Managing Downtime Has Become a Higher Priority for Financial Services Executives

Security Charles Adriaenssens
Downtime is no longer just a priority for technical teams in financial services organisations, it is now recognised as a business risk which has a direct impact on revenue, customer experience and resilience.

Introduction

Downtime can be defined as ‘any period where a system fails to meet its defined service requirements, making it inaccessible or non-functional for its intended users’. And as Charles Adriaenssens, Financial Services Industry Advisor EMEA at Splunk recognises, the time element really matters. The longer an outage lasts, the greater the cost to the organization.

Splunk’s latest research shows just how quickly the cost of downtime is rising. Based on research with around 2,000 executives globally in technology, finance, and marketing roles (including 268 from financial services) the total estimated global cost of downtime reached $600 billion in 2026, a 50% increase from 2024.

Three Key Forces Are Making Downtime Harder To Control

Key takeaways

Splunk’s research identified three key forces driving the impact of downtime in financial services.

  1. The cost of downtime is higher than ever.
  2. Outages are becoming harder to identify and prevent because the technology environment has become more complex.
  3. AI is changing how organisations operate. While it is clearly creating new opportunities, AI is also a new source of downtime that firms need to understand and govern carefully.

As environments become even more complex and the usage of AI continues to grow, it will become even harder to quickly detect issues that cause downtime.

The Cost of Downtime Is Higher In Financial Services

The cost of downtime in financial services is on average $309 million per company. This is the highest among all industries covered. It also showed the greatest increase over the last two years. This suggests that the impact of downtime has been greater in the industry than in others – despite the introduction of operational resilience regulation focused on service availability in many jurisdictions.

The composition of the downtime cost is also changing. Contractual costs and SLA breaches are the largest cost area for financial services organisations, with security-related issues the second largest. Together, those two categories account for more than half of the total downtime cost.

However lost revenue is now the third largest contributor and has seen the greatest increase since our previous research wave of research in 2024. This is significant because lost revenue often reflects customer-facing issues. Customer issues are not just frustrating for those who experience them, but over time they can reduce customer confidence, damage brand integrity and contribute to churn.

In our research, 71% of financial services executives mentioned increased customer expectations for always-on digital services as a reason why downtime has become a greater priority for them. This explains why 83% of financial services executives said reducing downtime was a higher priority than it was 12 months earlier.

Visibility Across The Organisation Is Now Essential

Increasing organisational complexity now extends beyond the technology stack. Monitoring every part of the organisation, as well as the connections between them, is now a key goal. This goes beyond regulated monitoring of critical services. It requires broader organisational visibility to support faster issue identification and response, as well as an improved customer experience.

To reduce downtime organisations need access to all relevant data, so that they can identify incidents and the impact on end customers. Without full visibility, response teams are slower to understand and respond to what is happening and business leaders struggle to assess the true impact on the organisation. A critical enabler here is the ability to produce relevant KPIs that combine business and technical metrics. When data outputs are clear and digestible, downtime becomes easier to discuss, prioritize, and act on.

Charles Adriaenssens notes that organisations are increasingly implementing data platforms to surface these actionable insights for relevant stakeholders. Their goal in doing so is to help both business and technical teams make decisions that minimise downtime impact.

As organisations become more complex - yet still interconnected - multiple teams need to work together to identify the root cause quickly. This is encouraging many organisations to adopt architectures that can support broader data access and analysis from a single data repository.

Charles Adriaenssens describes this type of ‘data fabric’ architecture as ‘a data layer that connects all data assets, making them discoverable, secure, and ready for analysis regardless of origin’. This helps organisations do more than detect a problem. It helps them connect technical signals to customer and business impact, coordinate across functions, and optimise the path to resolution.

AI Is A Significant Opportunity, But Also A New Risk

AI is undoubtably one of the biggest disruptive influences on financial services organisations right now. Organisations are already using AI to address a variety of use cases and further investment remains a priority. Some of the use cases most likely to attract significant investment include AI-driven security and observability. Instead of reacting after customers are affected, this enables organisations to catch issues before they have a negative impact.

But AI is not risk-free. Every financial services organisation participating in our research said that they had already experienced AI-related downtime. For this reason, AI is both part of the solution and part of the problem.

Charles Adriaenssens argues that stricter guidelines and guardrails for agentic observability and security are now required. Keeping humans in the loop is the most effective way to ensure AI does what it is designed to do.

Human Error And Third Party Issues Are A Persistent Source Of Incidents

Human error remains the most common cause of incidents. On average, an organization faces 6.5 cyber incidents and 7.3 infrastructure / application related incidents because of human error each year. That’s 14 incidents in total. Each of which takes on average 10 hours to fix! These figures reinforce why having full organisational visibility matters. When incidents take that long to resolve, being able to harness data to reduce the time taken to identify the root cause of any issue becomes critical.

Third-party risk adds another layer of complexity. Financial services organisations depend on a wide range of third parties to deliver critical services, from niche providers supporting a specific function to cloud service providers running multiple workloads.

More than half of respondents in our research (54%) said they had experienced security incidents from a SaaS provider or a third-party application. This creates a real challenge because getting visibility of third parties is notoriously difficult. In fact, this challenge is so significant that regulators have introduced specific operational resilience requirements for Critical Third Parties (CTPs) alongside requirements that already apply to financial services organizations themselves.

One Hidden Cost Of Downtime Often Goes Unacknowledged

Downtime does not only affect systems and customers. It also creates a significant burden for employees. Almost all executives said they had experienced incidents that took multiple employees to resolve.

Incident response teams sit at the sharp end. When incidents increase in frequency or duration, the effort required to investigate, coordinate, communicate, and recover also grows quickly. The impact this has on employee wellbeing is often overlooked, even though it directly affects how organisations perform during and after an outage. And it has a greater impact than many people realise....

Priorities For Reducing Downtime

The findings of our research point to three clear strategies for financial services organisations looking to minimize downtime.

Financial services organisations that can connect technical insight to business impact using data will be better positioned to respond quickly, protect customer experience, and ultimately strengthen their resilience.

Learn more about how Splunk helps financial services organisations minimise the impact of downtime in our report.

Related Articles

Splunk Security Content for Threat Detection & Response: April Recap
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: April Recap

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security Content Update app.
The 10 Essential Capabilities of a Best-of-Breed SOAR
Security
2 Minute Read

The 10 Essential Capabilities of a Best-of-Breed SOAR

Security orchestration, automation and response (SOAR) tools are here to stay, do you have the best-of-breed SOAR in your security stack?
Addressing CISOs AI Anxieties Through Resilience
Security
10 Minute Read

Addressing CISOs AI Anxieties Through Resilience

Splunk's Paul Kurtz explores how CISOs’ jobs will become more complex as they address AI-driven attacks, automated vulnerability exploitation, battle data poisoning, or deep fakes that make current phishing tactics look quaint.