OCDE - Cybersecurity and geopolitical risks in financial markets
OCDE - Organización para la Cooperación y el Desarrollo Económico
Descargar PDF
Disponible
Detalles
- Título
- OCDE - Cybersecurity and geopolitical risks in financial markets
- Autor
- OCDE - Organización para la Cooperación y el Desarrollo Económico
- Categoría
- Doctrina
- Área del derecho
- Cumplimiento
- Año
- —
OECD Business and Finance Policy Papers Cybersecurity and geopolitical risks in financial markets No. 1042
CYBERSECURITY AND GEOPOLITICAL RISKS IN FINANCIAL MARKETS © OECD 2026
This work is issued under the responsibility of the Secretary-General of the OECD, and does not necessarily reflect the official views of OECD Member countries. This document, as well as any data and map included herein, are without prejudice to the status of or sovereignty over any territory, to the delimitation of international frontiers and boundaries and to the name of any territory, city or area. The statistical data for Israel are supplied by and under the responsibility of the relevant Israeli authorities. The use of such data by the OECD is without prejudice to the status of the Golan Heights, East Jerusalem and Israeli settlements in the West Bank under the terms of international law.
Photo credits: © gorodenkoff/Getty images.
©
OECD 2026.
Attribution 4.0 International (CC BY 4.0). This work is made available under the Creative Commons Attribution 4 .0 International licence. By using this work, you accept to be bound by the terms of this licence (https://creativecommons.org/licenses/by/4.0/). Attribution – you must cite the work. Translations – you must cite the original work, identify changes to the original and add the following text: In the event of any discrepancy between the original work and the translation, only the text of original work should be considered valid. Adaptations – you must cite the original work and add the following text: This is an adaptation of an original work by the OECD. The opinions expressed and arguments employed in this adaptation should not be reported as representing the official views of the OECD or of its Member countries. Third-party material – the licence does not apply to third-party material in the work. If using such material, you are responsible for obtaining permission from the third party and for any claims of infringement. You must not use the OECD logo, visual identity or cover image without express permission or suggest the OECD endorses your use of the work.
file purporting to be the resume of a job applicant and, from there, the ransomware encr ypted the master file table that serves as a roadmap for the hard drive, making the data on the computer unrea chable. The victim was then asked to make a Bitcoin payment to get the hard drive decrypted. What seemed to be a new version of Petya spread quickly in June 2017. 5 Any cross-border information-sharing arrangement should, however, be designed s ubject to domestic legal, supervisory confidentiality, and data-protection constraints, with appropriate c ollaboration between the IMF and FSB. 6 To support preparedness, the G7 Fundamental Elements of Cyber Exercise Progra mmes provide a structured framework for multi‑year, cross‑stakeholder cyber incident simulations that help financial entities assess and improve their response and recovery capabilities. 7 While risk premia are commonly decomposed into equity, liquidity, and credit components, the discussion here focusses on the credit‑risk channel, which is most relevant for the real‑economy transmission of cyber shocks. Credit premia are particularly sensitive to disruptions affecting SMEs an d supply‑chain partners, as these firms typically operate with thinner cash buffers, weaker collateral positions, a nd higher baseline credit risk. Cyber incidents can therefore amplify borrowing costs or restrict credit access for smaller suppliers, generating spillovers along supply chains and magnifying macro ‑financial vulnerabilities. NotesOECD Business and Finance Policy Papers Cybersecurity and geopolitical risks in financial markets No. 104 Cyber incidents are escalating in magnitude, sophistication and geopolitical relevance, exposing critical weaknesses in the global financial system. This paper highlights three mutually reinforcing vulnerabilities: supply chain/third-party exposure, heightened systemic risk in rapidly digitalising developing regions, and strong timing effects that amplify shocks during market stress. The paper also recognises that cybersecurity extends beyond a purely technical concern and has broader macro-financial and economic-security implications. Finally, the paper emphasises a set of measures for financial firms and financial sector supervisors to contain propagation channels, safeguard confidence and reinforce financial stability.
Third-party material – the licence does not apply to third-party material in the work. If using such material, you are responsible for obtaining permission from the third party and for any claims of infringement. You must not use the OECD logo, visual identity or cover image without express permission or suggest the OECD endorses your use of the work. Any dispute arising under this licence shall be settled by arbitration in accordance with the Permanent Court of Arbitration (PCA) Arbitratio n Rules 2012. The seat of arbitration shall be Paris (France). The number of arbitrators shall be one.
