Overview
- Top risks facing financial services and insurance firms
- Cybersecurity and fraud dominate financial sector risk concerns
- Risk perceptions vary significantly across European and US markets
- Financial institutions report growing concern about emerging threats
- Risk management investment increases across financial institutions
- Financial institutions face budget and regulatory constraints
- Financial impact of third-party risk by country
- US financial institutions report financial losses and security breaches
- AI adoption and digital transformation lead 2026 priorities
Cybersecurity, fraud and third-party exposure are among the most pressing risks facing banks, insurers and other financial institutions, even as organizations increase investment in risk management and artificial intelligence.
Dun & Bradstreet’s Financial Services & Insurance Pulse Survey, based on responses from 2,005 senior financial services and insurance professionals across the United States, United Kingdom, Germany, Switzerland and Sweden, examined risk preparedness, operational resilience, data quality and investment priorities for 2026.
Cybersecurity ranked as the leading concern, cited by 79.2% of respondents, followed by fraud at 77.61%. Both exceeded traditional financial, regulatory and operational risks in the survey.
The findings also revealed a substantial gap between risk awareness and organizational preparedness. Nearly 38% of respondents said their businesses were not fully prepared for cybersecurity threats, despite widespread increases in spending on protective measures during the preceding 18 months.
Key highlights
- Cybersecurity (79.2%) and insurance fraud (77.6%) are the leading concerns among financial services and insurance professionals, with nearly 38% reporting inadequate preparedness for cyber threats.
- Third-party risk failures have affected 91% of surveyed organizations, generating average estimated financial losses of $706,000 across five markets, rising to nearly $1.5 mn in Germany.
- AI adoption (39%) and digital transformation (36%) are leading strategic priorities for 2026, although 64% of firms lack confidence in making informed decisions with their existing data.
Third-party risk management emerged as another significant weakness. Approximately 91% of organizations reported negative consequences from inadequate preparation for risks associated with external providers, with estimated financial costs averaging $706,000 across the five surveyed markets.
Top risks facing financial services and insurance firms
| Risk category | Respondents concerned |
| Cybersecurity | 79.20% |
| Fraud | 77.61% |
| Competitive | 74.76% |
| Financial | 74.51% |
| Legal and compliance | 74.11% |
| Strategic | 73.32% |
| Geopolitical | 72.57% |
| Macroeconomic | 72.12% |
| Operational | 72.02% |
| Reputational | 71.77% |
| ESG | 70.37% |
Technology investment is creating additional challenges. Although internal AI adoption and digital transformation were among the leading strategic priorities for 2026, 64% of firms lacked confidence in their ability to make informed decisions using existing data, and more than half reported AI project failures attributed to poor data quality.
Cybersecurity and fraud dominate financial sector risk concerns
Dun & Bradstreet’s research found elevated concern across every major category of financial and non-financial risk examined.
The findings indicate that financial institutions are dealing with multiple categories of risk simultaneously. Traditional exposures involving financial performance, compliance and operations remain significant, alongside cybersecurity threats and increasingly sophisticated forms of fraud.
Global cyber insurance premium is set to reach $16.4 bn in 2026 as rates fall, AI risks grow and SMEs remain the largest growth opportunity, according to Beinsure report.
- More than 70% of respondents expressed concern about their organization’s vulnerability to each of the 11 risk categories included in the survey.
- Cybersecurity led at 79.2%, followed by fraud at 77.61%. Competitive risk ranked third at 74.76%, slightly ahead of financial risk at 74.51%.
- Legal and compliance risk concerned 74.11% of respondents, while strategic risk was cited by 73.32%.
- Geopolitical and macroeconomic uncertainty also featured prominently, with concern levels of 72.57% and 72.12%, respectively.
- Operational risk, including potential disruptions to business activities, registered 72.02%. Reputational risk followed at 71.77%, while environmental, social and governance (ESG) risk remained a concern for 70.37%.
The report linked growing concern about cybercrime and financial fraud to high-profile incidents over the preceding 18 months and the increasing complexity of digital transactions.
How concerned about vulnerability, if at all, do you believe your business currently is to the following types of risk?

