
- 01Three trends across the banking and financial-services customer base for the 2024-2026 window: shifting initial-access vectors, declining dwell time (a positive trend), and concentration of impact on a smaller number of high-value targets.
- 02Initial access shifting: phishing still #1 by volume but declining as a share, third-party SaaS compromise the fastest-growing vector, infostealer-bought credentials a steady channel, mobile-platform attacks rising — particularly via SDK supply chain.
- 03Dwell time fell from 31 days median in 2023 to 17 days in 2025. Improvement is concentrated in customers with strong identity threat detection — a single-digit-day gap between ITDR-equipped and ITDR-absent customers.
- 04Impact is concentrated on wholesale banking platforms, payment switches, and executive-supporting systems. Defensive investment should be proportional to that concentration, not uniform. Looking ahead: continued growth in third-party access compromise and AI-assisted social engineering.
Across our banking and financial-services customer base, three trends stand out for the 2024-2026 window: shifting initial-access vectors, declining dwell time (a positive trend), and concentration of impact on a smaller number of high-value targets.
Initial access — the moving picture
- 01Phishing — still #1 by volume, declining as a percentage of total
- 02Third-party SaaS compromise — fastest-growing vector
- 03Credential theft via infostealers — purchased on initial-access markets
- 04Mobile-platform attacks — rising, particularly via SDK supply chain
Dwell time — encouraging numbers
Median dwell time across our banking customers fell from 31 days in 2023 to 17 days in 2025. The improvement is concentrated in customers with strong identity threat detection — a single-digit-day gap exists between ITDR-equipped and ITDR-absent customers.
Concentration of impact
While the volume of attempts is broad, the meaningful impact is concentrated on a small number of high-value targets — wholesale banking platforms, payment switches, and the systems supporting executive functions. Defensive investment should be proportional to that concentration, not uniform.
Looking ahead
Expect continued growth in third-party access compromise and AI-assisted social engineering. The defensive priorities are accordingly: vendor risk management with more teeth, and authentication flows that survive a convincing voice clone of the CFO.