Disclaimers 3
CYBERSECURITY AND GEOPOLITICAL RISKS IN FINANCIAL MARKETS © OECD 2026
Cyber incidents are escalating in magnitude, sophistication and geopolitical relevance, exposing critical weaknesses in the global financial system. This paper highlights mutually reinforcing vulnerabilities: supply chain/third-party exposure, and heightened systemic risk in rapidly digitalising emerging market and developing economies. The paper also recognises that cybersecurity extends beyond a purely technical concern and has broader macro-financial and economic-security implications. Finally, the paper emphasises a set of measures for financial firms and financial sector supervisors to contain propagation channels, safeguard confidence and reinforce financial stability. This paper is part of the series “OECD Business and Finance Policy Pap ers”, or https://doi.org/10.1787/bf84ff64-en.
Abstract4
CYBERSECURITY AND GEOPOLITICAL RISKS IN FINANCIAL MARKETS © OECD 2026
This report examines the rising frequency and complexity of cybersecurity incidents and their imp lications for global financial markets, with a focus on how cyber and geopolitical risks intersect through supply chains and shared digital infrastructure. It draws on examples from ASEAN economies and beyond and provides policy considerations to strengthen baseline security, third-party oversight , regional co-operation and forward-looking assessments, with a view to reduce infrastructure fragility, maintain market confidence and protect financial stability. The paper is an output of the OECD Committee on Financial Markets. The paper benefited from comments
policy considerations to strengthen baseline security, third-party oversight , regional co-operation and forward-looking assessments, with a view to reduce infrastructure fragility, maintain market confidence and protect financial stability. The paper is an output of the OECD Committee on Financial Markets. The paper benefited from comments from delegates to the Committee on Financial Markets, OECD colleagues, incl uding from the Directorate for Science, Technology and Innovation, and stakeholders, including the Economic Res earch Institute for ASEAN and East Asia (ERIA), and academia. The report was prepared by the Capital Markets and Financial Institutions Division of the OECD Directorate for Financial and Enterprise Affairs. It has been prepared by Masayoshi Chida, under the supervision of Fatos Koc, Head of the Financial Markets Unit, and Serdar Çelik, Head of Division. The author is grateful for the support of Kentaro Ogata (Ministry of Finance of Japan ), Tomoyuki Omori (Permanent Delegation of Japan to the OECD), and the Government of Japan for providing funding to this work. Foreword 5
CYBERSECURITY AND GEOPOLITICAL RISKS IN FINANCIAL MARKETS © OECD 2026
Table of contents Disclaimers 2
Abstract 3 Foreword 4 Executive summary 7 1 Introduction 9 2 Landscape of cyber incidents 11 2.1. Compositional shift in cyber incidents among supply chain and financial institutions 12 2.2. Security holes and cyber vulnerabilities 13 3 Emerging geopolitical risks and cybersecurity in supply chains 15 3.1. Shifts in motivations and actors 15 3.2. Geopolitical landscape and strategic targeting 17 3.3. Geopolitical risks and cyber incidents 18 3.4. Global cybersecurity and supply chain 19 3.5. Economic security considerations and broader market confidence 20 4 Cyber-attacks and damage analysis 23 4.1. Layered dimensions of damage 23 4.2. Systemic effects and contagion risks 23 4.3. Early warning system, stress testing and modelling techniques 24
3.5. Economic security considerations and broader market confidence 20 4 Cyber-attacks and damage analysis 23 4.1. Layered dimensions of damage 23 4.2. Systemic effects and contagion risks 23 4.3. Early warning system, stress testing and modelling techniques 24 4.4. Emerging technology and cyber shock analysis 24 5 Policy implications 27 5.1. Enhancing international co-operation 27 5.2. Private sector engagement and public-private partnerships 27 5.3. Third-party Issues among financial institutions 28 5.4. Strengthening monitoring and evaluation 286
CYBERSECURITY AND GEOPOLITICAL RISKS IN FINANCIAL MARKETS © OECD 2026
References 29 Annex A. Typology of cyber risks in the financial system and selected examples 37 Annex B. Supply chain vulnerabilities and systemic risks in ASEAN 39 Annex C. Cyber regulatory framework in ASEAN 42 Annex D. Credit risk premium and stress analysis 46 Notes 48
FIGURES Figure 1. Number of cyber incidents across G7 countries 12 Figure 2. Breakdown of cyber incidents in G7 countries 13 Figure 3. Intersection of three drivers of cyber vulnerabilities 14 Figure 4. Crypto hacking activity by year: Total value stolen and number of incidents (2015-2024) 16 Figure 5. Number of cyber incidents 18 Figure 6. Geopolitical risks and cyber incidents across OECD countries 19 Figure 7. Financial institutions: rising third-party (vendor) exposure in cyber incidents 20 Figure 8. Share of cyber incidents by region 22
Figure A B.1. Breakdown of cyber incidents across ASEAN member states 39 Figure A B.2. Cybersecurity survey in ASEAN 40 Figure A D.1. Credit risk premium amplification due to banking cyber risks and during market stress periods among G7 countries 47
