexity, governance, staffing, and financial fundamentals) and recover the residual for each bank; (II) We classify a bank as a laggard if its average residual over 2020–2021 falls below the sample median. The classification is fixed before the policy event and is not updated with post-treatment outcomes. This procedure has two important properties. First, it isolates investment behaviour that is unexplained by observable risk drivers, which is precisely the variation a supervisor would interpret as discretionary underinvestment (or a propensity to underinvest). Second, because the classification uses only pre-treatment data, it is immune to the “you defined treatment to find the result” critique: the laggard indicator cannot be a function of the post-2023 response we are trying to measure.
Pre-treatment, laggards and non-laggards are statistically indistinguishable on traditional financial dimensions (profitability, capitalisation, leverage) but differ specifically in cyber-related dimensions. This pattern suggests that the CyRST acted on banks with cyber-specific investment gaps rather than on financially distressed institutions.
Following the March 2023 announcement, cybersecurity investment rose by approximately 45% on average across the sector (before-after specification, PPML with bank fixed effects and time-varying controls). This sector-wide response is consistent with the CyRST acting as a coordinating signal that raised the salience of cyber resilience across SSM banks.
The cross-sectional response is highly heterogeneous. In the main difference-in-differences specification, laggard banks increased cybersecurity investment by approximately 81% relative to non-laggards. The event-study evidence (Figure 2) supports the identifying assumption: there are no detectable differential pre-trends prior to 2023, and the post-announcement increase is sharp, statistically significant, and persistent.
Figure 2. Event Study: Laggard × Year Effect on Cyber Investment

The effect is concentrated among the most severe laggards. When the classification is sharpened to compare the bottom quartile (Q1) of pre-treatment residuals with the top quartile (Q4), the differential response rises substantially; when comparing Q2 to Q3, it disappears. The CyRST did not nudge everyone proportionally; it produced a “catch-up” response concentrated among banks furthest from supervisory expectations.
If the response is driven by supervisory pressure rather than by other shocks coincident with the announcement, we should observe the effect concentrated among laggard banks that faced more intensive engagement during the exercise. We construct two confidential measures from the CyRST process (a severity-weighted score of supervisory findings, and a data-quality/plausibility flag indicator), and combine them into a composite high-scrutiny indicator.
The pattern is clear. Among laggards subject to high supervisory scrutiny, the post-CyRST investment response is large and statistically robust across specifications. Among laggards subject to low scrutiny, the response is economically smaller and statistically insignificant once fixed effects are included. The same pattern holds when scrutiny is proxied by high-severity findings specifically.
This provides the central mechanism evidence. Because the CyRST carried no capital penalties and produced no bank-level public disclosure, the response cannot plausibly be attributed to the capital channel or the market-discipline channel. The most parsimonious interpretation is a scrutiny channel: the credible prospect of detailed supervisory examination raises the expected cost of continued underinvestment, prompting banks to move closer to the supervisor’s expectations.
The CyRST is associated with broader changes in cyber-risk management beyond monetary outlays. Relative to non-laggards, laggard banks:
Laggards also reported fewer significant cyber incidents post-CyRST. While reporting incentives may have shifted in parallel, the magnitude is consistent with genuine improvements in detection, containment, or response.
(i) Supervisory scrutiny can discipline operational risk without capital or disclosure levers. The CyRST evidence is consistent with the broader argument that the threat of being looked at carefully by a supervisor is itself a regulatory instrument, particularly in domains, like cyber, where capital tools are blunt and disclosure is risk-laden. This complements Kok et al. (2023) on the supervisory scrutiny channel in traditional EU-wide stress tests.
(ii) Targeted designs work where uniform regulation does not. The effect is concentrated among banks that were furthest from supervisory expectations and faced the most intensive engagement. Uniform requirements would have imposed costs on already-compliant banks while under-disciplining laggards. The CyRST design implicitly targets the marginal underinvestor, which is a desirable property when supervisory capacity is scarce.
