Rankiteo Logo
Rankiteo

The Rankiteo MCP server is now available.

Discover MCP
!

Top 100 Worst Banking Companies

Identify the lowest-scoring Banking companies with 3,000+ employees. Understand where critical cyber risk exposure exists in this industry. 93 companies scored.

393
Companies in Industry
93
Scored
767.6
Avg Score
66
Cyber Incidents
Bottom 93
Shown

Banking Cybersecurity Risk Assessment - Lowest-Scoring Companies in 2026

Out of 393 banking companies with 3,000+ employees monitored by Rankiteo, this page highlights the Bottom 93 organizations with the weakest cybersecurity posture. These rankings are based on our proprietary Cyber Resilience Score, which integrates time-decayed incident exposure, sector-sensitive impact analysis, and market-cap-aware baseline and dampening to produce a single, interpretable score between 100 and 1,000.

Companies at the bottom of this ranking carry the heaviest accumulated cyber incident burden - including recent or severe ransomware attacks, data breaches with significant financial losses or records exposed, and repeated disclosure events. Their scores are further influenced by sector-specific impact multipliers that amplify penalties in high-criticality industries. Understanding where these risk concentrations exist is essential for supply chain risk management, regulatory compliance, and competitive benchmarking within the banking industry.

The current average score for Banking companies with 3,000+ employees is 767.6 out of 1,000. Companies shown below score significantly lower than this average, falling far behind an industry that generally maintains reasonable security standards.

Risk Highlights

844
Lowest Score
767.6
Industry Average
8%
Scoring B or Below
66
Recorded Incidents
AI Analysis

Cyber Risk in Banking

Generating industry analysis...