TABLES Table A C.1. Cybersecurity regulatory frameworks across ASEAN jurisdictions 45 7
Figure A D.1. Credit risk premium amplification due to banking cyber risks and during market stress periods among G7 countries 47
TABLES Table A C.1. Cybersecurity regulatory frameworks across ASEAN jurisdictions 45 7
CYBERSECURITY AND GEOPOLITICAL RISKS IN FINANCIAL MARKETS © OECD 2026
Cyber threats are growing in scale, sophistication and geopolitical impact, exposing critical weaknesses in the global financial system. Three interlinked risks stand out: supply chai n and third ‑party vulnerabilities, rising systemic exposure in developing regions experiencing rapid digitalis ation, and timing effects that intensify shocks during market stress. Cybersecurity is no longer merely a technical concern. At the same time, many jurisdictions are actively advancing measures to improve cyber r esilience and mitigate emerging cyber risks. Supply chain risk is increasingly the dominant transmission channel, and small and medium-sized enterprises (SMEs) are the weakest link Attackers are shifting towards indirect access routes by exploiting smaller supp liers, vendors and service providers with lower cyber maturity. In G7 economies, cyber incidents affecting SMEs increased more than fourteenfold between 2021Q1 and 2025Q1, and in recent years SMEs have recorded more incidents than banks. However, even well ‑defended financial institutions remain exposed through information and communications technology (ICT) suppliers and other third parties embedded in core business processes. Emerging markets face elevated systemic risk due to rapid digitalisation combined with uneven cyber maturity Emerging markets that are digitising quickly can experience a structural rise in exposure when governance, skills and regulatory enforcement do not keep pace with technology adoption. As ian emerging markets stands out because of ( i) very high SME prevalence (over 99% of firms), (ii) fast growth in digital f inance and cross ‑border connectivity, and (iii) an emerging role in certain cyber ‑enabled financial crime ecosystems. These conditions increase the likelihood that intrusions propagate acr oss borders, vendors, platforms and value chains, turning localised incidents into regional disruption s that undermine market
and cross ‑border connectivity, and (iii) an emerging role in certain cyber ‑enabled financial crime ecosystems. These conditions increase the likelihood that intrusions propagate acr oss borders, vendors, platforms and value chains, turning localised incidents into regional disruption s that undermine market trust. These vulnerabilities do not arise only from newer digital tools: legacy systems, weak interfaces between older and newer platforms, and outdated governance arrangements can also create materi al cyber and operational risks. Cyber shocks could amplify financial stress and reprice credit risk Market‑based evidence in the paper indicates that credit risk premia could increase more than fivefold during market stress and peak when systemic stress coincides with bank ‑focussed cyber activity. This non‑linearity implies that cyber incidents are especially destabilising when the y occur in fragile market states, when liquidity is tight, risk aversion is elevated, and confidence is more easily impaired , thereby reinforcing adverse feedback loops between operational disruption and financial conditions. The growing concern of cyber threats arising from advances in AI is also evident. Taken together, these patterns show that cyber risk can become systemic under certain ci rcumstances: it can spread through common third ‑party dependencies, concentrated critical services, and tightly connected financial and operational networks; it can interact with market stress and confi dence effects; and, in severe cases, it can spill over between the financial sector and the real economy. To limit the spread of cyber attacks safeguard confidence and reinforce financial stabi lity, the paper emphasises a set of possible measures for financial firms and financial sector supervisors: Executive summary8
CYBERSECURITY AND GEOPOLITICAL RISKS IN FINANCIAL MARKETS © OECD 2026
- Raise baseline cyber hygiene at scale, prioritising common “security holes” (patching, configuration hardening, access controls, monitoring, and tested backup/recovery), with a strong focus on high‑risk nodes such as SMEs and critical vendors. • Strengthen third‑party and supply ‑chain risk management in the financial sector for critical thirdhardening, access controls, monitoring, and tested backup/recovery), with a strong focus on high‑risk nodes such as SMEs and critical vendors. • Strengthen third‑party and supply ‑chain risk management in the financial sector for critical thirdparty services, including due diligence, contractual security requirements, conti nuous monitoring, and resilience and exit planning. • Enhance cross ‑border co-ordination and trusted information ‑sharing, recognising that cyber incidents propagate across jurisdictions and that effective response depends on timely, actionable and credible information exchange between authorities and market participants. • Enhance SME-focussed support, with particular attention to developing countries , by lowering compliance costs, addressing skills gaps and scaling practical support mechani sms, while promoting risk-based approaches, simplified regulatory frameworks and the use of stan dards and market-based incentives, underpinned by principles of shared responsibility and mutual trust, to strengthen cybersecurity and resilience. • Invest in ex‑ante assessment tools, while including stress testing, scenario analysis and evaluation mechanisms, and, where appropriate, consider a secure regional data centre to support data collection, oversight and preparedness.
