FINMA Risk Monitor 2024: Cyber Threats and Market Volatility in Detail

5 min readLast updated By Philipp Staiger

What the FINMA Risk Monitor 2024 is

The FINMA Risk Monitor is the annual, publicly available situational assessment by FINMA (Swiss Financial Market Supervisory Authority). It describes the risks that the authority deems most significant for supervised entities and for the Swiss financial centre, and discloses the thematic priorities for the coming year's supervisory work. The 2024 edition was published in November 2024.

Its audience comprises banks, insurers, asset managers, fund management companies, market infrastructures and their boards of directors and executive management. The Monitor does not replace binding circulars, but signals where FINMA will focus most intensely in audits, stress tests and supervisory dialogues.

For 2024, FINMA prioritises nine principal risks. On the operational-technical side, cyber risks, risks from third-party outsourcing and ICT resilience are in the foreground. On the market side, interest-rate and credit risks, liquidity risks, and risks from the real-estate and mortgage market dominate. Money-laundering risks and long-term climate risks are also listed.

Cyber risks: the central message of the Monitor

Cyber risks are again classified in the 2024 Risk Monitor as a structural principal risk. FINMA points to a growing number of cyber incidents reported under Art. 29 para. 2 FINMASA in conjunction with FINMA supervisory notice 05/2020; the reports confirm the shift from opportunistic attacks to professionalised, ransomware- and supply-chain-oriented operations.

In substance, FINMA accentuates three points: first, the growing importance of third-party and concentration risks, particularly with cloud providers and shared IT service providers; second, the maturity of detection and response capabilities, including the use of threat intelligence; third, the need for regular, scenario-driven testing, including threat-led penetration tests in line with TIBER-EU and the TLPT (Threat-Led Penetration Testing) logic anchored in DORA Articles 26-27.

These messages connect directly to FINMA supervisory notice 03/2024 and to FINMA Circular 2023/01 'Operational Risks and Resilience - Banks', in force since 1 January 2024.

Third-party and concentration risks

FINMA classifies third-party risks as a standalone principal risk for the first time in 2024. The background is the increasing migration of critical functions - in particular core-banking platforms, market-data services and cloud workloads - to a small number of specialised providers. This gives rise to concentration risks that, in a crisis, can call into question the substitutability of a given service.

Institutions are expected to manage their outsourcing along three dimensions: the criticality of the outsourced function, the substitutability of the provider, and transparency over the sub-contractor chain. The relevant rules are FINMA Circular 2018/3 'Outsourcing - Banks and Insurers' and FINMA Circular 2023/01.

In practice this means: a complete inventory of material outsourcing arrangements, defined Impact Tolerances for business interruption per critical function, regular tests of contingency and exit strategies, and a consolidated view of the providers' C5 attestations, ISO/IEC 27001:2022 certificates and SOC 2 reports.

Market volatility and interest-rate environment

FINMA assesses the 2024 market environment as marked by geopolitical uncertainty, a normalisation of monetary policy and volatile risk premia. In the foreground are interest-rate risks in the banking book, credit risks particularly relating to commercial real estate, and liquidity risks under stressed conditions.

Banks and insurers are expected to calibrate their risk models for sudden interest-rate and spread movements, to assess deposit-stability assumptions conservatively, and to embed stress and reverse-stress tests consistently in governance. The lessons from the events around Credit Suisse in 2023 continue to shape the supervisory focus on liquidity outflows and refinancing structures.

For the mortgage market, FINMA remains attentive to investment properties with high loan-to-value ratios and to affordability assumptions, which must be re-examined in a normalised interest-rate environment.

Link to DORA and international standards

Even though Switzerland is not part of the EU, Regulation (EU) 2022/2554 (DORA), applicable since 17 January 2025, perceptibly shapes FINMA's expectations regarding ICT resilience. DORA codifies four building blocks that recur in Swiss expectations: ICT risk management, incident reporting, resilience testing including threat-led penetration testing (TLPT), and third-party risk management with a focus on critical ICT third-party providers.

Swiss institutions with EU business, subsidiaries in the EEA, or EU customers fall indirectly within the scope of DORA. Even institutions without EU exposure adopt parts of the DORA vocabulary (Impact Tolerances, threat-led testing, sub-processor visibility) because FINMA regards these concepts as a contemporary articulation of Circular 2023/01.

A more detailed comparison of the Swiss and EU requirements is available in the German-language FINMA/DORA pillar at /einblicke/finma-dora-leitfaden/.

Expectations on governance and executive management

The 2024 Risk Monitor explicitly addresses the responsibility of the board of directors and executive management. Operational resilience is not a purely IT discipline; it is part of strategic leadership. Concretely, FINMA expects:

  • A documented risk appetite for operational and ICT risks, including quantitative thresholds.
  • Up-to-date inventories of critical functions, supporting processes, IT assets and third parties.
  • Defined Impact Tolerances per critical function with a traceable derivation.
  • Regular tests of recovery, including scenarios with third-party failure and severe cyber incidents.
  • Clear escalation paths with reporting to the board of directors and notifications to FINMA under Art. 29 FINMASA.

These expectations extend beyond the Risk Monitor itself into supervisory letters and on-site reviews in 2025.

Operational measures for 2025

From the priorities of the Risk Monitor, concrete measures can be derived which institutions should focus on in the coming months:

  • Update third-party mapping: complete inventory of material outsourcing arrangements with the sub-processor chain, geographic distribution and concentration analysis.
  • Deepen resilience testing: move from purely technical disaster-recovery exercises to scenario-based tests combining cyber, third-party failure and crisis communications.
  • Introduce threat-led testing: align with TIBER-EU and the DORA RTS on TLPT (Threat-Led Penetration Testing), at least for critical market participants.
  • Harden detection and response: review SOC process maturity, integrate threat intelligence, exercise run-books regularly.
  • Discipline vulnerability management: combine continuous vulnerability scanning with targeted penetration tests, prioritised by business criticality - see also Pentest vs. vulnerability scan.

The measures should be anchored in the risk inventory and reported to the board of directors.

How SIDD supports you

SIDD supports Swiss financial institutions in translating the Risk Monitor into measurable actions. We bring the maturity of your third-party management, of your detection and response capabilities and of your resilience testing to the level FINMA expects, and document the results in an audit-ready manner.

Our services include building and operating an ISMS to ISO/IEC 27001:2022, providing a fractional CISO for ongoing governance, and delivering penetration tests and vulnerability scans. Certifications are issued through CIS Cert (Quality Austria Group, ISO/IEC 17021-accredited).

Get in touch if you are looking for a structured stocktake on cyber and third-party risks in the spirit of the FINMA Risk Monitor 2024.

FINMA Risk Monitor 2024: Cyber Threats and Market Volatility in Detail

INSIGHT

All
28 May 2026
Philipp Staiger
The FINMA Risk Monitor 2024 is the annual situational assessment by the Swiss Financial Market Supervisory Authority. It prioritises cyber risks, third-party dependencies and market volatility as central supervisory focus areas for 2025.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.