menu
close

Author(s):

Nordine Abidi | International Monetary Fund (IMF)
Leonardo Gambacorta | Bank for International Settlements (BIS)
Christoffer Kok | European Central Bank (ECB)
Leonardo Madio | University of Padua
Ixart Miquel-Flores | European Central Bank (ECB)
Alberto Partida | European Central Bank (ECB)

Keywords:

Cyber risk , bank supervision , stress tests , operational resilience , cybersecurity investment

JEL Codes:

G21 , G28 , G32 , L86 , K23

This policy brief is based on ECB Working Paper No. 3222, “Disciplining Digital Risk: Evidence from Cyber Stress Tests.” The views expressed in this article are those of the authors and do not necessarily reflect those of the European Central Bank (ECB), the International Monetary Fund (IMF) or the Bank for International Settlements (BIS).

 

Abstract

Cybersecurity has become a central concern for financial stability. Because cyber resilience produces positive externalities across interconnected financial institutions, individual banks may underinvest in cybersecurity relative to the social optimum. We examine whether qualitative supervisory scrutiny, implemented without capital charges or public disclosure, can correct this distortion. Using confidential ECB supervisory data on 109 euro-area Significant Institutions over 2019–2024, we identify a subset of “laggard” banks that systematically underinvested in cybersecurity relative to their cyber-risk profile prior to the 2024 ECB Cyber Resilience Stress Test (CyRST) and exploit the March 2023 announcement as a quasi-natural experiment. In a difference-in-differences design, we find that laggard banks raised cybersecurity investment by approximately 81% relative to non-laggard peers following the announcement, with no detectable pre-trends. The response is concentrated among the most severe laggards and among those facing more intensive supervisory scrutiny, consistent with a scrutiny channel operating independently of capital or market-discipline channels. Beyond investment, laggard banks reduced external ICT dependencies, retained specialist cyber staff, and reconfigured cyber-insurance coverage. The findings suggest that targeted, non-capital-based supervisory scrutiny can discipline operational risk-taking in domains characterised by large externalities are large and where traditional regulatory tools are relatively blunt.

Why Cyber Risk Calls for a Distinct Regulatory Logic

Cyber risk no longer sits in the tail of the distribution of operational risks that banks face. As ECB Supervisory Board member Anneli Tuominen recently observed, “risks we previously thought of as belonging to a ‘tail’ scenario have now become part of the baseline.” The number of cyber incidents reported by banks to the ECB rose sharply through 2024, while cybersecurity is now cited as the main concern of three-quarters of chief risk officers in global banking, with geopolitical tensions identified as a key driver. Banks rank second only to governments among the most frequent targets of state-sponsored cyberattacks worldwide. Supervisors have also warned that advances in artificial intelligence may further amplify cyber vulnerabilities by lowering the cost and sophistication threshold for large-scale attacks.1 Open digitalised financial systems have become attractive vectors for adversarial state and non-state actors precisely because banks sit at the centre of payments, deposits, and credit allocation. The Draghi report on European competitiveness underscores the structural backdrop: the EU relies heavily on non-EU providers for digital infrastructure and cloud services. In this environment, cybersecurity has ceased to be a back-office operational issue and has become a core financial stability concern (Draghi et al, 2024; Tuominen, 2026).

Cyber risk has moved decisively to the centre of the financial stability conversation. Incidents involving payment infrastructures, cloud providers, and individual banks have shown that operational disruptions propagate quickly across interconnected institutions and can, under certain conditions, trigger funding-market stress (Duffie and Younger, 2019; Eisenbach et al., 2022; Crosignani et al., 2023). Cyber risk differs from many traditional operational risks in one important respect: a vulnerability at one institution can become the entry point for disruptions affecting many institutions simultaneously.

This generates a classic public-good problem. Cybersecurity investment yields private operational benefits, but it also produces network externalities for the broader system. Because banks internalise only part of these system-wide benefits, the privately optimal level of investment remains below the socially optimal level (Kashyap and Wetherilt, 2019; Aldasoro et al., 2023; Anand et al., 2024).

Standard prudential tools, namely capital requirements and market disclosure, are poorly suited to address this distortion. Cyber resilience is hard to quantify, fast-moving, and not naturally mappable into risk-weighted assets. Disclosure raises its own concerns: revealing bank-level vulnerabilities can be counterproductive in a domain where adversaries actively probe for weaknesses. The question is therefore whether supervisory scrutiny itself, implemented without capital consequences and without disclosure, can shift bank behaviour. The ECB’s 2024 Cyber Resilience Stress Test (CyRST) was designed in a way that allows us to answer this question cleanly.