In an era where cyber and geopolitical risks increasingly interact through supply chains and shared digital infrastructure, strengthening baseline security, third ‑party oversight, regional co-operation, and forward‑looking assessment capabilities are essential to reduce systemic fragility, mai ntain market confidence and protect financial stability. 9
CYBERSECURITY AND GEOPOLITICAL RISKS IN FINANCIAL MARKETS © OECD 2026
Global financial markets are undergoing a transformative digitalisation era. The most consequential shift for financial stability lies in the digitalisation of core financial act ivities – including payments, banking, customer communication and outsourced IT services. These changes have led to efficien cy gains, new products and services, and broader access, but they have also expanded the cyber and operational threat surface, from phishing and ransomware to disruptions affecting critical thirdparty services and outdated internal systems (OECD, 2022 [1]). As geopolitical tensions rise, particularly following Russia’s war of
products and services, and broader access, but they have also expanded the cyber and operational threat surface, from phishing and ransomware to disruptions affecting critical thirdparty services and outdated internal systems (OECD, 2022 [1]). As geopolitical tensions rise, particularly following Russia’s war of aggression against Ukraine , cyber incidents have surged, with operations driven by state and non-state actors targeting financial institutions to exert strategic pressure or reap illicit profits. The consequences are multifaceted: cyber-attacks compromise proprietary data, disrupt essential payment sy stems, trigger operational breakdowns, and erode trust which is a cornerstone of stable financial markets (FSB, 2024[2]). The digital economy’s growing reliance on interconnected platforms amplifies these risks, requiring concerted policy responses and international regulatory co-operation. Financial institutions, financial market infrastructures (FMIs), and non-bank fi nancial intermediaries are increasingly interconnected, sharing data and operational resources across borde rs. Network-based macro models suggest that shocks to a small set of central nodes can generate outsized aggregate effects, even when the initial disruption appears local (Acemoglu et al., 2012 [3]; Eisenbach, Kovner and Lee, 2022[4]). This interdependence elevates systemic risk, as a successful breach of one node can cascade through the entire network (FSB, 2023[5]). Concentration in shared technology providers (e.g. cloud and core IT vendors) can further turn operational outages into common shocks affecting many institutions simultaneously (Kot idis and Schreft, 2025 [6]). Emerging financial technologies and products , such as central bank digital currencies (CBDCs), crypto and digital asset platforms, tokenised securities, and quantum computing , further complicate the threat landscape (OECD, 2024 [7]). As digital assets become more institutionalised and attract growing interest from institutional investors, the potential for spillovers and contagion between dec entralised finance and the traditional financial system increases (OECD, 2022[8]). While attackers continually refine their methods, AI-enabled malware or social engineering phishing methods adapt to undermine or manipulate financial
from institutional investors, the potential for spillovers and contagion between dec entralised finance and the traditional financial system increases (OECD, 2022[8]). While attackers continually refine their methods, AI-enabled malware or social engineering phishing methods adapt to undermine or manipulate financial systems. Internet-of-Things (IoT) devices can become platforms for distributed denialof-service (DDoS) attacks, and quantum-based intrusion may in the future bypass encryption methods used to protect financial data, with recent research highlighting particular vulnerabilities within certain blockchain systems (Babbush et al., 2026[9]). Geopolitical tensions increasingly shape the incentives for disruptive cy ber operations, and in some contexts, expand the scope and co-ordination of such attacks in and around the financial system. In periods of heightened geopolitical stress, strategically motivated campaigns can overlap with financially motivated cybercrime, with attacks timed around sanctions, major negotiations, or other geopol itical events (Crosignani, Macchiavelli and Silva, 2023 [10]). By targeting cross-border payment networks, clearing and settlement systems, and trade finance platforms, such operations can disrupt liquidity flows and capital mobility, and undermine market confidence. In this sense, cybersecurity in financ e is no longer merely a technical or compliance issue; it has become intertwined with international security and diplomatic strategy, with evidence suggesting that cyber incident activity may move in parallel with geopolitical risk across some periods (IMF, 2024[11]). 1 Introduction10
