ECB cyber stress tests boost bank investment by 80 percent
The European Central Bank's 2024 Cyber Resilience Stress Test (CyRST) significantly increased cybersecurity investment among 'laggard' European banks. These banks, identified as underinvesting relative to their cyber-risk profiles, raised their cybersecurity spending by about 80 percent following the test's announcement.
Scrutiny drives cyber investment
A new ECB working paper provides the first evidence that targeted supervisory scrutiny can effectively address underinvestment in cybersecurity.
The 2024 Cyber Resilience Stress Test (CyRST) acted as a quasi-natural experiment, revealing that 'laggard' European banks — those underinvesting relative to their cyber-risk profiles — significantly increased their cybersecurity spending.
Following the CyRST announcement, these banks boosted investment by approximately 80% relative to their peers.
This response was particularly pronounced among laggards subject to high-intensity supervisory oversight, demonstrating a clear disciplining effect.
The findings suggest that non-capital-based stress tests can mitigate the systemic underinvestment problem inherent in cybersecurity, where individual banks fail to fully internalize the broader benefits of their security efforts for the interconnected financial system.
The scrutiny channel at work
The CyRST was designed to isolate the 'scrutiny channel' by explicitly neutralizing traditional regulatory levers.
It carried no direct capital consequences (Pillar 2 requirements) and involved no public disclosure of bank-level results, allowing researchers to study how heightened supervisory attention influences investment.
Using confidential supervisory data from 109 Significant Institutions in the euro area from 2019 to 2024, the study tracked detailed IT and cybersecurity spending.
The empirical strategy first identified 'laggard' banks based on their pre-CyRST investment relative to cyber-risk profiles, then used a difference-in-differences design to analyze changes post-announcement.
Supervision's quiet power
This research offers crucial insights into the effectiveness of qualitative supervisory tools in an evolving risk landscape.
By demonstrating that scrutiny alone can drive significant behavioral change, the findings validate a powerful, non-traditional lever for central banks.
For policymakers, it underscores the potential to foster systemic resilience in complex areas like cyber risk without relying solely on capital or public shaming.