The ECB Cyber Resilience Stress Test as a Quasi-Natural Experiment

The CyRST is a novel supervisory exercise designed to assess banks’ ability to detect, respond to, and recover from a sophisticated cyberattack scenario. Its institutional design has three features that, taken together, make it well suited to identifying the scrutiny channel as distinct from other regulatory mechanisms:

  1. No direct capital consequences. The exercise was not mechanically linked to Pillar 2 capital requirements, isolating the analysis from the capital channel that typically confounds studies of stress-test effects (Acharya et al., 2018; Gropp et al., 2019).
  2. No bank-level public disclosure. Only aggregate findings were published in July 2024, thereby muting the market-discipline channel that operates through investor reaction (Goldstein and Leitner, 2018).
  3. Qualitative supervisory engagement. The exercise relied on on-site assessments, recovery simulations, and granular supervisory interactions with each of the 109 Significant Institutions supervised by the ECB.

The timeline (Figure 1) supports identification. The exercise was first publicly signalled on March 9, 2023, in a widely reported interview by the then Chair of the Supervisory Board, with the formal launch on January 3, 2024 and the high-level public summary on July 26, 2024. We use the March 2023 announcement as the treatment date and conservatively omit 2022 from the analysis to address anticipation concerns.

Figure 1. Timeline of the ECB 2024 Cyber Resilience Stress Test

Identifying Cybersecurity “Laggards”

A core challenge in this literature is that underinvestment is unobservable: a small bank with low cyber spending may be appropriately calibrated to its risk profile, while a large complex bank with the same nominal spending may be severely under-resourced. We therefore identify laggards through a two-step procedure, using only pre-treatment data (2020–2021): (I) We regress cybersecurity investment on a rich set of bank-specific characteristics (cyber-risk profile, operational complexity, governance, staffing, and financial fundamentals) and recover the residual for each bank; (II) We classify a bank as a laggard if its average residual over 2020–2021 falls below the sample median. The classification is fixed before the policy event and is not updated with post-treatment outcomes. This procedure has two important properties. First, it isolates investment behaviour that is unexplained by observable risk drivers, which is precisely the variation a supervisor would interpret as discretionary underinvestment (or a propensity to underinvest). Second, because the classification uses only pre-treatment data, it is immune to the “you defined treatment to find the result” critique: the laggard indicator cannot be a function of the post-2023 response we are trying to measure.

Pre-treatment, laggards and non-laggards are statistically indistinguishable on traditional financial dimensions (profitability, capitalisation, leverage) but differ specifically in cyber-related dimensions. This pattern suggests that the CyRST acted on banks with cyber-specific investment gaps rather than on financially distressed institutions.

Cyber Stress Tests Raised Cybersecurity Investment, Especially Among Laggards

Following the March 2023 announcement, cybersecurity investment rose by approximately 45% on average across the sector (before-after specification, PPML with bank fixed effects and time-varying controls). This sector-wide response is consistent with the CyRST acting as a coordinating signal that raised the salience of cyber resilience across SSM banks.

The cross-sectional response is highly heterogeneous. In the main difference-in-differences specification, laggard banks increased cybersecurity investment by approximately 81% relative to non-laggards. The event-study evidence (Figure 2) supports the identifying assumption: there are no detectable differential pre-trends prior to 2023, and the post-announcement increase is sharp, statistically significant, and persistent.

Figure 2. Event Study: Laggard × Year Effect on Cyber Investment

The effect is concentrated among the most severe laggards. When the classification is sharpened to compare the bottom quartile (Q1) of pre-treatment residuals with the top quartile (Q4), the differential response rises substantially; when comparing Q2 to Q3, it disappears. The CyRST did not nudge everyone proportionally; it produced a “catch-up” response concentrated among banks furthest from supervisory expectations.

The Supervisory Scrutiny Channel

If the response is driven by supervisory pressure rather than by other shocks coincident with the announcement, we should observe the effect concentrated among laggard banks that faced more intensive engagement during the exercise. We construct two confidential measures from the CyRST process (a severity-weighted score of supervisory findings, and a data-quality/plausibility flag indicator), and combine them into a composite high-scrutiny indicator.

The pattern is clear. Among laggards subject to high supervisory scrutiny, the post-CyRST investment response is large and statistically robust across specifications. Among laggards subject to low scrutiny, the response is economically smaller and statistically insignificant once fixed effects are included. The same pattern holds when scrutiny is proxied by high-severity findings specifically.

This provides the central mechanism evidence. Because the CyRST carried no capital penalties and produced no bank-level public disclosure, the response cannot plausibly be attributed to the capital channel or the market-discipline channel. The most parsimonious interpretation is a scrutiny channel: the credible prospect of detailed supervisory examination raises the expected cost of continued underinvestment, prompting banks to move closer to the supervisor’s expectations.

