Celerium Research on the Financial Services Industry
Celerium has spent years working with small and mid-size organizations in the defense and healthcare sectors, where the same pattern holds: the institutions with the fewest resources face the same threats as the largest ones.
We are now researching how that pattern applies to smaller financial institutions.
Small Banks Are Overloaded. Software Vulnerabilities Are Accelerating.
By Vince Crisler, Chief Strategy Officer, Celerium
Small financial institutions are often overloaded by cyber threats. Historical and recent numbers of vulnerabilities make things worse. Patch management becomes a greater challenge. New approaches are needed, and in the era of AI, needed quickly.
Most banks and credit unions in this country run their entire technology operation with a handful of people, and at a lot of them the person responsible for patching is also the person responsible for the help desk, the backups, and whatever the examiner asked for last week. Software vulnerabilities are one line on that list. This year they have been arriving faster than usual.
July 2026 vulnerabilities are double from January and from July 2025
The National Vulnerability Database is the federal catalog of publicly disclosed software flaws, and nearly every vulnerability management program in the country is built on top of it, including most of the ones used by small financial institutions.
Last year ran at roughly 4,000 new entries a month, month after month, which is the grey line below. This year opened at about the same level and then went up.
July brought more than double January and more than double July of last year. The 2026 total passed all of 2025 in the first week of August, with almost five months still to run.
That is a steepening of something that was already steep.
The second chart matters more than the first, because it shows that the institutions were already behind before this year happened to them. The line does not creep. It steps, and it steps without giving anybody notice.
Resource-constrained institutions
We did not come to this from the banking side. Celerium has supplied solutions to the Department of Defense for use with small defense contractors for over seven years. In healthcare we have often supported hospitals with 20 to 300 beds. What those two have in common is that they are overloaded with IT work generally, and they run into the same set of resource constraints:
- They don’t have the budget that large institutions have.
- They don’t have the security tooling large institutions have invested in.
- They don’t have the security experts and threat hunters that large firms have.
- They don’t have the threat feeds and alerting that major firms use.
Community banks and credit unions sit in the same place, for the same reasons. And they carry one more constraint that money would not fix even if they had it. Banking runs on daily settlement and overnight batch, so the window for taking a system down is short, fixed, and already claimed by upgrades, releases and testing. Patching waits in line.
Although vulnerability disclosures are up sharply this year, budgets, tools and staff are not. The gap between them is the problem.
Why accelerated patching can be problematic
The natural response is to patch faster. Compress the testing, shorten the approval chain, get the queue down. It works up to a point, and it stops working before the queue is clear. Six reasons why.
Vendor patches can have errors
A patch is a software change, and software changes break things. Even Microsoft ships bad ones: the March 2026 Windows 11 patches caused trouble across a great many enterprise environments. Patch slowly and you stay exposed. Patch quickly and you cause outages.
Deployment itself creates errors
Rolling a patch across mixed operating systems, application versions, hardware and integration points, without taking the business down, leaves room for misconfigurations, incomplete rollouts, sequencing mistakes and skipped systems. The distance between released and actually applied everywhere is where most of the risk sits.
Interdependencies add more risk
A change to one component often has to be tested against dozens of others, and working out whether it disturbs something downstream is substantial analysis in its own right. Misjudge a dependency and one patch takes down several systems.
Severity scores may not be consistently available
In April 2026 NIST moved the National Vulnerability Database to a risk-based enrichment model, under which an estimated 15 to 20 percent of new entries receive full analysis. The rest are listed with no severity score. A program built on patching the Critical and High items first is now working from a list where most entries carry no rating at all.
AI chaining of vulnerabilities widens what counts as urgent
Severity scores rate flaws one at a time, on the assumption that attackers exploit them one at a time. Research and demonstrations suggest AI systems may increasingly chain lower-severity flaws into working compromise paths. A Medium that combines with two others to reach kernel access behaves, in practice, like a Critical. Which enlarges the set of patches that might matter, from a volume already beyond what most programs absorb.
Discovery now runs faster than patching
Vulnerability discovery increasingly happens in minutes and hours. Patching happens in weeks, across release cycles, testing windows and change control. Those weeks are not slack. They are how reliability gets preserved, and squeezing them only multiplies the five problems above.
None of which argues against patching. It is the first line of defense and there is no substitute for it. But the mismatch is structural, and working harder on the slower side does not close it.
AI-based threats in general are accelerating
In June the heads of the Five Eyes cyber agencies signed a joint statement, The AI Shift in Cyber Risk: Why Leaders Must Act Now. Six agency heads on one page is unusual by itself. Their assessment is that assumptions about cyber risk can now go out of date in months rather than years, and that AI is shortening the time between a vulnerability being discovered and being exploited. Statements of that kind are normally hedged a good deal more.
There is also a demonstration on the record. In July, OpenAI disclosed that two of its models, tested with their usual refusals turned down, found and exploited a flaw nobody knew about, escaped the environment they were meant to be sealed inside, and reached production systems at Hugging Face. Both companies published accounts of it. The models were trying to cheat on a benchmark rather than do harm, but the capability is not in dispute.
Neither is a prediction about community banks. What they establish is that the time between a flaw becoming known and somebody using it is not fixed, and is not moving in a helpful direction.
The bottom line for smaller financial institutions
Vulnerability disclosures keep rising, and the institutions with the least resources to patch them may get to some of the work but not all of it. Meanwhile the agencies watching the increase say the time between a flaw being found and being used is getting shorter. This is a gap that stays open regardless of how well the institution runs its program.
The result is that smaller financial institutions are going to need something in addition to patching. Not instead of it, and not eventually. AI is creating pressure to find and use additional approaches quickly.