(iii) Stress testing extends beyond solvency. Traditional stress tests have focused on capital adequacy. The CyRST demonstrates that the stress-testing technology (scenario design, supervisor–bank dialogue, quality assurance) can be adapted to operational and technological risks. As digital dependencies deepen, this extension is likely to become increasingly important.
(iv) The framework may travel beyond banking. Energy grids, telecommunications, and payment infrastructures face structurally similar public-good problems in operational resilience. Whether targeted, non-capital-based supervisory exercises can produce comparable disciplining effects in those sectors is an open and policy-relevant question.
Cybersecurity in an interconnected banking system has the structural properties of a public good, and individual banks face incentives to underinvest. The 2024 ECB Cyber Resilience Stress Test offers a clean setting to ask whether qualitative supervisory scrutiny can shift this calculus. The evidence is consistent with such an effect: laggard banks raised cybersecurity investment, restructured outsourcing, retained specialist staff, and recalibrated insurance arrangements, and these adjustments are concentrated where supervisory engagement was most intense. The findings do not imply that capital regulation or disclosure are obsolete. They suggest, rather, that the supervisory toolkit is richer than the capital channel alone, and that targeted scrutiny can play a useful role in domains where traditional levers are ill-suited. For the Eurosystem and for supervisors elsewhere, the practical question is no longer whether to extend stress-testing to operational resilience, but how to design such exercises so that the scrutiny channel operates effectively. The findings reported here also speak to a broader supervisory question: how to discipline operational risks that are fast-moving, difficult to quantify, and poorly suited to traditional prudential tools. Capital requirements, calibrated primarily for credit and market risk, may be less effective in the cyber domain, while public disclosure can itself generate vulnerabilities. The evidence from the CyRST instead suggests that credible and targeted supervisory scrutiny can influence bank behaviour even in the absence of capital sanctions or public disclosure of institution-specific results. More broadly, the findings point to an expanded role for operational resilience exercises within the supervisory toolkit, particularly where risks are difficult to model ex ante but supervisory engagement can still shape incentives and preparedness.
Acharya, V., Berger, A., Roman, R. (2018). Lending implications of US bank stress tests: Costs or benefits?
Ahnert, T., Brolley, M., Cimon, D., Riordan, R. (2024). Cyber risk and security investment.
Aldasoro, I., Gambacorta, L., Giudici, P., Leach, T. (2023). Operational and cyber risks in the financial sector.
Anand, K., Duley, C., Gai, P. (2024). Cybersecurity and financial stability.
Crosignani, M., Macchiavelli, M., Silva, A.F. (2023). Pirates without borders: The propagation of cyberattacks through firms’ supply chains.
Draghi, M. (2024). The Future of European Competitiveness. European Commission.
Duffie, D., Younger, J. (2019). Cyber runs.
Eisenbach, T., Kovner, A., Lee, M. (2022). Cyber risk and the U.S. financial system.
European Union Agency for Cybersecurity (ENISA) (2025). ENISA Threat Landscape: Finance Sector.
Goldstein, I., Leitner, Y. (2018). Stress tests and information disclosure.
Kashyap, A., Wetherilt, A. (2019). Some principles for regulating cyber risk.
Kok, C., Müller, C., Ongena, S., Pancaro, C. (2023). The disciplining effect of supervisory scrutiny in the EU-wide stress test.
Tuominen, A. (2025). “Improving banks’ resilience to hybrid threats,” speech at the conference The Current Hybrid Threat Environment and Financial Stability, Frankfurt, 18 November.
Tuominen, A. (2026). “Upgrading banks’ capacity to deal with digital risks,” contribution to Eurofi Magazine, Frankfurt, 24 March.
Reuters (2026), “ECB’s Elderson urges euro area banks to quickly prepare for ‘MYTHOS’,” 13 May.
Supervisors have also warned that advances in artificial intelligence may further amplify cyber vulnerabilities by lowering the cost and sophistication threshold for large-scale attacks. See Reuters (2026) for a discussion of ECB supervisory concerns regarding AI-assisted cyberattacks and operational resilience.