CYBERSECURITY AND GEOPOLITICAL RISKS IN FINANCIAL MARKETS © OECD 2026
Supply chains and third ‑party provider dependencies represent a significant attack surface and transmission channel.1 Adversaries can compromise smaller vendors or service providers to reach l arger institutions, and disruptions can propagate widely when critical inputs are difficul t to substitute. This dynamic mirrors well-documented mechanisms in production networks: when firms rely on very specific inputs and are tightly interconnected, shocks originating at a single node can spread through the network
institutions, and disruptions can propagate widely when critical inputs are difficul t to substitute. This dynamic mirrors well-documented mechanisms in production networks: when firms rely on very specific inputs and are tightly interconnected, shocks originating at a single node can spread through the network and amplify losses elsewhere (Acemoglu et al., 2012[3]; Carvalho, 2014[12]; Barrot and Sauvagnat, 2016[13]). In the cyber domain, this amplification has been illustrated by incidents such as the NotPetya ransomware cyberattacks in 2017, where indirect supp ly-chain spillovers substantially exceeded direct damages, and by more recent operational disruptions at concentrated technology providers that tested r esilience and market confidence (Kamiya et al., 2021 [14]; FCA, 2024 [15]). For the ASEAN region and Asia more widely, which is deeply integrated in cross-border value chains, these dynamics el evate cyber resilience into an economic-security issue: trusted digital security increasingly supports investor confidence and investment decisions by reducing operational uncertainty in trade, logistics, and financial intermediation (ASEAN-BAC, 2025[16]). 11
CYBERSECURITY AND GEOPOLITICAL RISKS IN FINANCIAL MARKETS © OECD 2026
Cyber-attacks against the financial sector have increased markedly in both freq uency and sophistication over the past two decades, with new and increasingly complex attack typologies emerging. Whereas early incidents often relied on relatively simple phishing schemes or malware emb edded in email attachments, threat actors now deploy a much broader and more advanced arsenal of tools and tactics. Adva nced persistent threats (APTs) conducted by organised cybercriminal groups and, in some cases, state ‑linked actors, and ransomware-as-a-service platforms have become commonplace, reflecting a mature , specialised, and highly lucrative cybercriminal ecosystem (IMF, 2024 [11]; BIS, 2021 [17]). The growing use of AI-enabled attacks further amplifies these risks, allowing malicious actors to dynami cally adapt to
actors, and ransomware-as-a-service platforms have become commonplace, reflecting a mature , specialised, and highly lucrative cybercriminal ecosystem (IMF, 2024 [11]; BIS, 2021 [17]). The growing use of AI-enabled attacks further amplifies these risks, allowing malicious actors to dynami cally adapt to institutional defences. At the same time , sophisticated malware can remain dormant within systems for extended periods, enabling attackers to time disruptions for maximum financial or operational impact. As the threat landscape continues to evolve, cyber resilience measures are also evolving in response. Private cybersecurity firms are increasingly working in close co-ordination with governments and law enforcement agencies to detect, attribute and disrupt malicious campaigns. Although there is often overlap between financially motivated cybercrime and geopolitically driven operations, this convergence has been met with a parallel increase in public-private collaboration in cybersecurity. Inform ation-sharing initiatives and co-ordinated incident response mechanisms are becoming more widespread, strengthening the overall resilience of the financial ecosystem. This growing alignment between priv ate and official sector countermeasures underscores a broader shift towards collective cybersecurity as both att ackers and defenders become more sophisticated. The number of cyber incidents across G7 countries has increased during the las t two decades (Figure 1 ) Most incidents took place in the United States, followed by countries in Europe. It is likely that cyber incidents in G7 countries were mainly carried out for financial gain, with around 20% of cyber-attacks targeting financial institutions in the past two decades (IMF, 2024 [11]). Recent geopolitical risks and the widespread introduction of advanced artificial intelligence (e.g. Generative AI) may have caused the growth in cyber-attacks. Recently, there have been more frequent incidents related to supply chai n disruptions in manufacturing industries, showing that cyber risks can also pose operational and infras tructure risks (Crosignani, Macchiavelli and Silva, 2023 [10]).2 Cross-country comparisons should be interpreted with caution, as incident disclosure, media visibility and dataset coverage differ mater ially across jurisdictions. Higher counts may therefore reflect both underlying risk and differences in reporting and public visibility.
