A ransomware attack on a single third-party provider was enough to disrupt trading workflows across multiple jurisdictions, delay regulatory reporting and force firms to manually reconstruct trading records.
The 2023 cyberattack on Ion Markets provides a stark reminder that cyber incidents can quickly become market-wide events in the interconnected cleared derivatives ecosystem.
During a recent FIA Law and Compliance Division webinar, Aaron Charfoos and Michelle Reed, partners and co-chairs of the data privacy and cybersecurity practice at Paul Hastings LLP, examined how cyber, privacy and artificial intelligence risks are reshaping the operational resilience challenges facing exchanges, clearinghouses, futures commission merchants and other market participants.
Their message was clear: cyber risk is no longer a technology issue. In today's interconnected markets, it is increasingly a clearing risk, a regulatory risk and a market integrity risk.
The speakers repeatedly returned to the lessons of the 2023 Ion Markets ransomware attack, which affected a technology provider whose systems were deeply embedded in trade execution, clearing and post-trade workflows. Firms around the world struggled to process trades, some requiring up to two weeks to recover, and regulators in multiple jurisdictions became involved as disruptions spread throughout the market.
The incident highlighted a reality of modern derivatives markets: operational resilience is only as strong as the resilience of the industry's most critical service providers.
"One particular bit of ransomware hitting one part of the supply chain resulted in an entire ecosystem that went into chaos." Reed said.
The ION incident also reinforced concerns around concentration risk. Market participants rely on vendors for services ranging from trade processing and reconciliation to collateral management, market data and risk calculations. As a result, a disruption affecting one provider can affect multiple market participants simultaneously.
"When you look at the interconnectedness of the market, and how much overlap there is in technologies that are used, you are only as strong as your weakest link in the supply chain." Reed said.
This vulnerability helped drive FIA's post-incident work, including the creation of its Cyber Risk Task Force and the Industry Resilience Committee, bringing together clearing firms, exchanges, central counterparties and vendors to strengthen coordination and improve preparedness for future events.
One of the most practical lessons discussed on the webinar concerned recovery. According to Reed, restoring internal systems is only one part of the process. Reconnection with exchanges, counterparties and service providers often requires extensive attestations, forensic reviews and evidence that systems are secure before trading relationships can resume. Many firms focus on recovery, only to discover that reconnecting to counterparties, exchanges and service providers can become a significant challenge in its own right, Reed said.
While artificial intelligence is creating opportunities across trading, risk management and compliance, it is also transforming the threat landscape.
Charfoos noted that while many cyber risks associated with AI are not entirely new, AI is making familiar attack methods significantly more effective. Phishing emails have become more convincing, social engineering attacks more targeted and fraudulent IT helpdesk calls more difficult to identify.
"Artificial intelligence is taking the old-school cybersecurity hacking techniques and making them much, much more dangerous,” he said.
Cyberattacks are also moving faster than ever. According to figures cited during the webinar, the average "breakout time" between initial compromise and lateral movement through a network is now just 29 minutes, while some attacks have progressed in as little as 27 seconds. At the same time, attackers are increasingly relying on stolen credentials rather than malware, making identity management and access controls a growing area of focus for firms.
The discussion also touched on the growing use of autonomous AI in cyberattacks, allowing threat actors to automate activities that previously required significant human involvement.
For derivatives firms, the implications extend beyond cybersecurity. AI is already being deployed across algorithmic trading, surveillance, risk modelling, anti-money laundering processes and client onboarding. The speakers stressed that firms should not expect special treatment from regulators simply because AI is involved. Existing supervisory, governance and risk management requirements continue to apply.
The webinar also explored operational resilience through the lens of 24/7 trading, a topic receiving growing attention across derivatives markets.
Although extended trading hours could provide greater flexibility for market participants, the speakers noted that continuous markets would create significant operational and cybersecurity challenges. Many organisations currently depend on planned maintenance windows to install software patches, test systems and implement security updates. A 24-hour trading environment could make these activities considerably more difficult.
At the same time, security teams would need to monitor systems continuously across time zones, manage significantly larger volumes of data and maintain readiness to respond immediately to incidents.
Charfoos noted that traditional market hours provide firms with valuable opportunities to recover from operational disruptions and cyber incidents. In a 24/7 trading environment, however, there would be no natural downtime for firms to restore systems and resume operations without potential market impact.
The discussion underscored FIA's previously stated concerns regarding the expansion of trading and clearing into a 24/7 environment before operational, infrastructure and resilience challenges have been fully assessed and addressed.
The speakers concluded by encouraging firms to stress-test critical vendor dependencies, strengthen incident response plans, map data flows, improve governance around AI deployments and participate in industry-wide resilience exercises.
Cybersecurity, they said, can no longer be viewed as a standalone technology function. As market infrastructure becomes increasingly interconnected, resilience depends on coordination across firms, vendors and the wider derivatives ecosystem.
Learn more about FIA's 2026 Disaster Recovery Exercise here.
Watch the full webinar here.