Insurers showed particularly high levels of risk awareness. More than 80% of insurance respondents expressed concern about fraud, cybersecurity and compliance, which the report associated with the sector’s regulatory obligations and operational complexity. U.S. cyber insurance premiums rose nearly 11% in 2025 as policy volume jumped, but weaker pricing, higher losses, and AI-driven threats added fresh pressure.
Risk perceptions vary significantly across European and US markets
Risk assessments differed considerably between the five countries included in the research.
- Switzerland recorded some of the highest levels of concern across multiple categories. More than 80% of Swiss respondents expressed concern about fraud, legal and compliance exposures, and strategic risks.
- In the United Kingdom, fraud and reputational damage were particularly prominent, each registering concern among 83% of respondents.
- US financial institutions reported their highest concern about cybersecurity, at 85%, followed by fraud at 78%.
- Germany generally recorded the lowest concern levels among the surveyed markets. Only 58% of German respondents expressed concern about cybersecurity, while 56% identified macroeconomic risk as a significant issue.
These differences indicate that perceived vulnerability is not uniform across the financial services sector, even where institutions operate within an interconnected international financial system.
What, if any, types of risk do you feel your organization is not fully prepared for?

Although cyber incidents have not resulted in a significant systemic event for the U.S. financial services sector to date, they could pose risks to financial stability.
Financial institutions are lucrative targets because they manage substantial funds, hold sensitive customer data, and can be impacted by operational disruptions.
Although cyber incidents have not resulted in a significant systemic event for the U.S. financial services sector to date, they could pose risks to financial stability given the high complexity and interconnectedness of global financial institutions and their systems.
The cyber threat landscape is evolving rapidly, with nation-state actors and sophisticated criminal groups continuing to target financial institutions.
Financial institutions report growing concern about emerging threats
The survey also examined how perceptions of non-financial risks had changed over the previous 18 months.
Nearly 69% of respondents reported becoming more concerned about cybersecurity, making it the category with the largest increase in perceived risk.
Fraud followed at 65.69%, reflecting concerns about increasingly sophisticated financial crime and the complexity of digital financial transactions.
Competitive risk registered an increase in concern among 64.09% of respondents, while 63.39% became more worried about macroeconomic exposures.
Are you more or less concerned about the following non-financial risks now than you were 18 months ago?

Strategic risk concerned more respondents than previously in 62.94% of cases, followed by geopolitical risk at 62.59% and legal and compliance risk at 62.19%.
Concern about operational risk increased among 61.65% of respondents. ESG and reputational risks recorded corresponding figures of 60.40% and 59.95%.
The strongest increases in non-financial risk concerns were reported in the UK, US and Switzerland.
Risk preparedness versus increased investment
| Risk category | Not fully prepared |
| Cybersecurity | 37.86% |
| Fraud | 27.53% |
| Operational | 24.29% |
| Strategic | 26.38% |
| Competitive | 25.34% |
| Legal and compliance | 22.69% |
| ESG | 25.39% |
| Reputational | 23.64% |
| Geopolitical | 27.58% |
| Macroeconomic | 23.24% |
Dun & Bradstreet associated heightened macroeconomic uncertainty with tariffs, sanctions, international conflicts and broader political and economic developments. Existing risk management systems were struggling to address increasingly interconnected exposures. Ransomware cases surge as cloud and AI adoption expands attack surfaces, driving higher losses, supply chain risk, and tougher cyber insurance conditions.
The fact that nearly 70% of firms feel more vulnerable than they did 18 months ago is a wake-up call: resilience must be built into strategy, not pieced together after the fact.
Financial institutions and insurers must shift from reactive to predictive models, embedding intelligence into every layer of their operations.
Nearly 38% of firms are not fully prepared for cyber risks
Despite heightened awareness and increased expenditure, many financial institutions acknowledged weaknesses in their ability to manage potential threats.
Data limitations added to the problem. Approximately 73% of respondents said their existing data did not allow them to assess non-financial risk effectively.
- Cybersecurity presented the largest preparedness gap, with 37.86% of respondents stating that their organizations were not fully prepared.
- Financial risk ranked second at 31.42%, followed by geopolitical risk at 27.58% and fraud at 27.53%.
