Financial services entered 2026 as the second most expensive industry to breach on the planet. A data breach now costs a financial institution USD 6.29 million on average, 26% above the global average and 12% higher than the same figure a year ago, according to the IBM Cost of a Data Breach Report 2026. The premium is getting larger, not smaller.

Understanding why requires looking past the headline number and into what the sector's testing programmes actually look like right now.

The Attack Pressure Is Unlike Any Other Sector
Financial services does not share attack pressure evenly with other industries. It absorbs it. SonicWall's 2026 report found the sector took 132,378 intrusion prevention system hits per device in the first half of 2026, the highest attack intensity of any tracked industry and more than double the cross-sector average.
Log4Shell, disclosed in late 2021, generated 35.6 million detection events in the first half of 2026 inside financial institutions alone. More than four years after disclosure, attackers are still finding unpatched instances. Two thirds of financial services organisations were hit by ransomware in the most recent measurement period, according to Sophos. Ten active ransomware families are currently targeting the sector.
The reason is structural. Banks, insurers, and superannuation funds hold the most liquid and most reusable categories of stolen data. Credentials, payment records, identity documents, and policy details have a longer exploitation shelf life than data from most other industries. That does not change regardless of which framework a firm is complying with.

What Regulators Now Require in ANZ
Both the Australian and New Zealand financial regulators have moved well beyond voluntary guidance. The frameworks are now mandatory and enforceable.
In Australia, APRA Prudential Standard CPS 234 applies to every regulated entity: banks, credit unions, insurance companies, and superannuation funds. It requires institutions to maintain an information security capability commensurate with their threat exposure and regularly test the effectiveness of those controls. Critically, the standard extends to third-party and outsourced environments. An entity under CPS 234 remains fully accountable for the security of its data regardless of whether that data sits with a vendor or cloud provider. APRA supervises institutions holding AUD 6.5 trillion in assets.
In New Zealand, the RBNZ and FMA jointly introduced mandatory cyber resilience reporting for banks, non-bank deposit takers, and insurers. Material cyber incidents must be reported within 72 hours. The RBNZ's May 2026 Financial Stability Report states directly that regulated entities are expected to maintain cybersecurity strategies that adequately address the threats they face. The FMA's operational guidance recommends that entities engage a specialist to conduct penetration testing as part of evidencing control effectiveness. As covered in our guide to penetration testing services in New Zealand, independent testing from an accredited provider is the clearest way to produce the assurance both regulators expect.
In the USA, financial institutions operate under NYDFS 23 NYCRR 500, the FTC Safeguards Rule, GLBA, and the SEC cyber disclosure rule. Each adds notification, audit, and remediation obligations on top of the technical response requirement.

Where the Testing Gap Actually Lives
The sector's testing gap is not about intent. It is about scope and frequency.
Third-party risk is the clearest blind spot. The share of breaches involving a third party has doubled to 30% across all industries. In financial services it runs higher, because banks and insurers are deeply connected to fintech integrations, payment processors, cloud platforms, and managed service providers. Most testing programmes scope to the core internal environment and treat vendor infrastructure as someone else's problem. CPS 234 does not accept that separation. For financial institutions relying on third-party APIs and cloud-hosted platforms, our guide to API penetration testing explains what regulators now expect to see covered.
Legacy system coverage is the second gap. Among financial organisations citing regulatory compliance as a modernisation driver, 79% report that at least half their applications and infrastructure are still legacy systems, per Secret Double Octopus's 2026 State of Identity Security research. Legacy environments are tested less frequently because the process requires more coordination to avoid disrupting core operations. The result is that the oldest infrastructure, often handling the most sensitive transaction data, gets the least validation. The cost this creates is examined in the analysis of security debt in financial services.
Detection latency is the third gap. Breaches in financial services take an average of 168 days to detect, according to IBM's 2026 data. Annual testing creates an evidence window far wider than that number justifies. Continuous penetration testing for compliance frameworks is how stronger programmes now structure their validation: findings are live, evidence is current, and the audit trail is not built retrospectively from a single engagement twelve months prior.
Remediation verification closes the loop. Finding a vulnerability is not the same as confirming it is closed. The steps required after a test, including re-testing and documentation, are covered in our remediation and re-testing guide. Regulators treat that verification step as the difference between a mature programme and a compliance exercise that produces a report and stops there.

Your Last Pentest Is Already Out of Date
Every week you ship without continuous testing is a week a vulnerability goes unseen. See what Capture The Bug finds in your first engagement.
The Number That Summarises the Situation
USD 6.29 million per breach. That figure covers the technical response, the regulatory notification obligations, the customer remediation, and the legal exposure. It does not include what insurers now demand to see before underwriting that risk: evidence of regular, independent security testing across the whole environment, not just the parts that were easiest to schedule.
Financial services is not struggling to understand why testing matters. It is struggling with the gap between what current testing programmes cover and what the actual attack surface now looks like. That gap is where the risk lives.
Book a free security consultation with Capture The Bug to benchmark your current testing programme against what APRA CPS 234, RBNZ guidance, and your actual threat exposure require at our Request Demo page.
Plan Your Annual Pentesting Strategy the Right Way
Learn how modern SaaS companies structure pentesting across the year to reduce risk, stay compliant, and avoid last-minute panic before audits.
FAQ
What does APRA CPS 234 require for penetration testing?
APRA CPS 234 requires all regulated entities, including banks, insurers, and superannuation funds, to regularly test the effectiveness of their information security controls, proportionate to risk exposure. The standard covers third-party and outsourced environments. An entity under CPS 234 remains fully accountable for the security of its data regardless of where it is hosted.
How much does a data breach cost a financial services organisation in 2026?
The IBM Cost of a Data Breach Report 2026 puts the average financial services breach cost at USD 6.29 million, 26% above the global average of USD 4.99 million and 12% higher than 2025. The premium is driven by regulatory disclosure obligations under APRA CPS 234, RBNZ requirements, NYDFS 23 NYCRR 500, and the SEC cyber disclosure rule, each of which adds notification, audit, and remediation costs on top of the technical response.
What are the RBNZ cyber resilience requirements for New Zealand banks and insurers?
The RBNZ requires registered banks, licensed insurers, and non-bank deposit takers to report material cyber incidents within 72 hours and submit periodic reports of all incidents. The RBNZ's May 2026 Financial Stability Report states that regulated entities must maintain cybersecurity strategies that adequately address the threats they face. The FMA recommends independent penetration testing to evidence control effectiveness.
Why does financial services experience higher attack volumes than other industries?
Banks, insurers, and superannuation funds hold the most liquid and most reusable categories of stolen data. SonicWall's 2026 report found financial services absorbed 132,378 IPS hits per device in H1 2026, the highest attack intensity of any tracked industry and more than double the cross-sector average.
How often should financial services organisations run penetration testing?
APRA CPS 234 requires testing commensurate with risk exposure, covering the full information asset environment including third parties. With financial sector breach detection averaging 168 days in 2026, annual testing creates a window far wider than the threat environment justifies. Testing frequency should reflect the pace of change in the environment, not the audit calendar.





