The Weakest Link May Not Be Yours: Third-Party Cyber Risk in an Age of Banking Ecosystems
A large regional bank's own network held. The breach still happened anyway, through a vendor. As First Citizens knits together the vendor and technology ecosystems of several acquired institutions, the question is no longer whether its internal defenses are strong, but how far its view of risk actually extends.
The OCC's Spring 2026 semiannual risk perspective placed cyber risk, fraud, and emerging AI-enabled security threats near the top of its supervisory concerns for the industry. Days later, the point was underlined by real-world events: a large U.S. regional bank disclosed that customer information had been extracted through a third-party vendor in April 2026, even though the bank found no evidence that its own network had been breached. The institution's internal defenses, in other words, worked exactly as intended; customer data left the building anyway.
The pattern is now familiar enough to describe a trend rather than an isolated event: cyber risk in banking has become substantially a third-party and extended-enterprise problem, not primarily an internal information-security one. The effective perimeter a bank must defend no longer ends at its own data center or cloud tenancy; it extends through vendors, cloud and infrastructure providers, data processors, software dependencies, and the fourth and fifth parties those vendors rely on in turn. Regulators are responding by pushing institutions to connect cyber risk, third-party risk, data risk, and operational resilience far more tightly than most risk operating models currently do, precisely because the historical practice of managing each in its own silo leaves exactly the kind of gap that keeps surfacing in these incidents.
A pattern with particular relevance for First Citizens
Few banks have added third-party and vendor complexity as quickly as First Citizens. In the space of roughly three years, the organization has absorbed CIT's specialty commercial-finance technology stack, the core infrastructure and fintech-adjacent vendor relationships that came with Silicon Valley Bank, an institution whose entire client base is technology and venture-capital companies with their own elevated cyber profile, and, pending completion in 2026, the branch and technology footprint of more than 130 BMO locations. Each of those heritage organizations arrived with its own vendor population, its own cloud dependencies, and, quite likely, its own view of which vendors are truly “critical” to the business.
Layered on top of that integration workload, First Citizens has signaled through its planned fourth-quarter 2026 rebrand of the SVB franchise into First Citizens Innovation Banking and First Citizens Fund Banking that it intends to expand further into cryptocurrency, payments, and international banking. Each of those is a business line built almost entirely on third-party infrastructure: custodians and crypto infrastructure providers, payment rails and gateways, correspondent banking relationships abroad. Each will add fourth-party exposure that did not exist in the franchise's more traditional retail and commercial banking businesses.
The bank's own network can be sound and the exposure can still be real. The relevant question shifts from ‘are we secure’ to ‘do we know, across every business we have acquired, which vendors we cannot afford to lose visibility into?’
None of this implies that First Citizens' own security posture is inadequate; the recent incident at a peer regional bank is a reminder that strong internal controls and third-party exposure are not mutually exclusive; a bank can get its own house in order and still inherit risk through the front door of a vendor relationship. The more pointed question is whether First Citizens' view of vendor criticality, fourth-party visibility, and concentration risk has been genuinely consolidated across its heritage organizations, or whether it still reflects four different starting points: legacy North Carolina retail banking, CIT's commercial-finance operations, SVB's innovation-economy footprint, and shortly, BMO's branch infrastructure. A single enterprise-wide register of critical vendors and their downstream dependencies is a very different risk posture than four coexisting ones that happen to sit under the same holding company.
As the bank's ambitions extend into cryptocurrency, cross-border payments, and international banking, each introducing new categories of vendor and counterparty relationships, that question only becomes more pressing. The institutions most exposed in the next cycle of third-party incidents are unlikely to be those with weak internal cyber controls; recent events suggest they will be the ones whose enterprise-wide view of vendor and fourth-party risk didn't keep pace with the speed and breadth of their own growth.
Sources: Office of the Comptroller of the Currency, Semiannual Risk Perspective (Spring 2026); public reporting on a third-party vendor incident affecting a large U.S. regional bank (April 2026).
Is digital and AI delivering what your business needs?
Digital and AI can solve your toughest challenges and elevate your business performance. But success isn’t always straightforward. Where can you unlock opportunity? And what does it take to set the foundation for lasting success?