- Strategic risk was identified as an area of inadequate preparedness by 26.38% of respondents.
- Other categories also showed material gaps. ESG risk registered 25.39%, competitive risk 25.34% and operational risk, including supply chain exposures, 24.29%.
- Reputational risk accounted for 23.64%, followed by macroeconomic risk at 23.24% and legal and compliance risk at 22.69%.
These findings distinguish concern about potential threats from an organization’s assessment of its ability to address them. Although cybersecurity and fraud ranked highly on both measures, preparedness levels varied across other risk categories.
Dun & Bradstreet identified fragmented information systems, manual processes and inadequate data quality as obstacles to effective risk monitoring and technology adoption.
Risk management investment increases across financial institutions
Most surveyed organizations increased spending on risk mitigation during the 18 months preceding the research.
- Cybersecurity attracted the largest share of additional investment, with 68.79% of respondents reporting increased expenditure.
- Fraud prevention followed at 65.01%, while 63.61% increased investment in operational risk management.
- Strategic risk spending rose among 61.92% of organizations, compared with 61.56% for competitive risk and 61.44% for legal and compliance risk.
- Investment increases were also reported for ESG risk by 60.38% of respondents, reputational risk by 60.02%, geopolitical risk by 59.71% and macroeconomic risk by 59.15%.
- Operational risk ranked higher in investment priorities than in overall levels of concern, suggesting greater attention to vulnerabilities involving external suppliers, service providers and other third parties.
In the last 18 months, has your organization increased or decreased its investment in solutions that would help mitigate risks you’re concerned about?

Investment patterns also differed geographically
UK organizations reported the highest levels of increased investment across risk categories, followed by Switzerland.
In the United States, 73% of surveyed firms increased spending on cybersecurity risk mitigation, consistent with the country’s elevated concern about digital threats.
Germany recorded the lowest overall investment increases. Some 57% of German firms increased cybersecurity spending, while 52% invested more in fraud and operational risk management. For other risk categories, the proportion increasing expenditure was 45% or lower.
Swedish organizations showed particularly strong investment in strategic risk management, with 67% reporting increased spending.
ESG investment moved in the opposite direction for some businesses. More than 16% of respondents in Germany, Switzerland and Sweden reported reductions in ESG risk spending during the preceding 18 months.
Financial institutions face budget and regulatory constraints
Although many firms wanted to expand risk management investment, the research identified several barriers.
Limited budgets were the most frequently cited obstacle, affecting 31% of respondents. Regulatory constraints followed closely at 30%, while 29% reported difficulty quantifying risks sufficiently to justify additional expenditure.
The combination of financial limitations, complex regulatory requirements and insufficient risk measurement capabilities constrains organizations seeking to improve their operational resilience.
The report also pointed to the importance of cooperation between financial institutions and external partners in managing systemic exposures.
Rather than concentrating exclusively on internal controls, financial institutions were described as increasingly extending risk management efforts to relationships with suppliers, counterparties and other participants in the financial system.
What negative impacts, if any, has your organization faced as a result of not being prepared for risks related to third parties?

The global specialty insurance landscape is entering a period defined less by isolated events and more by interconnected risk. Cyber incidents can trigger business interruptions. Natural catastrophes impact affordability while emerging technologies continue to reshape exposure faster than the industry can keep pace, according to Munich Re Specialty’s latest Global RiskScan survey.
Financial impact of third-party risk by country
| Country | Average financial cost |
| Germany | $1,495,260 |
| United Kingdom | $580,937 |
| Sweden | $544,595 |
| United States | $431,002 |
| Switzerland | $262,756 |
| Five-market average | $706,000 |
Insufficient visibility into third-party relationships emerged as a substantial financial and operational concern.
Across the five markets, 91% of surveyed businesses reported experiencing negative consequences because they were inadequately prepared for risks involving external organizations.
Financial loss was the most common consequence across all markets, reported by 41.45% of respondents. Security breaches affected 35.06%, while 34.81% reported lost business opportunities. Reputational damage was cited by 33.22%, followed by supply chain disruption at 32.37%.
What is the estimated financial cost to your business from these negative impacts?

