The recent cyber incidents affecting Marks & Spencer, Co-op and Qantas may have occurred outside the banking industry, but the lessons they offer are highly relevant to every financial institution. Each organisation faced different operational challenges, yet all were ultimately judged on the same criteria: how quickly they responded, how transparently they communicated and how effectively they maintained customer confidence. For banks, where trust is the foundation of every relationship, these incidents reinforce a growing reality that cybersecurity is no longer just about protecting systems. It is about protecting confidence, preserving reputation and demonstrating resilience when disruption inevitably occurs.
Cyberattacks Have Become Public Trust Events
Cyber incidents no longer remain confined to security operations centres or executive boardrooms. Within minutes of an attack becoming public, customers, investors, regulators and the media begin forming opinions about how effectively an organisation is responding.
The experiences of M&S, Co-op and Qantas demonstrated how quickly operational disruptions become public conversations. Service interruptions, delayed communications and uncertainty often attract as much attention as the technical attack itself. In today’s connected world, every cyber incident is also a communications challenge.
Banks operate under even greater public scrutiny. Customers expect continuous access to their accounts, payments and digital banking services, meaning confidence can begin eroding long before investigators fully understand what has happened.
Customers Judge the Response More Than the Attack
Most customers understand that cybercrime has become an unavoidable reality.
What distinguishes organisations is how they respond.
Clear communication, visible leadership and regular customer updates demonstrate preparedness and accountability during periods of uncertainty. By contrast, delayed responses, inconsistent messaging or prolonged silence often create greater reputational damage than the original technical compromise.
For banks, crisis communication has become an extension of customer service. Every interaction during a cyber incident either strengthens or weakens public confidence.
This reinforces a point Finnoex explored in The Cost of a Cyberattack Isn’t Downtime. It’s Lost Confidence, where preserving trust increasingly matters as much as restoring systems.
Digital Trust Is Becoming a Competitive Asset
Banking has always relied on trust, but digital transformation has fundamentally changed how that trust is earned.
Customers rarely visit branches today. Their confidence is built through mobile applications, online banking platforms, payment experiences and digital interactions. Every successful login, instant payment and fraud alert reinforces the perception that their financial institution is secure and reliable.
Cyber incidents therefore affect more than operational continuity. They directly influence customer confidence in the digital experience itself.
Institutions that consistently demonstrate resilience, transparency and accountability strengthen their reputation long after individual cyber incidents have passed.
Third-Party Risk Continues to Expand
One of the most important lessons from recent cyber incidents is that organisations are only as resilient as the ecosystems supporting them.
Banks increasingly depend on cloud providers, software vendors, payment processors, identity verification platforms and fintech partners to deliver modern financial services. Every new integration expands the digital supply chain while creating additional cyber exposure.
Managing third-party cyber risk has therefore become just as important as protecting internal infrastructure. Resilience now depends on understanding dependencies across the entire technology ecosystem rather than focusing solely on internal networks.
Artificial Intelligence Is Changing the Nature of Cybercrime
Artificial intelligence is accelerating both cyber defence and cybercrime.
Financial institutions are increasingly deploying AI to analyse security events, identify anomalies and automate incident response. At the same time, cybercriminals are using AI to generate convincing phishing emails, clone executive voices, produce deepfake content and automate reconnaissance activities.
This rapidly evolving landscape means banks can no longer rely solely on traditional security controls. Continuous adaptation, intelligent monitoring and rapid decision-making are becoming essential capabilities.
As Finnoex discussed in Banks Don’t Need Bigger Models. They Need Better Decisions, technology delivers its greatest value when it improves the quality and speed of organisational decisions.
Operational Resilience Is Becoming More Important Than Prevention
No organisation can realistically expect to prevent every cyberattack.
The experiences of M&S, Co-op and Qantas reinforce that resilience increasingly matters more than perfection. The ability to isolate affected systems, restore critical services quickly and continue serving customers has become a defining measure of organisational maturity.
Financial regulators are already moving in this direction through increased emphasis on operational resilience, business continuity and incident response capabilities.
Banks that prepare for recovery rather than assuming complete prevention will be significantly better positioned to maintain customer confidence during future disruptions.
This aligns closely with Finnoex’s recent analysis in Every Bank Will Be Hacked. The Winners Will Recover First, where recovery speed is emerging as a competitive advantage.
Complexity Makes Recovery Harder
Many cyber incidents expose an underlying problem that existed long before the attack itself.
Highly fragmented technology environments often delay investigations, complicate incident response and slow operational recovery. Multiple customer databases, disconnected applications and overlapping infrastructure create uncertainty during periods when rapid decisions matter most.
Simpler architectures improve visibility, accelerate containment and reduce recovery times because technology teams understand system dependencies more clearly.
As discussed in The Silent Cost of Complexity: Why Banks Must Simplify Before They Can Innovate., reducing organisational complexity strengthens both innovation and cyber resilience.
The Future of Banking Will Be Built on Digital Trust
The cyber incidents affecting M&S, Co-op and Qantas demonstrate that digital trust has become one of the most valuable assets any organisation can possess. While these companies operate outside financial services, the lessons are especially significant for banks, whose business models depend entirely on confidence.
Technology will continue evolving, cyber threats will become more sophisticated and regulatory expectations will continue rising. The institutions that succeed will not necessarily be those that avoid every incident, but those that demonstrate resilience, communicate transparently and recover quickly enough to preserve customer trust.
In the digital economy, cybersecurity is no longer simply protecting technology.
It is protecting confidence.
What it means for the industry
- Recent cyber incidents highlight that customer confidence is increasingly shaped by an organisation’s response rather than the attack itself.
- Banks should treat cyber resilience as a strategic business capability, not solely an IT responsibility.
- Third-party technology providers have become a critical component of enterprise cyber risk management.
- AI is transforming both cyber defence and cybercrime, requiring continuous investment in intelligent security capabilities.
- Simpler technology architectures improve incident response, operational resilience and recovery times.
- Digital trust is becoming one of banking’s most valuable competitive advantages as customers increasingly judge institutions on transparency, resilience and reliability.

