Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› What should teams do when bear market resilience…
Cyber Security

What should teams do when bear market resilience and adoption growth point in different directions?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Cyber Security

Treat that divergence as a signal to separate price cycles from usage trends. A bear market can reduce speculation while adoption, payments use, and criminal activity continue to expand in specific regions or asset classes. Teams should reassess exposure by use case, monitor corridor shifts, and avoid assuming that lower market prices mean lower operational or compliance risk.

When market prices weaken but adoption, payments, or illicit use continue to expand, the question is no longer whether the asset is “performing” in a trading sense. It is whether the underlying network, payment corridor, or abuse pattern is changing in a way that still affects operations, controls, and exposure. Teams need to look past chart direction and ask which use cases are still growing, where, and for whom.

A bear market can suppress speculative activity without reducing settlement, treasury, remittance, or criminal demand. That means volume can shift into different venues, geographies, or asset types while headline prices fall. NIST Cybersecurity Framework 2.0 is useful here because it keeps the focus on governance, identification, protection, detection, response, and recovery rather than on a single market indicator.

How Teams Should Reassess Exposure by Use Case

The practical move is to segment exposure by use case, not by market sentiment. Payments rails, consumer adoption, exchange activity, custody exposure, sanctions touchpoints, and criminal use can move differently from one another, so a general “risk is down because prices are down” assumption is usually too coarse. Teams should identify which corridors, counterparties, and product flows remain active even when investor interest softens.

That matters because the operational and compliance implications are not uniform. A region with declining speculative volume may still show rising payment adoption, while a lower-priced asset may remain attractive for laundering, fraud, or sanctioned flows. For control design, NIST AI Risk Management Framework is not the subject here, but its broader risk framing is a reminder to separate trend signals, evidence, and impact before concluding that exposure has changed.

What to Monitor When the Signals Split

Teams should monitor corridor shifts, counterparty concentration, and use-case migration at a level that can catch movement before it appears in losses or incidents. A useful readout is whether activity is moving from one region to another, from transparent venues to opaque ones, or from legitimate payments into higher-risk flows. Those changes often matter more than the aggregate market direction.

Governance should also account for third-party and regulatory drag. If adoption is growing in one corridor while controls are lagging in another, the organisation can inherit more exposure even as market enthusiasm cools. For teams that need an external policy anchor, the EU NIS2 Directive and EU Digital Operational Resilience Act (DORA) both reinforce the need to manage changing operational dependencies, not just static asset values.

Risk and Threat Considerations

When price weakness and adoption growth diverge, the main risk is false reassurance. A team that equates falling prices with falling exposure may miss continued activity in payments, custody, sanctions-sensitive corridors, or abuse-driven flows. That can leave monitoring thresholds, compliance reviews, and incident readiness calibrated to the wrong signal.

Failure mechanism: Teams anchor on market performance instead of activity patterns, so they underweight corridors, counterparties, and product lines that are still expanding or attracting abuse.

Impact: Exposure can persist or increase even in a bear market, leading to missed control updates, weaker detection, and under-scoped compliance or operational risk reviews.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while DORA and NIS2 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyThe question is about separating market sentiment from operational exposure.
ID.RA-01 — Asset Vulnerabilities Are Identified and DocumentedTeams need to reassess exposure by use case and corridor as conditions change.
GV.SC-01 — Cyber Supply Chain Risk Management StrategyThe answer emphasizes third-party and corridor shifts that alter dependency risk.
Recommendation — Re-baseline risk decisions on actual use-case and corridor trends, not on price alone. Identify which corridors, counterparties, and use cases still create material exposure. Review third-party and corridor dependencies when adoption shifts into new channels.
DORAOperational ResilienceThe subject involves changing operational and third-party exposure in financial activity.
Recommendation — Stress-test operational assumptions against changing activity patterns and corridor concentration.
NIS2Risk management measuresThe question calls for updated controls when exposure changes despite falling prices.
Recommendation — Update monitoring and incident readiness when use-case growth outpaces market decline.

Practitioner Guidance

What to prioritise: Split your review into market risk, adoption risk, and abuse risk, then score each use case separately. The most useful question is not “is the asset down?” but “where is activity still growing, and what control assumptions depended on the old distribution?”

What to verify: Confirm whether corridor growth is coming from legitimate payments, speculative rotation, or higher-risk activity such as fraud or laundering. If the same flow is appearing in new geographies or through new counterparties, treat that as a control change, not just a market observation.

Practitioner takeaway: Divergence should trigger a control reset, not a sentiment debate. If adoption or abuse trends remain strong, the organisation should re-baseline exposure and monitoring on actual usage patterns, not on price alone.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org