Thomas Murray Releases His Second Report

0
2

Key Takeaways

  • Cyber risk is now the primary transmission mechanism through which infrastructure failures affect institutional assets.
  • Failures often originate outside an institution’s own perimeter—in custodian sub‑networks, IT outsourcers, cloud platforms, and help desks.
  • State‑sponsored cyber activity is converging with geopolitical risk, directly targeting critical infrastructure such as banking systems.
  • Traditional due‑diligence approaches (deep but infrequent or broad but shallow) are insufficient; continuous, contextualised risk intelligence across the entire dependency chain is required.
  • Thomas Murray’s new report advocates a shift from periodic compliance checks to ongoing portfolio‑level monitoring of third‑party providers.

Overview of the Report
Thomas Murray, the global risk intelligence and ratings firm, released “Beneath the Asset: Cyber Risk and the Infrastructure Institutions Depend On” on July 27, 2026. The publication marks the second installment in the firm’s flagship Beneath the Asset series, extending its core thesis that asset safety is no longer solely a custody concern but increasingly an infrastructure issue. By analysing recent high‑profile cyber incidents, the report demonstrates how cyber risk has become the dominant pathway whereby weaknesses in supporting infrastructure propagate to an institution’s assets.


Illustrative Cyber Incidents of 2025‑2026
The paper draws on two notable events from 2025 and 2026 to substantiate its argument. First, a ransomware attack on Jaguar Land Rover was modelled at £1.9 billion in UK economic loss—recorded as the most damaging cyber event to date. Second, the Marks & Spencer breach cost the retailer roughly £300 million in lost profit. In both cases, the point of failure lay not within the target’s own defensive perimeter but in a third‑party supplier or an individual with privileged access. This mirrors the pattern identified in Thomas Murray’s inaugural Beneath the Asset report, which traced similar vulnerability chains through custody chains, central securities depositories (CSDs), and post‑trade infrastructure.


Geopolitics and Cyber Risk Convergence
A key finding highlights the merging of geopolitical tension and cyber risk. State‑sponsored actors are increasingly targeting infrastructure directly, creating an additional transmission route alongside traditional vectors such as sanctions and market‑access restrictions. The report cites destructive cyber activity against Iranian banking infrastructure in June 2025 and again in June 2026 as concrete examples. These attacks illustrate how nation‑state motives can disrupt financial systems, amplifying systemic risk for institutions that rely on the compromised infrastructure.


Cyber Risk as the Primary Transmission Mechanism
The analysis concludes that cyber risk now serves as the chief conduit for infrastructure risk to reach institutional assets. When a CSD, custodian, fund administrator, or any of their outsourced providers suffers a compromise, the assets residing on that infrastructure are simultaneously exposed. Consequently, the safety of an institution’s holdings is intrinsically linked to the cyber resilience of its entire dependency network, not just its internal controls.


Where the Critical Exposure Lies
The report stresses that the most consequential exposure exists beyond an institution’s own perimeter. Vulnerabilities reside in custodian sub‑networks, outsourced IT services, cloud platforms, and even help‑desk functions that support core operations. These external touchpoints often lack the same level of security oversight as the institution’s internal environment, creating blind spots that attackers can exploit to cascade damage inward.


Limitations of Current Assessment Tools
Existing risk‑assessment methodologies force practitioners into a false dichotomy: either conduct deep, one‑entity‑at‑a‑time due diligence (which is thorough but infrequent and static) or rely on broad surface‑scanning tools that provide wide coverage but lack contextual depth. Neither approach, on its own, delivers a continuous, defensible view of risk across a portfolio of dependencies. As a result, asset owners and custodians remain vulnerable to emerging threats that evolve between assessment cycles.


Proposed Solution: Continuous, Contextualised Risk Intelligence
Thomas Murray argues that the remedy lies not in performing more due diligence of the same type, but in adopting a continuous, contextualised risk‑intelligence framework. This approach would combine the depth of maturity and control assessments with the scale and timeliness of external attack‑surface monitoring. By maintaining real‑time visibility into the full chain of infrastructure on which assets depend, institutions can detect anomalies, prioritise remediation, and adjust exposure dynamically.


Pathfinder Programme and Industry Collaboration
To operationalise this vision, Thomas Murray is launching a pathfinder programme involving a select group of like‑minded organisations. The initiative aims to test and refine continuous monitoring techniques, share insights, and develop best‑practice standards for managing cyber‑driven infrastructure risk. Further findings and recommendations from the programme are expected to be released in subsequent publications.


Leadership Perspective
Ioan Peters, Managing Director, Cyber Risk at Thomas Murray, encapsulated the report’s message: “Cyber risk has become the fastest‑moving route through which infrastructure failures reach an institution’s assets. The organisations that stay safe will be the ones that stop treating their custodians and providers as a once‑a‑year compliance exercise and start seeing them as a portfolio of risk to be monitored continuously.” This statement underscores the shift from periodic compliance to ongoing, proactive risk management.


About Thomas Murray
Thomas Murray provides risk intelligence and ratings for central securities depositories, custodians, market infrastructures, and financial systems worldwide. With over three decades of experience, the firm assists financial institutions in understanding and managing risks that affect the safety, resilience, and performance of their assets across global markets.


Media Contact
Amie Johnstone
Head of Marketing and Communications, Thomas Murray
[email protected]

This press release was distributed via Reach, the non‑regulatory press release service of RNS, part of the London Stock Exchange.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here