Asset safety used to be a custody question: where are assets held, who is responsible for them, and how strong are the controls? Increasingly, it’s an infrastructure question, and cyber risk is the mechanism through which that infrastructure now fails. A weak link at a technology provider, an IT outsourcer, or a help desk is becoming the most common way an institution’s assets are put at risk. Often, the disruption never touches the institution’s own systems at all.
Contributed by Shreeji Doshi, director, GRC and Cyber Risk, Thomas Murray
The risk is no longer theoretical

A run of events across 2025 and 2026 has made this impact hard to ignore. Japan’s securities sector suffered a wide-reaching account hijacking campaign in 2025. By July 2026, the European Systemic Risk Board had flagged frontier AI models as a growing systemic cyber risk to European financial services, warning that incidents propagating through payment systems, clearing, and settlement could severely disrupt or shock the financial system and lead to heightened financial volatility.
Two 2025 incidents outside financial services show the scale of what’s possible. The cyber attack on Jaguar Land Rover has been modelled at £1.9 billion in UK economic loss, the most damaging UK cyber event on record. The ransomware breach at Marks & Spencer cost the retailer roughly £300 million in lost profit. In both cases, the point of failure was a third party and a person, not the target’s own perimeter. The same pattern is now running through custody chains, CSDs, and post-trade infrastructure.
Three forces widening the exposure
• Digitalisation
AI adoption is accelerating fast, with an estimated 88% of companies using AI in at least one business function by 2025, often outside governed channels. Every new integration between a custodian and a technology vendor is a new dependency an asset owner didn’t sign off on. The Bybit exchange heist, in which an estimated US$1.5 billion in assets was stolen, shows the scale of attacks now possible against digital infrastructure.
• A professionalised, AI-enabled threat landscape
State-sponsored actors are compromising networks worldwide, including telecommunications and critical infrastructure. Financial market infrastructure sits squarely in that target set. Social engineering, the method behind the M&S breach, has also been industrialised, with AI now used to scale phishing and fraud campaigns. During the response to an incident for an organisation within the digital asset ecosystem, Thomas Murray identified clear use of AI by the attacker to facilitate the attack. The result is an adversary well-resourced and automated enough to probe every custodian, CSD, and outsourcer continuously for the weakest point.
• Perimeter expansion
An institution’s cyber perimeter no longer ends at its own firewall; it extends through every custodian, sub-custodian, CSD, IT outsourcer, and cloud platform in its chain. Outages at Telstra and at the ECB’s own T2 payment system illustrate how far that perimeter now reaches. The safety of an institution’s assets is now a function of the security of entities it doesn’t control and, in most cases, cannot see.
Why current tools can’t see this exposure
Two approaches dominate cyber risk assessment today, and each solves only half the problem:
• Maturity and control assessments – deep, one-entity-at-a-time reviews, produce rich context but are point-in-time and don’t scale across a global chain of dependencies.
• External attack-surface tools – scan many entities continuously but carry no risk context. They can show a port is open at a sub-custodian; they can’t say whether that matters, or whether the custodian could recover from an attack.
Neither alone can answer the question that matters: which entities in an institution’s chain are exposed, how badly, and could they withstand and recover from an incident?
A context-at-scale approach
The way out is to combine depth and breadth. Depth means genuine context on every entity: an inherent risk assessment, the cyber threat landscape including deep and dark web exposure, an external attack surface assessment, and a clear understanding of key controls, particularly the critical ones. Breadth means applying that same depth consistently across an entire panel of custodians, CSDs, and providers, refreshed continuously and compared across entities, so it becomes a single, ongoing view of the infrastructure beneath an institution’s assets rather than a point-in-time snapshot of one link in the chain.
Scale matters because financial services is a highly interconnected industry; risk doesn’t stop at direct third parties, it extends to counterparties and other entities across the value chain. Bringing that level of context to a large and growing number of entities isn’t a nice-to-have; a context-at-scale approach is a must.
That shift matters because both JLR and M&S were failures of visibility at the edges of the organisation, not failures of effort. Continuous, contextualised intelligence is designed to close exactly that gap, enabling nuanced risk positions instead of pass/fail scores, a focus on resilience (“if it’s hit, can it recover?”) rather than security alone, and defensible, ongoing assurance for clients and regulators.
The bottom line
The safety of an institution’s assets now depends on a chain of infrastructure it doesn’t fully control or have full visibility over. Cyber risk is the mechanism through which that dependency turns into loss, transmitted through third parties and people, reaching crown-jewel assets without ever touching the victim’s own front door. The institutions that keep their assets safe will be those that treat their custodians, CSDs, and outsourced providers not as a periodic compliance exercise, but as a portfolio to be seen, in context, at scale, and continuously. Once the monitoring capability is delivered at scale with the appropriate context, mechanisms within their organisations must proactively trigger actions to manage the changing cyber risk at the speed and scale the nature of the risk demands.
This article is based on Thomas Murray’s paperBeneath the Asset: Cyber Risk and the Infrastructure Institutions Depend On.Learn more at thomasmurray.com.











