May 5, 2014

Security Trends In The Financial Services

By Daniel Price

Security Trends

Readers who subscribe to our newsletter will have already read Fridays news about Microsoft’s latest report into key security trends in financial services. The report is part of a series which looks at security trends in cloud computing across four specific industries – financial services, healthcare, retail, and public sector.

Microsoft chose to focus on financial services as one of their key industries because of its scale and omnipresence across all areas of society and business. Financial services organisations handle trillions of transactions each year, and have huge amounts of sensitive data about individuals, companies, and other parties. Protecting that information is a critical component in building trust with customers.

The Problem

Several countries use regulatory bodies to try and force financial services firms to take greater responsibility for data protection. The UK’s regulatory body – the ‘Financial Services Authority’ (FSA) – uses its ‘Principles for Business’ to state that a firm must conduct its business with “due skill, care and diligence, while taking reasonable care to organise and control its affairs responsibly and effectively”. Across the Atlantic, the American Government takes a similarly hard-line approach, using its Securities and Exchange Commission to force some financial services firms to have a disaster recovery plan as a fiduciary responsibility. Sadly, in many cases, either companies do not heed their government’s advice, or they do not have strict government guidelines to adhere to.

Microsoft’s report highlights several shortcomings in firm’s security measures. 38 percent of financial services firms do not have budgeted disaster recovery plans, 22 percent have no formal risk management program, 23 percent have inadequate policies for secure data disposal, 29 percent do not have a plan for responding to security breaches, 37 percent do not use standardised data classification – the list goes on.

The financial industry appears susceptible to what an FSA report termed ‘The Five Fallacies’. They believe there are five key misconceptions amongst companies that serious impact on their security; 1) a belief that the customer data they held was too limited or too fragmented to be of value to fraudsters, 2) a belief that only individuals with a high net worth are attractive to hackers, 3) a belief that that only large firms with millions of customers are likely to be targeted, 4) an assumption that threats to data security are exclusively from external sources, and 5) a belief their security systems are already adequate and fool-proof.

These misconceptions feed poor decision-making with regard to security issues. Some firms regard data security as the sole responsibility of IT staff, whereas others fail to recognise that data security is their responsibility. Some firms that do recognise the risk t rate it so low that it never attracts the attention of senior management, nor is it allocated adequate financial or human resources.

All this creates a problem, especially as these institutions are now starting to move into the cloud. As the uptake of cloud services increases, so does the vulnerability of a firm’s data. Yet, perhaps the cloud is also the answer to the problem? Perhaps it can in fact help solve some of the Vulnerabilities?

Microsoft’s Recommendations

Microsoft believe that hiring a cloud service provider can help financial organisations improve their data security profile.

They claim that switching to the cloud can shift the burden of regulatory compliance and managing risk to the cloud provider. Experienced providers typically employ large teams of IT security and compliance experts who can manage their customers’ systems more efficiently and troubleshoot when something goes wrong.

Cloud service providers already offer several solutions to the current security issues posed in the report – for example, they conduct regular pre-hire and post-hire background checks on their employees, they classify data and other assets according to well-defined policies, they maintain a data backup and recovery framework that is consistent with industry practices, and they conduct regular risk assessments that evaluate threats to the confidentiality, integrity, and availability of data under their control.

The Future

Do you agree with Microsoft’s findings? Do you work in a financial services firm and have experienced poor security practices? Do you think the cloud is the answer?

By Daniel Price

Daniel Price

Daniel is a Manchester-born UK native who has abandoned cold and wet Northern Europe and currently lives on the Caribbean coast of Mexico. A former Financial Consultant, he now balances his time between writing articles for several industry-leading tech (CloudTweaks.com & MakeUseOf.com), sports, and travel sites and looking after his three dogs.
Jeremy Smillie

Securing the Future: Insights from DevSecOps Expert, Jeremy Smillie

Welcome to another insightful discussion on CloudTweaks. Today, we have the privilege of delving into [...]
Read more
Dolores

Q&A: Airport Security Trends with Dolores Alemán, Frost & Sullivan Analyst

Airport Security Trends In this CloudTweaks interview, we delve into the evolving landscape of airport [...]
Read more
Algirdas Stasiūnaitis

The Future of Cybersecurity: Insights from Cyber Upgrade’s Founders

AI and Cybersecurity: Innovations and Challenges In the rapidly evolving landscape of technology, where artificial [...]
Read more

AI-Powered Analytics: Q&A with Sonata Software’s Manu Swami

Welcome to today’s enlightening Q&A session on “AI for Enhanced Analytics,” where we are privileged [...]
Read more
Randy

Adapting to the Changing IT Landscape

The Rising Importance of Cloud Engineers The landscape of information technology and cloud computing is [...]
Read more
Stacey Farrar

Six Things to Consider When Choosing Between Free and Paid Migration Tools

Choosing Between Free and Paid Migration Tools Microsoft recently decided to stop offering its free [...]
Read more

SPONSOR PARTNER

Explore top-tier education with exclusive savings on online courses from MIT, Oxford, and Harvard through our e-learning sponsor. Elevate your career with world-class knowledge. Start now!
© 2024 CloudTweaks. All rights reserved.