What Drives Cyber Losses at U.S. Banks? Potential Statistical Markers
Using new individual bank-level data, this study reveals that cyber loss rates at U.S. banks follow a U-shaped relationship with bank size and are primarily driven by idiosyncratic factors, though more profitable and efficient banks tend to experience lower loss rates when controlling for size.
Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Every bank holds a digital vault, not just for money, but for the vast streams of data that keep the modern economy moving. Protecting these vaults is a constant battle against cyberattacks, which can range from minor glitches to massive thefts that threaten financial stability. For years, regulators and bank leaders have worried about who is most vulnerable: is it the giant institutions with complex, sprawling networks, or the smaller community banks with fewer resources to build strong defenses? To answer this, researchers need a way to measure the average amount of money a bank might lose in a typical year due to these digital threats. This figure, known as the average annual loss, acts as a baseline for understanding risk, helping officials decide how much insurance to buy or how much to spend on security. Until recently, however, there was no clear picture of how these potential losses changed as banks grew larger or smaller, leaving a gap in the understanding of where the greatest dangers truly lie.
A team of researchers from the Federal Reserve Bank of Dallas set out to fill this gap by combining new, detailed estimates of cyber risk with standard financial data from thousands of U.S. banks. They used a sophisticated modeling platform that simulates tens of thousands of potential cyber incidents, ranging from data theft and ransomware demands to service outages. By feeding this simulated loss data into statistical models alongside real-world bank performance numbers, they sought to identify the specific factors that drive these losses up or down. Their goal was to move beyond guesswork and find the actual statistical markers that signal a higher or lower risk of financial loss from cyber events.
The researchers discovered a pattern that defied the common assumption that bigger banks are simply more at risk. Instead of a straight line where risk increases or decreases steadily with size, the data revealed a distinct U-shape. The risk of losing money to cyberattacks is highest for the smallest banks and the largest banks, while it dips to its lowest point for mid-sized institutions. This finding challenges the idea that cyber risk simply declines as banks get bigger. The smallest banks often lack the deep pockets needed to invest in robust security systems, making them easy targets. Conversely, the largest banks, despite their massive security budgets, are so complex and hold such valuable data that they remain highly attractive, high-reward targets for attackers. Mid-sized banks appear to sit in a "sweet spot," possessing enough resources to defend themselves effectively without the overwhelming complexity that makes giant institutions vulnerable.
Beyond the shape of the curve, the study found that a bank's size is the single most powerful predictor of its cyber loss rate. Once the size of the bank is accounted for, other standard financial measures have surprisingly little power to explain why one bank loses more than another. This suggests that cyber risk contains a large, unique element specific to each institution that cannot be easily predicted by looking at their balance sheets alone. However, among the factors that do matter, the researchers found that more profitable and efficient banks tend to have lower loss rates. This implies that banks with strong financial health and good management may be better positioned to invest in the security measures that prevent losses, or perhaps their operational discipline extends to their digital defenses.
The study relied on data from 2023 and focused on "attritional" losses, which are the frequent, smaller-scale incidents that happen regularly, rather than rare, catastrophic events that could shake the entire system. While the numbers are small—averaging just over one basis point of a bank's revenue—the patterns they reveal are significant for regulators. The findings suggest that a one-size-fits-all approach to cyber risk is insufficient. Instead, supervisors must recognize that the threats facing a small community bank are fundamentally different from those facing a global giant, and that the middle ground offers a surprising degree of safety. As artificial intelligence and new attack methods evolve, these baseline measurements will remain essential for understanding how the financial system holds up against the ever-present digital threat.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.