Score Distribution

Aaa
0 (0.0%)
Aa
0 (0.0%)
A
16 (17.2%)
Baa
63 (67.7%)
Ba
7 (7.5%)
B
1 (1.1%)
Caa
5 (5.4%)
Ca
1 (1.1%)
C
0 (0.0%)
#CompanyLabelScoreBandIncidentsScore Bar
1
KeyBankkey.com
Commercial Banking583Ca6
2
Western Alliance Bankwesternalliancebancorporation.com
Commercial Banking603Caa2
3
Desjardinsdesjardins.com
Commercial Banking626Caa3
4
Flagstar Bankflagstar.com
Commercial Banking629Caa5
5
Arvest Bankarvest.com
Commercial Banking632Caa3
6
QNB Groupqnb.com
Commercial Banking649Caa2
7
Webster Bankwebsterbank.com
Commercial Banking679B1
8
Monzo Bankmonzo.com
Commercial Banking703Ba1
9
DBS Bankdbs.com
Commercial Banking704Ba2
10
Banco PANbancopan.com.br
Commercial Banking725Ba1
11
Banortebanorte.com.mx
Commercial Banking733Ba1
12
YES BANKbank.in
Commercial Banking739Ba1
13
BancoEstadobancoestado.cl
Commercial Banking743Ba2
14
Zions Bancorporationzionsbancorporation.com
Commercial Banking749Ba2
15
TSB Banktsb.co.uk
Commercial Banking754Baa2
16
IndusInd Bankbank.in
Commercial Banking760Baa1
17
Caisse d’Epargnecaisse-epargne.fr
Commercial Banking761Baa1
18
Crédit Mutuelcreditmutuel.com
Commercial Banking762Baa1
19
PUNJAB & SIND BANKpsbindia.com
-762Baa0
20
Pinnacle Financial PartnersPNFP.com
Commercial Banking763Baa0
21
UOBuobgroup.com
Commercial Banking763Baa1
22
Keystone Bank Limitedlinktr.ee
Commercial Banking764Baa0
23
Bandhan Bankbank.in
Commercial Banking765Baa0
24
Bank Internasional Indonesiabii.co.id
Commercial Banking765Baa0
25
Central Bank of Nigeriacbn.gov.ng
Commercial Banking765Baa0
26
Meezan Bank Limitedmeezanbank.com
Commercial Banking765Baa0
27
HypoVereinsbank - UniCredit - Deutschlandhvb.de
Commercial Banking766Baa0
28
Mobilize Financial Servicesmobilize-fs.com
Commercial Banking766Baa0
29
ABBabb-bank.az
Commercial Banking766Baa0
30
Bank of Ceylonboc.lk
Commercial Banking767Baa0
31
Hatton National Bank PLChnb.lk
Commercial Banking767Baa0
32
La Banque Postalelabanquepostale.com
Commercial Banking767Baa1
33
KBZ Bankkbzbank.com
Commercial Banking768Baa0
34
ASB Bankasb.co.nz
Commercial Banking769Baa0
35
Raiffeisen Bank Romaniaraiffeisen.ro
Commercial Banking770Baa0
36
Silicon Valley Banksvb.com
Commercial Banking770Baa0
37
Union Bank of Nigeriaunionbankng.com
Commercial Banking770Baa0
38
Bank Millenniumbankmillennium.pl
Commercial Banking771Baa0
39
Banco Bradescobanco.bradesco
Commercial Banking771Baa2
40
First City Monument Bank Limitedfcmb.com
Commercial Banking771Baa0
41
Alpha Bankalpha.gr
Commercial Banking772Baa0
42
NatWestnatwest.com
Commercial Banking772Baa0
43
VakıfBankvakifbank.com.tr
Commercial Banking772Baa0
44
Credem Bancacredem.it
Commercial Banking773Baa0
45
BNP Paribas Fortisbnpparibasfortis.be
Commercial Banking774Baa0
46
Crédit Agricole Italiacredit-agricole.it
Commercial Banking774Baa0
47
OCBC Indonesiaocbc.id
Commercial Banking776Baa0
48
Santander Bank, N.A.santanderbank.com
Commercial Banking776Baa0
49
CIB Egyptcibeg.com
Commercial Banking777Baa0
50
Federal Bankfederalbank.co.in
Commercial Banking777Baa1
51
Philippine National Bankpnb.com.ph
Commercial Banking777Baa0
52
ICICI Bankbank.in
Commercial Banking778Baa2
53
SABsab.com
Commercial Banking779Baa0
54
Bank of the Philippine Islands (BPI)bpi.com.ph
Commercial Banking779Baa0
55
Industrial and Commercial Bank of Chinaicbc.com.cn
Commercial Banking779Baa0
56
Yapı Krediyapikredi.com.tr
Commercial Banking779Baa0
57
LCLlcl.fr
Commercial Banking780Baa0
58
Banco de Occidentebancodeoccidente.com.co
Commercial Banking781Baa0
59
Santander Argentinasantander.com.ar
-781Baa0
60
ALEXBANKalexbank.com
Commercial Banking781Baa0
61
Türkiye İş Bankasıisbank.com.tr
Commercial Banking782Baa0
62
Akbankakbank.com
Commercial Banking783Baa0
63
CIMB Niagacimbniaga.co.id
Commercial Banking783Baa0
64
Arab Bankarabbank.com
Commercial Banking784Baa0
65
Comerica Bankcomerica.com
Commercial Banking784Baa0
66
Security Bank Corporationsecuritybank.com
Commercial Banking784Baa0
67
ING Polanding.pl
Commercial Banking788Baa0
68
Banamexbanamex.com
Commercial Banking789Baa0
69
Santander Bank Polskasantander.pl
-790Baa0
70
Intesa Sanpaolointesasanpaolo.com
Commercial Banking791Baa1
71
Julius Baerjuliusbaer.com
Commercial Banking791Baa0
72
Santander Chilesantander.cl
Commercial Banking791Baa0
73
Union Bank of Indiabank.in
Commercial Banking791Baa0
74
UniCreditunicreditgroup.eu
Commercial Banking794Baa4
75
Bank of Irelandbankofireland.com
Commercial Banking795Baa0
76
ADIB - Abu Dhabi Islamic Bankadib.ae
-796Baa0
77
National Bank of Egypt (NBE)nbe.com.eg
Commercial Banking796Baa0
78
Santandersantander.com
Commercial Banking800A1
79
Capiteccapitecbank.co.za
Commercial Banking801A0
80
Axis Bankaxisbank.com
Commercial Banking803A1
81
Handelsbankenhandelsbanken.com
Commercial Banking804A0
82
RBCrbc.com
Commercial Banking808A1
83
Santander Brasilsantander.com.br
Commercial Banking811A0
84
Bank of Americabankofamerica.com
Commercial Banking812A5
85
Emirates NBDemiratesnbd.com
Commercial Banking812A1
86
First Abu Dhabi Bank (FAB)bankfab.com
Commercial Banking815A0
87
Societe Generalesocietegenerale.com
Commercial Banking816A1
88
Alfa-Bankalfabank.ru
Commercial Banking817A1
89
Credit Suissecredit-suisse.com
Commercial Banking819A4
90
HDFC Bankhdfcbank.com
Commercial Banking820A2
91
Sberbanksber.ru
Commercial Banking822A0
92
China Merchants Bankcmbchina.com
Commercial Banking831A0
93
State Bank of Pakistan (SBP)sbp.org.pk
Commercial Banking844A0

How Cyber Risk Scores Are Calculated

Rankiteo's Cyber Resilience Score produces a single value between 100 and 1,000 for each organization, where higher scores indicate lower estimated cyber risk. The framework integrates three principal components that together balance evidence, context, and comparability across industries and company sizes. Learn more in our AI Cyber Score methodology.

