Walk through any preparedness forum long enough and you will find it: the scenario where a nation-state cyberattack takes down the banking system, ATMs go dark, payment rails freeze, and suddenly your debit card is a laminated rectangle with no function. People stock cash for this. People buy gold for this. People have argued, with apparent sincerity, that a thumb drive full of Bitcoin stored in a fireproof safe is the only rational response to living in the digital economy.

We are not worried about this scenario. Not because cyberattacks aren't real — they are, and they will keep happening — but because the household-level threat is almost nothing like the version the preparedness industry sells.

The actual threat landscape

Large financial institutions in the United States are among the most hardened targets in any sector. The largest banks each spend over a billion dollars annually on cybersecurity, employ dedicated red teams, and operate under regulatory frameworks (including Federal Reserve stress-testing requirements that now include cyber scenarios) that would embarrass most Fortune 500 companies. Smaller regional banks and credit unions sit in the middle tier — less resourced, but also far less interesting to sophisticated state actors who want maximum disruption, not maximum fraud.

The cyberattacks that actually hit consumers are almost always at the credential or account level: phishing, SIM-swapping, data breaches that expose passwords. These are real annoyances. They can cost you real time and money. But they are categorically different from a systemic collapse of the payment infrastructure. One is a mugging. The other is the scenario where the entire transportation grid dissolves.

The "grid-level" attacks that do happen — and they have happened, including ransomware incidents at regional utilities and a handful of credit union processors — tend to be disruptive for days, not weeks, and tend to affect specific systems rather than cascading across the whole ecosystem. The 2023 MOVEit vulnerability, for instance, compromised data at dozens of organizations, but it did not prevent anyone from buying groceries.

Why this fear spreads so easily

The cyberattack-on-banking fear is compelling for a few structural reasons. First, it is unfalsifiable in advance — you cannot point to the attack that didn't happen the way you can point to the hurricane that missed. Second, digital financial infrastructure is genuinely invisible to most people, which makes it feel fragile. Third, the preparedness industry has a product for it: hard assets, physical cash, precious metals. Fear with a purchase attached tends to circulate.

There is also a subtle conflation happening between two different things. Corporate data breaches are frequent. Systemic financial infrastructure failure is extraordinarily rare. The preparedness discourse often treats the first as evidence that the second is imminent. It isn't.

The Federal Reserve and the major clearing networks (ACH, Fedwire, CHIPS) have redundancy architectures specifically designed to prevent single points of failure. This does not make them invulnerable — it means a successful attack would need to be extraordinarily sophisticated and would likely be detected before full collapse. The scenario where all of them fail simultaneously is not zero-probability, but it is not in the same risk tier as an ice storm that cuts your power for five days.

What we are actually watching

The real consumer-level cyber risk is identity theft and account takeover — not infrastructure collapse, but personal exposure. Roughly one in three households experiences some form of financial fraud in any given year, according to general survey data from the FTC and financial services industry research. That is worth defending against. The defense, however, is not a gold coin under the mattress.

What to do this week

Enable transaction alerts on every financial account you hold. Most banks and credit unions will text or email you on any transaction over a threshold you set. Set it low — $10 or $25. This catches account takeover early.

Freeze your credit at all three major bureaus. This takes about 20 minutes total and costs nothing since 2018. It is the single highest-return security action a household can take. Unfreeze temporarily when you need a hard pull.

Keep two to four weeks of cash at home. Not because the banking system is going to collapse — it won't — but because local infrastructure disruptions (storms, extended power outages, processor outages at your specific bank) are common enough that having some cash is just sensible. This is not a doomsday hedge; it is a practical buffer.

Use a password manager and unique credentials for every financial site. The vector for most consumer financial harm is credential reuse. A good password manager eliminates that vector entirely.

That's it. No gold. No crypto bunker. No alternate payment rail.

The bigger picture

The preparedness community does something valuable when it forces people to think about systems they normally take for granted. Banking is worth thinking about. But the useful question is not "what do I do when the whole system goes down?" — it is "what do I do when my access goes down?" Those are different problems with different solutions, and the second one has answers that are boring, cheap, and effective.

The catastrophic scenarios get the oxygen. The realistic ones get the solutions.