They underestimate how a small percentage of activity can still represent billions in losses and serious reputational damage. The report shows illicit activity is a minority of total volume, yet scams alone account for most criminal value. The mistake is focusing on percentage share instead of absolute impact, typology concentration, and the downstream need for monitoring, triage, and response.
When percentage thinking hides the real crypto risk
The core error is confusing share of activity with share of harm. A small slice of transaction volume can still contain the highest-value criminal flows, the most repeatable fraud patterns, and the most expensive remediation burden. For organisations, that means the right question is not “how much of the total is illicit?” but “where is the loss concentrated, how fast does it move, and what must we detect and stop first?”
Why typology concentration matters more than volume share
Crypto risk is rarely evenly distributed. Scams, laundering patterns, and high-velocity abuse can dominate the loss picture even when they represent a small fraction of overall activity. That is why absolute impact matters more than percentage share: a low-volume typology can still drive the largest financial loss, create the widest victim footprint, and generate the most visible enforcement and reputational fallout.
Organisations also get misled when they lump all illicit activity together. Different typologies have different control needs, different detection windows, and different response priorities. If one pattern is responsible for most criminal value, then generic “illicit activity” reporting hides the operational reality that matters for monitoring, triage, and escalation.
What this changes in monitoring and response
Once loss concentration is understood, the monitoring model changes. Teams need to focus on signals that reveal high-value abuse early, not just aggregate suspicious activity counts. That usually means triaging by value, recurrence, speed, and counterparty risk, then escalating cases that may indicate organised fraud or coordinated laundering rather than treating every alert as equivalent.
It also changes response design. High-consequence crypto abuse is not solved by volume reporting alone. Organisations need case handling that can support rapid containment, preservation of evidence, and cross-functional response when a small number of transactions may account for most of the damage. Independent control frameworks such as ISO/IEC 27001:2022 Information Security Management and the FATF Recommendations are useful here because they reinforce risk-based control design, customer due diligence, and suspicious activity handling rather than superficial volume-based comfort.
Risk and Threat Considerations
The main risk is underestimating loss because the exposed share looks small on paper. In crypto and related financial flows, low-percentage activity can still drive the majority of criminal value, so organisations that optimise for percentage metrics often miss the transactions most likely to create direct loss, legal scrutiny, and reputation damage.
Failure mechanism: Concentrated scam or laundering typologies sit inside a small slice of activity, but they move value disproportionately fast and are often missed when monitoring thresholds, investigations, and executive reporting are based on total volume rather than value concentration and typology mix.
Impact: Losses can scale into the billions, response teams can be overwhelmed by the wrong alerts, and the organisation may discover too late that its controls were tuned to the average case instead of the worst case.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.15 — Access control | Risk-based control design needs access controls that focus on high-risk transaction paths. |
| A.5.16 — Identity management | Monitoring and response depend on being able to attribute and triage risky transaction behavior. | |
| A.5.24 — Information security incident management planning and preparation | High-value fraud and illicit flows require prepared response handling beyond aggregate reporting. | |
| Recommendation — Tune access control to protect the transaction paths that concentrate the highest harm. Ensure identity records support rapid attribution and investigation of high-loss activity. Prepare incident response for concentrated high-value abuse cases, not just broad volume alerts. | ||
| NIST CSF 2.0 | ID.RA-01 — Asset Vulnerabilities Are Identified and Documented | The issue is misjudging where harm concentrates across transaction activity and abuse patterns. |
| DE.CM-01 — Networks and systems are monitored to detect potential cybersecurity events | The answer centers on monitoring and triage for high-value abuse inside a small activity share. | |
| Recommendation — Document where transaction abuse concentrates so risk reporting reflects actual exposure. Monitor transaction flows for concentrated abuse signals, not just overall activity levels. | ||
Practitioner Guidance
What to prioritise: Separate activity volume from harm volume in every risk report. If the same typology keeps reappearing in the highest-loss cases, treat it as a priority even if it remains a minority of total transactions.
What to verify: Confirm that monitoring thresholds, triage queues, and management dashboards are keyed to loss concentration, not just transaction counts. A healthy control set should show whether the organisation can spot the small set of events that produce the largest downstream exposure.
Decision rule: If a pattern is low-frequency but high-value, escalate it as a control issue and a response issue, not merely as a reporting outlier. That is the point where targeted detection, faster case handling, and stronger governance matter more than broad activity summaries.
Practitioner takeaway: The useful metric is not how small the illicit share looks, but whether you can identify and contain the few transactions that create most of the harm.
Related resources from NHI Mgmt Group
- What do organisations get wrong when they treat online signing as a low-risk convenience control?
- What do organisations get wrong when they treat risk management as separate from framework adoption?
- What do organisations get wrong when they treat crypto agility as a one-time migration project?
- What do organisations get wrong when they treat cybersecurity risk management as just an antivirus problem?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org