Adjustments Beyond Headline Investment

The CyRST is associated with broader changes in cyber-risk management beyond monetary outlays. Relative to non-laggards, laggard banks:

  • Reduced reliance on external ICT outsourcing, especially payments to extra-group providers, consistent with greater internal control over critical infrastructure;
  • Accelerated legacy modernisation, with the number of critical end-of-life systems falling by about 41% across the sector;
  • Stabilised specialised human capital, with lower turnover within third-line ICT control functions (about –20.5% sector-wide), suggesting retention of cyber expertise in precisely the functions most exposed to operational risk;
  • Reconfigured cyber-insurance arrangements: relative to non-laggards, laggards reduced deductibles (broader per-incident coverage) but were about 15.5% less likely to hold coverage overall, consistent with a concentration of coverage among insured institutions rather than a uniform expansion.

Laggards also reported fewer significant cyber incidents post-CyRST. While reporting incentives may have shifted in parallel, the magnitude is consistent with genuine improvements in detection, containment, or response.

Policy Implications

(i) Supervisory scrutiny can discipline operational risk without capital or disclosure levers. The CyRST evidence is consistent with the broader argument that the threat of being looked at carefully by a supervisor is itself a regulatory instrument, particularly in domains, like cyber, where capital tools are blunt and disclosure is risk-laden. This complements Kok et al. (2023) on the supervisory scrutiny channel in traditional EU-wide stress tests.

(ii) Targeted designs work where uniform regulation does not. The effect is concentrated among banks that were furthest from supervisory expectations and faced the most intensive engagement. Uniform requirements would have imposed costs on already-compliant banks while under-disciplining laggards. The CyRST design implicitly targets the marginal underinvestor, which is a desirable property when supervisory capacity is scarce.

(iii) Stress testing extends beyond solvency. Traditional stress tests have focused on capital adequacy. The CyRST demonstrates that the stress-testing technology (scenario design, supervisor–bank dialogue, quality assurance) can be adapted to operational and technological risks. As digital dependencies deepen, this extension is likely to become increasingly important.

(iv) The framework may travel beyond banking. Energy grids, telecommunications, and payment infrastructures face structurally similar public-good problems in operational resilience. Whether targeted, non-capital-based supervisory exercises can produce comparable disciplining effects in those sectors is an open and policy-relevant question.

Conclusion

Cybersecurity in an interconnected banking system has the structural properties of a public good, and individual banks face incentives to underinvest. The 2024 ECB Cyber Resilience Stress Test offers a clean setting to ask whether qualitative supervisory scrutiny can shift this calculus. The evidence is consistent with such an effect: laggard banks raised cybersecurity investment, restructured outsourcing, retained specialist staff, and recalibrated insurance arrangements, and these adjustments are concentrated where supervisory engagement was most intense. The findings do not imply that capital regulation or disclosure are obsolete. They suggest, rather, that the supervisory toolkit is richer than the capital channel alone, and that targeted scrutiny can play a useful role in domains where traditional levers are ill-suited. For the Eurosystem and for supervisors elsewhere, the practical question is no longer whether to extend stress-testing to operational resilience, but how to design such exercises so that the scrutiny channel operates effectively. The findings reported here also speak to a broader supervisory question: how to discipline operational risks that are fast-moving, difficult to quantify, and poorly suited to traditional prudential tools. Capital requirements, calibrated primarily for credit and market risk, may be less effective in the cyber domain, while public disclosure can itself generate vulnerabilities. The evidence from the CyRST instead suggests that credible and targeted supervisory scrutiny can influence bank behaviour even in the absence of capital sanctions or public disclosure of institution-specific results. More broadly, the findings point to an expanded role for operational resilience exercises within the supervisory toolkit, particularly where risks are difficult to model ex ante but supervisory engagement can still shape incentives and preparedness.

References

Acharya, V., Berger, A., Roman, R. (2018). Lending implications of US bank stress tests: Costs or benefits?

Ahnert, T., Brolley, M., Cimon, D., Riordan, R. (2024). Cyber risk and security investment.

Aldasoro, I., Gambacorta, L., Giudici, P., Leach, T. (2023). Operational and cyber risks in the financial sector.

Anand, K., Duley, C., Gai, P. (2024). Cybersecurity and financial stability.

Crosignani, M., Macchiavelli, M., Silva, A.F. (2023). Pirates without borders: The propagation of cyberattacks through firms’ supply chains.

Draghi, M. (2024). The Future of European Competitiveness. European Commission.

Duffie, D., Younger, J. (2019). Cyber runs.

Eisenbach, T., Kovner, A., Lee, M. (2022). Cyber risk and the U.S. financial system.

European Union Agency for Cybersecurity (ENISA) (2025). ENISA Threat Landscape: Finance Sector.

Goldstein, I., Leitner, Y. (2018). Stress tests and information disclosure.

Kashyap, A., Wetherilt, A. (2019). Some principles for regulating cyber risk.

