Human Risk in Financial Services: Where the Money Moves
Finance is the sector where a persuaded employee converts directly to cash. What DORA demands of your people — and how to build a program that holds.

Money in a bank does not move because a system decides to move it. It moves because a person with the right permissions believes an instruction is real. That single fact explains most of the modern threat picture in financial services: UK banks alone lost £1.28 billion to payment fraud in 2025, with authorised push payment fraud — victims persuaded to send the money themselves — up 19% to £576.4 million, two-thirds of it originating online. Globally, the FBI's IC3 has tallied $55.49 billion in exposed losses to business email compromise over a decade. None of that required breaking encryption. All of it required convincing a human.
Regulators have noticed. Since 17 January 2025, the EU's Digital Operational Resilience Act (DORA) has made security awareness training a directly applicable legal obligation for nearly every financial entity in the Union — and it names senior management personally. This guide covers why finance carries a distinctive human-risk profile, what the regulation actually demands of your people, and how to build a program that satisfies a supervisor while measurably hardening the workforce.
Why finance is the shortest path from persuasion to profit
Every sector has phishing. Finance has phishing with a built-in cash-out. The Verizon DBIR attributes 62% of breaches to the human element, but in most industries an attacker who compromises an employee still faces a monetization problem — data to sell, ransomware to negotiate. In a bank, an insurer, or a corporate treasury, the person being manipulated is the monetization step. Approve the transfer, change the vendor's account details, release the payment run: the attack and the payday are the same action.
The numbers reflect that concentration of value:
| Signal | Figure | Source |
|---|---|---|
| Average breach cost, financial sector | $6.29M — second only to healthcare | IBM Cost of a Data Breach 2026 |
| BEC exposed losses, 2013–2023 | $55.49 billion | FBI IC3 PSA240911 |
| Average BEC wire-transfer request | $42,663 | APWG Q1 2026 |
| APP fraud, UK, 2025 | £576.4M, up 19% | UK Finance data |
| Voice phishing growth | +442% H1→H2 2024 | CrowdStrike Global Threat Report |
And the pretexts are getting better. Finance teams now face deepfake voice and video attacks engineered around live deals — the attempt on Ferrari failed only because an executive asked a verification question the cloned voice could not answer. FinCEN considered the trend serious enough to issue a dedicated alert on deepfake fraud schemes targeting financial institutions. The irony is that finance is, by most technical measures, a mature sector — ENISA's NIS360 assessment places banking among the most cyber-mature industries in Europe. Attackers read the same assessments. When the perimeter is hard, they call the treasury desk.
In financial services, the human layer is not adjacent to the crown jewels. It holds the keys and executes the transaction. That is why the regulator now audits your people, not just your firewalls.
What DORA actually requires of your people
DORA (Regulation (EU) 2022/2554) is best known for its ICT risk management, incident reporting, resilience testing, and third-party provisions. But Article 13(6) contains the sentence that lands on the awareness program:
Financial entities shall develop "ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes," applicable "to all employees and to senior management staff" — with complexity commensurate to their remit. The full text is on EUR-Lex.
Three properties make this stricter than the awareness clauses most compliance teams have met before. It is compulsory by name — awareness training is not an example of a reasonable measure, it is the measure. It is universal — "all employees" leaves no carve-out for the trading floor, the branch network, or the contractors running your call center, and "senior management staff" puts the board's own training on the record. And it is directly applicable — as a regulation rather than a directive, DORA needed no national transposition and offers none of the delay that has slowed NIS2 across member states. For many groups both regimes apply at once; the pragmatic route is a single program built to the stricter standard.
The supervisory logic mirrors what healthcare firms learned under HIPAA and what NIS2 entities are now discovering: a training record is evidence, and its absence is a finding. After an incident, "we ran annual training" is a weak exhibit if the phished payments operator last saw a generic e-learning module eleven months earlier and had never rehearsed a vendor bank-detail change request.
