22,382
Internet-facing assets discovered
Across 5 scanned organisations
1,466
Supplier connections mapped
script · cert · ASN · DNS · header
120
Fix Now priorities
Requiring immediate action
7/5
Suppliers common to all 5 orgs
Microsoft · Amazon · Cloudflare · Google · GitHub · jQuery · Meta
Why financial services attack surfaces carry unique systemic risk
Financial institutions are custodians of trust. Banks, insurers, wealth managers, fund administrators, and professional services firms handle client assets, personal financial data, and highly sensitive transaction records. Their external digital estate — every subdomain, API endpoint, third-party script, and cloud-hosted portal visible from the public internet — is a primary target for attackers seeking financial gain, data theft, or reputational damage.
The complexity of modern financial services infrastructure makes this attack surface difficult to control. Wealth platforms integrate with custody banks and data providers. Fund administrators operate portals spanning dozens of fund structures. Insurance platforms connect to claims processors, actuarial tools, and partner networks. Each integration point, hosted application, and third-party library extends the external footprint — often without the security team's knowledge.
This report draws on simultaneous scans of five financial services organisations across the Netherlands, Belgium, United Kingdom, and Luxembourg — spanning an ethical bank, an insurance group, a wealth management platform, a global fund administrator, and a professional accounting firm. The findings reveal a sector where email authentication failures expose client-facing domains to impersonation, where software supply chain risks are universal, and where seven technology suppliers are embedded in every organisation's external estate. One organisation stands out with a B rating — demonstrating that strong external security posture is achievable in this sector.
All organisations in this report are anonymised. Technology suppliers and infrastructure providers are named as they appear on the external attack surface.
Sector Benchmark
How do financial services organisations compare?
ThingsRecon scanned five financial services organisations simultaneously — from a Dutch ethical bank to a Luxembourg-based global fund administrator. Four of five received an overall score of C; one achieved a standout score of B. The sector's most alarming single indicators are Email F ratings at two organisations — one a UK wealth management platform, one a global fund administrator — meaning the domains of these financial firms can be impersonated to send spoofed emails to clients and counterparties. Additionally, one insurance group carries both a Header F and Software F rating, indicating the most severe category-level exposure in the benchmark.
Organisation
Assets
Suppliers
Fix Now
Fix Soon
Score
Weak indicators
Company AEthical bank · NL
2,229
94
9
18
B
Headers C · Software C
Company BInsurance group · BE
3,750
64
31
37
C
Headers F · Software F · App D
Company CWealth platform · UK
5,604
175
18
31
C
Email F · Software D · Domain C
Company DFund administrator · LU
6,026
209
48
51
C
Email F · Headers D · Network B · Domain C
Company EAccountancy & advisory · BE
4,773
69
14
44
C
Headers C · Software C · Domain B
Sector-wide Risk Patterns
Structural vulnerabilities across the financial services digital estate
The patterns below appear consistently across financial services organisations regardless of sub-sector, size, or geography. They reflect the accumulated digital complexity of organisations that have layered new client-facing platforms on top of legacy infrastructure — creating an external surface that grows faster than security teams can track.
Email Authentication
Critical
Two of five organisations carry Email F ratings — the most dangerous finding category for financial entities. Missing or misconfigured DMARC/SPF/DKIM enforcement means these domains can be freely impersonated. Financial institutions are among the most targeted brands for business email compromise: their clients move large sums on the basis of an email, making effective email authentication a first-line financial fraud control. Under DORA Article 5, managing ICT risk includes protecting client-facing communication channels from impersonation.
HTTP Security Headers
Critical
One organisation received an F rating for HTTP security headers — the worst possible score — while two others received C and one received D. Only the highest-scoring organisation (B overall) maintained adequate header controls. Client portals for banking, wealth management, and fund reporting without Content-Security-Policy and HSTS controls are directly exposed to clickjacking, cross-site scripting, and credential-interception attacks. The F-rated organisation has 23 web applications online, multiple of which handle client authentication and account data.
