19 May 2026

Finance as critical infrastructure
A nation's payment systems, exchanges and banks are infrastructure in the fullest sense: when they stop, commerce stops. Regulators worldwide have drawn the consequence, shifting from asking whether firms can prevent incidents to demanding proof they can operate through them. Continuity of critical business services under attack is the new test.
The threat picture for financial firms
Financial institutions face the most professionalised end of the threat spectrum: organised criminal groups running ransomware and fraud operations at industrial scale, state-linked actors interested in disruption and intelligence, and systemic exposure through third parties: the vendors, processors and market utilities on which every firm silently depends and through which incidents propagate sector-wide.
What OT thinking brings to banking
The operational-resilience agenda imports the OT mindset into finance: identify the critical services whose interruption harms the real economy, map every system and third party they traverse, set tolerances for how much disruption is survivable, and rehearse severe-but-plausible scenarios until continuity is demonstrated rather than asserted. It is availability-first security, the discipline industrial operators have always lived by.
Where the disciplines physically meet
The convergence is also literal: data centres, trading floors and cash-processing sites run on building management, power and cooling systems that are themselves OT, and a bank that cannot cool its data centre is offline as surely as one that is breached. Serious resilience programmes now scope the physical control layer, its vendors and its remote-access paths alongside the digital estate.
The takeaway for financial firms
For financial institutions, infrastructure in the fullest sense, the advantage now lies in proving continuity rather than promising prevention. The operational-resilience agenda imports the OT mindset regulators increasingly expect: identify the critical services whose interruption harms the real economy, map every system and third party they traverse, set tolerances for how much disruption is survivable, and rehearse severe-but-plausible scenarios until continuity is demonstrated, not merely asserted. The often-missed conclusion is that the physical control layer belongs inside that scope, because data centres, trading floors and cash-processing sites depend on building-management, power and cooling systems that are themselves OT, and a firm that cannot cool its data centre is offline as surely as one that is breached. Firms that protect the digital estate and the control layer together, and confront their third-party concentration honestly, keep their critical services running when it counts.