Core Scoring Components

  • Time-Decayed Incident Exposure (Pinc): Every confirmed cyber incident - ransomware, data breach, cyber attack, or disclosed vulnerability - contributes a penalty weighted by recency and scaled by quantitative severity (financial loss and records exposed). Category-specific base weights reflect real-world impact: ransomware (100 pts), data breach (60 pts), cyber attack (20 pts), and vulnerability (5 pts). Each category decays at a different rate - roughly 3 years for ransomware and data breaches, 2 years for cyber attacks, and 18 months for vulnerabilities - so older, lower-impact events fade while recent, severe incidents retain lasting influence.
  • Sector-Sensitive Impact Multipliers: Identical incidents carry different weight depending on the industry. Each NAICS sector receives multipliers based on four dimensions: safety-of-life risk, service continuity, regulatory/legal exposure, and data sensitivity. A ransomware attack on a hospital or utility carries a higher penalty than the same attack on a retail company, reflecting the greater real-world consequences.
  • Market-Cap Baseline & Dampening: A logistic baseline between 750 and 850 anchors each company's starting score based on organizational size. A continuous dampening factor attenuates incident penalties for very large firms, recognizing higher disclosure rates and greater absorption capacity - without masking genuinely severe events.
  • Industry Adjustment (Aind): A bounded additive term derived from NAICS-level historical incident-rate z-scores. This rewards companies in historically resilient sectors, but only when they maintain a clean or near-clean record. Once material incidents occur, firm-specific performance dominates.
  • Quantitative Severity Scaling: When financial loss or records-exposed data is available, incident penalties are amplified proportionally - scaled relative to market capitalization so the same dollar loss has a larger effect on a smaller firm. The combined severity multiplier caps at 3×.
  • Ransomware Recurrence Escalation: Repeated ransomware events trigger a bounded recurrence multiplier (up to 1.5×), reflecting elevated systemic risk from persistent adversarial footholds or remediation failures.

Understanding the Risk Bands

Each score maps to a letter-grade band. Companies appearing in this lowest-scoring ranking typically fall in the bottom bands:

  • Aaa (900–1,000): Exceptional cyber resilience - very few companies in a worst list reach this level.
  • Aa (800–899): Very strong security posture with minimal weaknesses.
  • A (700–799): Strong practices with some areas for improvement.
  • Baa (600–699): Adequate protection but notable security configuration gaps exist.
  • Ba (500–599): Below average - multiple risk areas require attention.
  • B (400–499): Weak security with significant exposure across categories.
  • Caa (300–399): Very weak with a high probability of exploitable vulnerabilities.
  • Ca (200–299): Critically poor with severe, widespread security gaps.
  • C (0–199): Extreme risk - immediate remediation is needed across all dimensions.

Why Monitoring Low-Scoring Banking Companies Matters

Cybersecurity risk doesn't exist in isolation. If your organization works with, purchases from, or shares data with companies in the banking sector, their security weaknesses become your risk. Supply chain attacks - where adversaries compromise a less-secure vendor to reach a larger target - have become one of the most common and damaging attack vectors in recent years.

By identifying the lowest-scoring banking companies, procurement teams, risk managers, CISOs, and compliance officers can:

  • Flag third-party vendors that may introduce unacceptable risk into the supply chain.
  • Require cybersecurity improvement plans as part of vendor management and contract renewal processes.
  • Benchmark their own organization against industry peers and understand where the floor lies.
  • Satisfy regulatory due-diligence requirements such as those mandated by NIS2, DORA, SOC 2, and ISO 27001 supply chain provisions.

Rankiteo continuously monitors 393 banking companies with 3,000+ employees, keeping these rankings up to date so you always have an accurate, current picture of the sector's risk landscape.

Top 100 Worst Banking Companies by Cybersecurity Score (2026) | Rankiteo