Financial sector organizations are the most heavily targeted by DDoS attacks and, on average, better protected than most other sectors at the network layer. The gap between network-layer protection and application-layer protection is, however, larger in financial services than in any other sector DDactic has assessed. The reason: financial institutions invest significantly in volumetric DDoS scrubbing (required by regulators and standard in enterprise contracts) while application-layer API hardening has historically been treated as an application security concern rather than a DDoS concern.
The aggregate findings below are derived from DDactic assessments of financial sector organizations including commercial banks, insurance companies, payments processors, and fintech platforms. Individual findings are anonymized; sector patterns are aggregate observations.
Finding 1: Customer Portal APIs Are the Weakest Point
In 82% of financial sector assessments, the customer-facing portal API (the API serving mobile banking applications, online account management, or customer service tools) had the lowest rate limit coverage of any assessed API surface. The pattern is consistent: the public marketing website and the authentication endpoint receive rate limiting attention because they are the most visible external-facing surfaces. The API that actually serves customer transactions often runs without per-endpoint rate limits because it sits behind authentication and is assumed to be protected by session management.
Finding 2: Legacy Systems Expose Unprotected APIs
Financial institutions with on-premises core banking systems commonly expose API endpoints that pre-date modern WAF integration. These endpoints were designed for internal consumption (branch systems, back-office tools) but have been given internet-accessible addresses for partner or mobile app integration without corresponding WAF configuration. DDactic finds these through subdomain enumeration and port scanning that reveals hosts with unusual TLS certificate patterns (self-signed or internal CA) responding on internet-accessible addresses.
Finding 3: DORA Compliance Does Not Guarantee Resilience
The EU Digital Operational Resilience Act (DORA) requires financial entities to perform ICT risk management including measures against network-layer threats. DORA compliance assessments focus on the presence of documented policies, tested incident response procedures, and vendor risk management. They do not require demonstration that API rate limits fire correctly or that origin IPs are not discoverable. DDactic assessments run in parallel with DORA compliance exercises consistently find L7 gaps that are out of scope for the compliance audit.
Finding 4: Third-Party Integrations Expand the Surface
Financial institutions have high numbers of third-party API integrations: payment processors, credit bureaus, fraud detection providers, identity verification services. Each integration adds a surface -- the callback endpoint that accepts webhooks from the third party, the shared API key that both sides use, the IP allowlist that is often wider than necessary. In assessed organizations, third-party integration endpoints represent an average of 23% of the total API surface but have rate limiting coverage approximately half that of first-party API endpoints.
Sector OPI Distribution
Financial sector OPI scores from DDactic assessments have a bimodal distribution: a cluster of scores in the 70-85 range (organizations with mature network-layer protection and some API hardening) and a cluster in the 40-60 range (organizations with network-layer protection but limited application-layer hardening). The sector median is 62. Organizations in the 40-60 range are typically characterized by strong network-layer defenses and weak API coverage -- the pattern described in Finding 1.
Priority Recommendations for Financial Sector CISOs
- Inventory all API endpoints serving customer-facing applications and verify rate limit coverage for each
- Audit for legacy system endpoints with internet-accessible addresses and no WAF coverage
- Review third-party integration endpoints for rate limiting and authentication adequacy
- Run DDactic assessment after each major API deployment or infrastructure change, not just annually
- Include API rate limit coverage as a metric in DORA compliance reporting, even if not explicitly required
Assess Your Financial Services API Surface
DDactic assessments are designed for the financial sector's API complexity and DORA reporting requirements.
Run a Free Scan