(Crosignani, Macchiavelli and Silva, 2023 [10]).2 Cross-country comparisons should be interpreted with caution, as incident disclosure, media visibility and dataset coverage differ mater ially across jurisdictions. Higher counts may therefore reflect both underlying risk and differences in reporting and public visibility. 2 Landscape of cyber incidents12
CYBERSECURITY AND GEOPOLITICAL RISKS IN FINANCIAL MARKETS © OECD 2026
Figure 1. Number of cyber incidents across G7 countries
Note: The Cyber Events Database collects publicly available information on cyber events from 2014 onwards. It was created to address the lack of consistent, well-structured data necessary for making strategic decisions ab out how to invest resources to prevent and respond to cyber events. The most recent months may be subject to reporting lags and should be interpreted with caution.
Source: Based on Cyber Events Database (
https://cissm.umd.edu/cyber-events-database), Center for International and Security Studies at Maryland, and OECD calculations. Moreover, the cyber threat surface has expanded dramatically, including through the growing reliance on shared service providers such as cloud infrastructure. Disruptions at a critical fi nancial service provider can create simultaneous operational stress across multiple institutions, es pecially where substitution is difficult and recovery takes time. At the same time, these risks are not limited to cloud-based environments: legacy systems, weak interfaces between older and newer platforms, and poorly governed internal architecture can also create serious cyber and operational vulnerabilities. Lar ge technology providers are nevertheless widely used because they often offer scale, security expertise, and resil ience investments that many firms cannot replicate on their own. The policy challenge is therefo re to manage common dependencies and governance weaknesses, not simply to treat concentration itself as inherently problematic. 2.1. Compositional shift in cyber incidents among supply chain and financial institutions Beyond overall growth in incident frequency, Figure 2 suggests a sectoral shift in cy ber incidents in G7 countries. Incident counts are low and constant in the early 2000s, but bank-related inci dents become
2.1. Compositional shift in cyber incidents among supply chain and financial institutions Beyond overall growth in incident frequency, Figure 2 suggests a sectoral shift in cy ber incidents in G7 countries. Incident counts are low and constant in the early 2000s, but bank-related inci dents become highly volatile and dominate the mid-2000s to mid-2010s, with at least one distinct spike. From the late 2010s onwards, the composition shifts: SME incidents rise strongly and in the most recent years often exceed bank incidents, while large-firm incidents increase more moderately. 3 Overall, the pattern is consistent with cyber risk broadening from episodic, through supply chain to wider targeting where smaller firms represent an increasingly large share of observed incidents. The growth in SME incidents could therefore reflect attackers’ targeting of weaker links and third-party dependencies. Even with strong internal controls, the “weakest link” is frequently a supplier/partner with lower cyber maturit y, especially smaller suppliers, making supply chain/third ‑party vulnerabilities a leading cyber-resilience challenge (WEF, 2026[18]). 0 20 40 60 80 100 120 140 160 Number of cyber incidents USA Other G7 Countries 13
CYBERSECURITY AND GEOPOLITICAL RISKS IN FINANCIAL MARKETS © OECD 2026
Figure 2. Breakdown of cyb