Software Supply Chain
High
All five organisations carry Software risk of C or worse — including one F and one D. Outdated, vulnerable JavaScript libraries appear across client-facing financial portals and reporting dashboards. In financial services, a compromised script on an authenticated client portal can silently harvest session tokens, intercept two-factor codes, or redirect authenticated users to credential-harvesting pages — all without any server-side intrusion. Software F and D ratings indicate known-vulnerable library versions that have publicly documented exploits.
Application Security
High
Application-level findings appear across all five organisations. The insurance group scored D on application risk — driven by 13 Fix Now application findings across 23 online web applications. The fund administrator, with 206 applications in scope and 48 Fix Now items overall, has the most complex application estate and the highest absolute priority count. Financial applications handling client KYC data, investment positions, and transaction histories are high-value targets; application-level weaknesses provide direct access to this data.
Supplier Concentration
High
Seven technology suppliers appear in all five financial services organisations simultaneously — the highest cross-sector supplier overlap across all ThingsRecon sector reports. Microsoft, Amazon, Cloudflare, Google, GitHub, the OpenJS Foundation, and Meta Platforms are each present in every organisation's external estate. Microsoft achieves an average digital proximity of 60% across the sector — meaning its infrastructure is woven into the core of every financial institution's client-facing estate. A supply chain compromise affecting any of these seven providers has simultaneous sector-wide impact.
Cookie & Session Controls
Medium
Cookie risk appears across all five organisations, with D-rated cookies detected at three. In financial services, poorly configured session cookies — missing Secure, HttpOnly, or SameSite attributes — on authenticated client portals represent a direct path to session hijacking. Wealth management and fund administration portals that hold authenticated sessions for clients managing portfolios are particularly sensitive: a stolen session token is functionally equivalent to stolen credentials.
Domain & Certificate Hygiene
Medium
Domain risk indicators appear at three organisations, with C ratings at the wealth platform and fund administrator. Financial institutions typically manage complex domain portfolios spanning client portals, regulatory submission interfaces, partner integrations, and legacy service domains. Certificate mismanagement and dangling DNS records across this estate create subdomain takeover exposure — particularly relevant for fund administrators and wealth platforms whose clients interact with branded sub-domains for portfolio access and reporting.
Sector verdict: The financial services sector's external attack surface combines high data sensitivity with structural authentication failures. Two organisations have email domains that can be freely spoofed — a direct financial fraud risk. One insurance group carries the sector's most severe category-level ratings (Header F, Software F). Across five organisations, 120 Fix Now and 181 Fix Soon items require structured remediation. Under DORA, financial entities must continuously assess ICT risk across their external estate — and these findings show the gap between what firms believe their perimeter looks like and what is actually visible from the public internet.
Why Financial Services Needs This
Discovery. Prioritisation. Monitoring.
Financial services organisations manage external estates that span client portals, regulatory reporting interfaces, partner APIs, custody integrations, and mobile banking applications — all growing continuously and all holding or transmitting client financial data. ThingsRecon maps every publicly visible asset and supplier connection from a single seed domain, with no agents required and no access to internal systems.
01
Continuous Discovery
Financial digital estates expand with every new product launch, acquired entity, or partner integration. ThingsRecon discovers every subdomain, cloud-hosted service, third-party script, and certificate — including email authentication configuration — continuously. Email F ratings, dangling DNS records, and unmanaged legacy portals are identified the moment they appear on the external surface.
02
Risk Prioritisation
With 120 Fix Now items across five organisations, financial security teams cannot address everything simultaneously. ThingsRecon scores every finding by exploitability and proximity to client-facing assets — enabling teams to remediate Email F domains, patch vulnerable client portal libraries, and fix application-level weaknesses before lower-priority hygiene issues consume security capacity.
03
Supply Chain Monitoring
Seven technology suppliers appear in every financial services organisation scanned. ThingsRecon monitors every supplier connection for changes — new scripts, CDN routing changes, certificate rotations, unexpected subdomain appearances — the moment they occur on the external surface, before they become ICT incidents requiring notification under DORA or FCA operational resilience expectations.