The effects also extended to employees. Increased staff turnover was reported by 29.63% of respondents, while 29.18% experienced lower staff morale.
Only 8.98% reported no negative consequences associated with inadequate third-party risk preparedness.
The estimated average financial cost of these incidents reached $706,000 across the five markets, although reported costs differed substantially by country.
- Germany recorded the highest average estimated impact at $1.495 mn.
- The UK followed at $580,937, while Sweden reported $544,595.
- US organizations estimated their average financial impact at $431,002, compared with $262,756 in Switzerland.
Although Switzerland and the United States recorded lower average estimated costs than the other surveyed markets, third-party incidents remained widespread.
US financial institutions report financial losses and security breaches
In the United States, 88% of surveyed firms reported negative consequences from inadequate preparation for third-party risks.
Financial losses were the most common reported impact, affecting 49% of US respondents. Security breaches followed at 38%, while lost opportunities and reputational damage were each reported by 35%.
The average estimated financial cost for US organizations exceeded $400,000.
Beinsure identified third-party risk management as a weakness in financial institutions’ operational resilience strategies. Third-party risk is the adversary of operational resilience. The combination of widespread incidents and substantial estimated losses showed the limitations of existing risk management frameworks.
These approaches are intended to provide financial institutions with better visibility into external relationships and potential disruptions before they produce operational or financial consequences.
AI adoption and digital transformation lead 2026 priorities
Technology modernization emerged as a leading strategic objective for financial services and insurance organizations. Cyber insurers are reviewing policy wording as autonomous AI agents create new questions over cyberattack definitions, liability and coverage triggers.
Internal AI adoption was identified as a priority by 39% of respondents, making it the most frequently cited strategic goal for 2026. Digital transformation followed at 36%.
Despite these ambitions, the research found substantial weaknesses in the information infrastructure needed to support implementation.
Nearly two-thirds of organizations, or 64%, lacked confidence in their ability to make informed decisions using their existing data. More than half reported failed AI projects caused by poor data quality.
The findings indicate that technology investment has not consistently translated into successful implementation, particularly where organizations rely on disconnected systems, manual workflows or information that is insufficiently accurate and accessible.
AI adoption, data quality and 2026 strategic priorities
| Indicator | Survey finding |
| Firms prioritizing internal AI adoption in 2026 | 39% |
| Firms prioritizing digital transformation in 2026 | 36% |
| Firms lacking confidence in decisions based on existing data | 64% |
| Firms reporting failed AI projects due to poor data quality | 50% |
| Respondents unable to assess non-financial risk effectively using current data | 73% |
The report also warned that weak data governance could increase exposure to third-party technology risks. Financial institutions adopting advanced technologies may face additional operational and compliance vulnerabilities when they have limited visibility into the external providers developing or supplying those systems.
For insurers and other financial services organizations, these constraints affect the ability to apply AI and advanced analytics to risk detection, operational processes and decision-making.
The research identified accurate, accessible and appropriately governed data as a necessary foundation for effective digital modernization.
D&B calls for stronger operational resilience
The survey identified a disconnect between the financial sector’s expanding investment in technology and risk mitigation and its confidence in managing emerging threats.
Cybersecurity and fraud remained the most widely recognized vulnerabilities, yet substantial shares of respondents considered their organizations inadequately prepared.
Third-party relationships presented additional exposure, with negative consequences reported by more than nine in ten organizations and average estimated financial costs varying from approximately $263,000 in Switzerland to nearly $1.5 mn in Germany.
At the same time, the sector’s stated priorities for 2026 placed AI adoption and digital transformation ahead of other strategic initiatives, despite continuing limitations in data quality and information management.
Dun & Bradstreet’s recommendations focused on improving operational resilience, strengthening risk detection, expanding cooperation across financial institutions and integrating advanced analytics into existing risk management processes.
The report emphasized that investment decisions should be supported by reliable data and better visibility into external dependencies.
With 64% of surveyed organizations expressing insufficient confidence in their existing data for informed decision-making, information quality remains a central obstacle to the sector’s stated AI and digital transformation priorities.
………………
AUTHOR: Peter Sonner – Lead Tech Editor at Beinsure