Kok, C., Müller, C., Ongena, S., Pancaro, C. (2023). The disciplining effect of supervisory scrutiny in the EU-wide stress test.

Tuominen, A. (2025). “Improving banks’ resilience to hybrid threats,” speech at the conference The Current Hybrid Threat Environment and Financial Stability, Frankfurt, 18 November.

Tuominen, A. (2026). “Upgrading banks’ capacity to deal with digital risks,” contribution to Eurofi Magazine, Frankfurt, 24 March.

Reuters (2026), “ECB’s Elderson urges euro area banks to quickly prepare for ‘MYTHOS’,” 13 May.

  • 1.

    Supervisors have also warned that advances in artificial intelligence may further amplify cyber vulnerabilities by lowering the cost and sophistication threshold for large-scale attacks. See Reuters (2026) for a discussion of ECB supervisory concerns regarding AI-assisted cyberattacks and operational resilience.

About the authors

Nordine Abidi

Nordine Abidi is an Economist at the International Monetary Fund (IMF), where his work focuses on macroeconomic surveillance, program design, and policy analysis. He previously served as an Economist at the European Central Bank (ECB), focusing on macro-financial analysis and monetary policy evaluation. His research interests lie at the intersection of macro-finance, systemic financial risk (including cybersecurity and digital transformation), and international finance. He holds a Ph.D. in Economics from the Toulouse School of Economics (TSE).

Leonardo Gambacorta

Leonardo Gambacorta is the Head of the Emerging Markets unit at the Bank for International Settlements. Prior to his current role, he served as Head of Innovation and Digital Economy, Research Adviser and Head of Monetary Policy in the Monetary and Economic Department. His primary research interests include monetary transmission mechanisms, the effectiveness of macroprudential policies in curbing systemic risk, and the effects of technological innovation on financial intermediation. He is a research fellow of the Centre for Economic Policy Research.

Christoffer Kok

Christoffer Kok is Head of the Stress Test Experts Division of the DG Horizontal Line Supervision at the ECB. He is responsible for carrying out the ECB’s annual supervisory banking sector stress tests and supporting supervision with stress-related simulations and forward-looking analysis. Previously he was Deputy Head of the Stress Test Modelling Division in the ECB’s DG Macroprudential Policy and Financial Stability responsible for developing and maintaining the institution’s top-down stress test models. Before that he was Adviser in the same DG and Principal Economist in the DG Monetary Policy. Before joining the ECB, Christoffer was an Economist in the Central Bank of Denmark (Danmarks Nationalbank). He has numerous publications on financial sector and monetary policy topics. He holds a MSc in Economics from Aarhus University and Université Paris I Sorbonne-Panthèon and a MSc in Finance from Copenhagen Business School.

Leonardo Madio

Leonardo Madio is Associate Professor in Economics at the University of Padova. His research focuses on industrial organization, digital economics and competition policy. His recent work studies cybersecurity investment by banks, platform governance and content moderation activities, privacy regulation, and mergers and innovation. He has contributed to research published in outlets including the International Economic Review, Management Science, the Journal of Economics & Management Strategy, the International Journal of Industrial Organization, and the Journal of Industrial Economics.

Ixart Miquel-Flores

Ixart Miquel-Flores is a doctoral candidate in Finance at Frankfurt School of Finance & Management. He has also been a visiting Ph.D. student in the Finance Departments of the University of Virginia Darden School of Business and the University of Chicago Booth School of Business. His research uses modern applied econometric methods to study the effects and consequences of monetary policy, financial regulation, and new technologies on the banking sector. He is a regular contributor to El País Negocios and has also contributed to the Financial Times, CEPR VoxEU, LSE EUROPP, Oxford Business Law Blog, and SUERF. His research has been covered by reputable outlets such as the Financial Times and Les Échos, as well as by platforms including Quantpedia and the Oxford Business Law Blog.Ixart works at the European Central Bank, where he has gained experience in monetary policy and banking supervision.

Alberto Partida

Alberto Partida is a Senior Team Lead at the European Central Bank, working on cyber risk within DG Horizontal Line Supervision, with a focus on emerging threats and incident response. He has over twenty years of experience in cybersecurity across both industry and academia. He is also a researcher at the Technological Institute for Data, Complex Networks & Cybersecurity Sciences of the Universidad Rey Juan Carlos and a faculty member at Universidad Europea de Madrid. He holds a PhD in Mathematics, an MSc in Telecommunications Engineering from the Polytechnic University of Madrid, and a dual MBA from Frankfurt School of Finance & Management and Henley Business School. His research interests include complex networks, blockchain, and cyber resilience in the context of financial systems and business strategy. He is the author of two cybersecurity books and a contributor to specialized technical publications.

More on these topics

Tags:
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.