Supply Chain Intelligence
The suppliers inside every financial services digital estate
ThingsRecon maps the technical supply chain — every third-party component detected on the external attack surface via scripts, certificates, DNS, ASN routing, and HTTP headers. These are the suppliers that standard TPRM questionnaires miss because they were never deliberately onboarded: they arrived embedded in web platforms, analytics tools, CMS themes, and acquired digital estates. In financial services, where client-facing portals carry authenticated sessions, investment positions, and payment data, the risk profile of this invisible supply chain is directly tied to client financial harm.
Sector-wide supplier connections1,466 connections mapped
Across 5 financial services organisations — detected via script, cert, ASN, DNS, and header vectors. The large majority are undeclared in any TPRM register and unknown to security teams.
Universal suppliers (all 5 orgs)7 in every estate
Microsoft, Amazon, Cloudflare, Google, GitHub, OpenJS/jQuery, and Meta each appear in all 5 organisations — the highest cross-sector supplier overlap across all ThingsRecon sector benchmarks.
Fix Now items — fund administrator48 Company D alone
The global fund administrator carries 48 Fix Now and 51 Fix Soon items across 6,026 assets and 206 web applications — the largest and most complex attack surface in the benchmark.
Sector best performerB Company A — Ethical bank
One organisation achieves a B rating — the only non-C score across all five. With only 9 Fix Now items, it demonstrates that strong external security hygiene is achievable in financial services.
Supplier
Avg proximity
Connection vector
In
Found in
Microsoft Corporationmicrosoft.com · azure.com · office365.com
60%
script · header · ASN
5 / 5
Company A, B, C, D, E
Amazon Technologies, Inc.amazon.com · aws.com · amazonaws.com
54%
ASN · cert · dns
5 / 5
Company A, B, C, D, E
Cloudflare, Inc.cloudflare.com · cloudflare.net
52%
ASN · cert · header
5 / 5
Company A, B, C, D, E
Google LLCgoogle.com · googleapis.com
52%
script · header · dns
5 / 5
Company A, B, C, D, E
GitHub Inc.github.com · githubusercontent.com
36%
script · header
5 / 5
Company A, B, C, D, E
Critical Supplier Spotlight
Microsoft Corporation
microsoft.com · azure.com · office365.com | Avg proximity 60% · Max 64%
Found in
All 5 scanned financial services organisations
Digital proximity
64% max Highest proximity in Company A
Connection vectors
JavaScript scripts · response headers · ASN routing · DNS
Financial risk profile
Identity dependency Client data platform
Microsoft is the most deeply embedded technology supplier across every financial services organisation in this benchmark — present at an average digital proximity of 60%, with a peak of 64% at the sector's best-performing organisation. In practice, this means Azure Active Directory controls identity for every client-facing and internal application, Microsoft 365 handles all staff and client communications, and Azure hosts financial workloads, compliance tooling, and client data platforms. For financial entities, the implication is critical: a misconfigured Entra ID application registration, an overpermissioned OAuth scope, or an undeclared Azure-hosted service creates a path from the public internet to client financial records. Under DORA Article 28, Microsoft qualifies as a critical ICT third-party service provider — requiring documented risk assessment, contractual resilience provisions, and continuous monitoring of the connection. ThingsRecon detects every Microsoft touchpoint on the external estate, maps its proximity to client-facing applications, and monitors for configuration changes that may not trigger internal change management controls.
Attack vector: Misconfigured Azure Entra ID app registration → overpermissive OAuth token issued to third-party → lateral access to M365 mailboxes → harvested client communications → impersonation of financial advisor → fraudulent instruction
Financial services attack path — Email F to client financial fraud
1
Entry point
Email F-rated financial domain exploited — DMARC absent, domain spoofed, attacker sends email appearing to originate from a legitimate wealth management firm
Entry
No authentication required — email authentication controls absent on public domain
2
Pivot
Spoofed email delivers fake investment confirmation or urgent wire transfer instruction to high-net-worth client — trusted sender domain bypasses spam controls
Pivot
Client has no means to distinguish spoofed email from genuine firm communications
3
Impact
Fraudulent transfer authorised, client credentials harvested via fake portal link, or investment positions manipulated — direct financial and reputational harm
Impact
Sector Findings
Aggregated risk signals across all scanned organisations
The following findings reflect patterns observed across all five financial services organisations. Individual organisation-level findings with full asset detail are available through a full ThingsRecon engagement.