The finance-specific attack playbook
Generic awareness content misses the scenarios that actually drain accounts. A finance-sector program should be built around the pretexts attackers use against money-moving roles:
- Vendor bank-detail changes. The highest-yield BEC variant: a supplier "updates" its account before a large scheduled payment. Defense is procedural — callback verification to a number already on file, never one supplied in the request. Our BEC defense guide covers the full control stack.
- Executive payment requests. Urgent, confidential, deadline-driven — and increasingly delivered by cloned voice or video on a live call rather than by email.
- Authorized push payment pretexts. The consumer-fraud pattern has an enterprise twin: an employee or client persuaded to initiate the transfer themselves, which strips away many technical recall options (see APP fraud).
- Help-desk and MFA-reset socialing. The path that opened MGM and Clorox works at banks too: call IT, claim to be a locked-out trader, and inherit their access.
- Client-facing impersonation. Your customers are targeted with your brand — and regulators increasingly expect firms to train staff to detect the resulting anomalous instructions on client accounts.
Building a DORA-ready human risk program
1. Tier your workforce by payment power. Map who can move, approve, or redirect money — treasury, accounts payable, payroll, relationship managers, executives and their assistants — and treat them as a high-risk cohort with harder scenarios and tighter cadence. A human risk score per role and team turns this from an org-chart exercise into a measurable baseline a supervisor can inspect.
2. Rehearse the money scenarios, not just email. With voice phishing up 442% and QR and SMS lures mainstream, an email-only test misses the channels where finance is actually attacked. Run multi-channel simulations that include vendor bank-detail changes, urgent executive requests, and MFA-reset calls — the reflex you need to build is "verify out-of-band before value moves."
3. Make verification a protected behavior. Ferrari's save was cultural, not technical: an employee felt safe challenging his "CEO." Publish the verification protocol, have leadership state explicitly that no legitimate executive request ever punishes a callback, and test whether the protocol survives contact with a convincing pretext.
4. Put the board in the program. Article 13(6) names senior management; supervisors will ask for their completion records first. Board-level sessions double as sponsorship for everything else.
5. Keep evidence continuously. Cadence, content mapped to role risk, simulation outcomes, trend lines. Under DORA the program itself is a supervisable control — documentation is not overhead, it is the deliverable.
Finance already runs on measured risk — credit risk, market risk, operational risk all have owners, models, and trend lines. Human risk management simply extends that discipline to the layer where most attacks now begin: the people who move the money. The regulator has made the training mandatory. Making it work — measurable, role-based, rehearsed against the pretexts that actually empty accounts — is the part that protects the balance sheet.
Frequently asked questions
Does DORA require security awareness training?
Yes, explicitly. Article 13(6) of Regulation (EU) 2022/2554 requires financial entities to include ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes, applicable to all employees and to senior management. DORA has applied in full since 17 January 2025, and because it is a regulation rather than a directive, it applies directly — there is no national transposition to wait for and no grace period left.
Which financial firms are in scope of DORA's training obligation?
Almost all of them. DORA covers banks, insurers and reinsurers, investment firms, payment and e-money institutions, crypto-asset service providers, central counterparties, trading venues, and more — plus the critical ICT third-party providers that serve them. The training duty in Article 13(6) is not scaled away for smaller entities, though the broader principle of proportionality lets firms match the depth of their program to their size and risk profile.
Why are finance teams targeted more heavily than other departments?
Because they sit at the end of the shortest path from persuasion to profit. A compromised engineer gives an attacker access they still have to monetize; a persuaded payments operator or treasury analyst executes the monetization step themselves. That is why finance-specific pretexts dominate: fake invoices, vendor bank-detail changes, executive payment requests, and deepfake calls timed to deal deadlines. The FBI puts exposed losses from business email compromise alone at over $55 billion between 2013 and 2023.
How should a bank or insurer measure whether its human-risk program works?
Measure behavior, not attendance. Track simulation failure and reporting rates by role and channel — email, SMS, voice, QR — with harder scenarios for payment-approving roles, and watch whether verification protocols are actually invoked when a simulated out-of-band payment request lands. A quantified human risk score per team gives supervisors the audit trail DORA expects and gives the CISO a trend line that completion certificates cannot provide.
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo