2025 State of Financial Services: Hidden Dangers in the Vendor Ecosystem
While direct ransomware attacks on financial institutions have plummeted—from 191 in 2023 to just 55 by mid-2025—this apparent calm masks a critical and growing storm brewing within the sector’s extensive third-party vendor ecosystem. Among these vendors:
An alarming 92% are failing or performing poorly in Information Disclosure.
A staggering 64% are flagged with high-risk threat categories.
65% are not maintaining current patch levels.
This report provides the hard data and expert analysis you need to understand the pervasive nature of vendor weaknesses and how to stop the cascading impact a single cyber event can have on your operations.
Black Kite delivers unmatched visibility into your third-party ecosystem through defendable cyber ratings, financial impact powered by Open FAIR™, likelihood of a ransomware attack in your cyber ecosystem, and platform to share asset-level intelligence directly with your vendors.
EARLY WARNINGS FOR PROACTIVE DEFENSE
Our platform identifies emerging risks like critical CVEs and active cyber events that could be hiding deep in the vendor ecosystem, enabling financial organizations to stay ahead of cyber threats.
STREAMLINED VENDOR COLLABORATION
Black Kite closes the loop between risk identification and remediation with the ability to collaborate closely with vendors to resolve risks.
Overall, our company's experience with Black Kite has been very positive. The intel we are getting has significantly improved our 3rd-party supply chain monitoring process compared to where we were with other popular products in this space.
- 5 Star Review, Financial Services User (Gartner)
Excellent product, having the ability to share the findings with the vendor/partner is a tremendous help. The system is easy to use and has a ton of features.
- 5 Star Review, Financial Services User (Gartner)
We selected Black Kite to execute on our goals related to Third Party risk. We monitor higher risk vendors and have received regular, meaningful updates that require those vendors to action.
- 5 Star Review, Financial Services User (Gartner)
Learn how to narrow down the tens of thousands of CVEs to the handful that truly matter in your vendor ecosystem and how to apply risk hunting to TPRM.