- Fix Now
Email domain spoofing exposure (Email F) — Two organisations have no effective DMARC enforcement on their primary email-sending domains. Any attacker can send emails appearing to originate from these financial entities, targeting clients and counterparties with fraudulent communications. Immediate DMARC policy enforcement at reject mode is required.
- Fix Now
Software F — known-vulnerable libraries on client-facing applications — One insurance group carries an F rating for software risk, with 18 Fix Now software findings indicating known-exploitable component versions present on live web applications. Client authentication portals and claims submission interfaces running vulnerable JavaScript dependencies are directly exposed to CVE-documented exploits.
- Fix Now
Application-level Fix Now findings across the fund administrator estate — The fund administrator carries 48 total Fix Now items including 24 application-level Fix Now findings across 206 web applications. Applications graded D and F within the estate include live investor-facing portals handling fund positions, NAV reporting, and document exchange for institutional clients.
- Fix Soon
HTTP Security Header F at insurance group — The insurance group's external estate lacks fundamental browser security controls across 23 online applications. Absence of Content-Security-Policy and HSTS enforcement on authenticated insurance portals exposes policyholders to cross-site scripting, clickjacking, and man-in-the-middle attacks on authenticated sessions carrying personal financial and health data.
- Fix Soon
Cookie D ratings across three organisations — Poorly configured session cookies appear at three of five financial services organisations, with D-rated cookies detected on authenticated portals. Missing Secure, HttpOnly, and SameSite cookie attributes on client investment portals and account management interfaces expose authenticated sessions to theft and replay attacks without any server compromise required.
- Fix Soon
Domain C ratings at wealth platform and fund administrator — Domain risk indicators at both the wealth management platform and the global fund administrator suggest misconfigured or dangling DNS records within complex domain portfolios. Fund administrators and wealth platforms frequently operate large numbers of branded client-access subdomains — unclaimed or misconfigured records within these portfolios create subdomain takeover exposure on exactly the URLs clients trust for portfolio access.
- Monitor
Seven universal technology suppliers — undeclared in TPRM registers — Microsoft, Amazon, Cloudflare, Google, GitHub, the OpenJS Foundation, and Meta are each present in all five financial services organisations. Under DORA Article 28, critical ICT third-party service providers require formal risk assessment and contractual resilience provisions. The technical connections detected by ThingsRecon frequently represent undeclared dependencies invisible to standard vendor management processes.
- Monitor
Network B rating at the fund administrator — One organisation, the Luxembourg fund administrator, is the only entity in this benchmark to receive a non-A network risk rating. A B-rated network profile indicates publicly visible network-level findings — potentially open ports, service banner disclosures, or network-accessible management interfaces — on an estate spanning 65 IP addresses and 407 FQDNs. Given the fund administrator's global institutional client base, network perimeter hygiene requires close monitoring.
- Track
SSL/TLS configuration issues across all five organisations — SSL B ratings appear across all five financial services entities, with Fix Now SSL findings at two. Financial portals that handle client authentication, investment transactions, and document exchange rely on TLS integrity — weak cipher configurations, certificate mismanagement, and outdated TLS versions represent a persistent hygiene risk requiring structured remediation programmes and ongoing monitoring.
Get the Full Picture
Your organisation's external attack surface — mapped in 24 hours
This sector report shows patterns across five anonymised organisations. A full ThingsRecon engagement gives you the complete asset inventory, supplier proximity map, and prioritised remediation backlog for your own estate — with no agents, no network access, and no internal onboarding required.
✦ Full asset inventory
✦ Supplier proximity scores
✦ Email authentication audit
✦ Fix Now / Fix Soon list
✦ DORA Article 5 & 28 evidence
✦ Continuous monitoring
Request your scan