Posted in

The Top 5 Challenges Financial Services Security Professionals Face

If you’re in the financial services industry, you know it’s time to batten down the hatches. With the recent devastating cyberattack against Capital One, other attackers may be emboldened to probe the defenses of other financial services firms with the intent of finding similar vulnerabilities. In this environment, however, attackers may not be your only challenge.

If you’re part of a smaller organization, you probably have fewer resources to bring to bear than larger firms. In addition,  leadership may back-burner your security concerns.

On the other hand, if you don’t surface your concerns and do everything to ensure that your organization complies with security regulations like the Bank Secrecy Act, the new NYDFS laws, SOX, and others, you run the risk of incurring heavy penalties.

There’s a way to thread the needle, however. If you successfully navigate these five challenges, you’ll have done everything in your power to make your company safer “ deflecting attackers and satisfying regulators alike.

1. Your Concerns Are Not Front and Center

CEOs and board members are getting better about prioritizing information security “ much more so than they were even as little as five years ago. With that said, maybe you got unlucky. Your CEO may not be one of the enlightened ones. Even if they are, they might misunderstand the risks. There is any number of reasons “ reasons that might look good from the standpoint of a business professional “ to temporarily de-emphasize information security.

From the standpoint of a security professional, however, it could not be a worse time to downplay infosec. Fortunately, even CEOs aren’t immune to being scared straight. Tell them about Emotet “ the polymorphic banking trojan that now comprises 60% of all phishing payloads. Tell them about the PayID breach that stole banking information from nearly 100,000 Australian banking customers. Tell them about how a Mastercard breach resulted in leaked banking information of 90,000 German users.

If that doesn’t work, ask for permission to set up a penetration test “ or even do an in-house demonstration on your own. This should show them how easy it is for unauthorized users to gain access to critical controls.

2. You Have No Budget

Even if your CEO supports the idea that your organization should be better protected, there’s no guarantee that you’ll have the budget to act on it. Only 47 percent of SMB leaders reported information security as a top ten budget priority. On average, security came in third place on the IT budget priority list. That’s not an encouraging sign.

Fortunately, you don’t need the latest in advanced machine learning software to prevent the most advanced malware from attacking your systems. Instead, you should focus on detectionless solutions that keep untrusted files from reaching your endpoints as a blanket rule. Remote Browser Isolation, for example, doesn’t care about detecting malware. Its only job is to confine all downloaded files to a secure container that’s located in the cloud.

This and other low-cost tools don’t scan your system actively, but they still provide an effective barrier to even the most advanced intrusion methods. You can enhance your defenses even more by looking into free and open-source tools that can provide as much functionality as tools from major manufacturers.

3. Reliance on Outside Vendors

How many external vendors are you using right now? Companies like Procter and Gamble can have up to 75,000 partners and vendors that they closely work with. You might have fewer suppliers, but many companies simply don’t know how many suppliers they actually have. If your partners get hacked, attackers will get some of your information as well.

It’s important to plan for this eventuality by vetting your partners’ security. Do they perform regular assessments? Do they have security staff? Do they use best practices? The answers should help you assess whether to continue these business relationships or recommend switching to other vendors.

4. Compliance Requirements

In general, the compliance regimes you work with require you to do the utmost “ with the budget you possess “ to secure your organization. This means keeping all applications patched up to date, erecting a firewall, and adopting encryption among other things. What’s more, you’ll need to keep records “ lists of who has access to critical documentation, as well as how often those records are accessed, moved, or altered.

As a financial services company, you’re likely subject to multiple compliance regimes, each with slightly different and overlapping requirements. Your best move is to hire an auditor to make sure you’re not forgetting to check any boxes. This might include security awareness training, disaster recovery plans, and more.

5. Human Error

People aren’t perfect, and sometimes they’re downright malicious ” your employees included. About 90% of cyberattacks are caused by human error, sometimes as simple as clicking the wrong link or trusting the wrong person.

Security awareness training may be partially effective ” but considering the scale at which hackers operate, anything less than a 100% success rate is not good enough. Researchers estimate that the operators of a single malware strain, Emotet, send up to 1 million attacks per day. Even if you have multi-factor authentication, which can  mitigate up to 90% of average phishing attacks, that leaves 100,000 attacks per day still getting through ” and that figure doesn’t include non-Emotet attacks

Putting It All Together “ Zero Trust

Even basic protections can create an effective defense when you adopt the simple mindset that underlies the Zero Trust approach “ that anyone inside your network is a potential bad actor. Tools like MFA and Remote Browser Isolation help impose safeguards on your users at a manageable cost, and you can establish basic segmentation and identity management with tools you most likely already have onboard. Remember, this is an age when even your most trusted accounts ” including those of your most senior management and officers ” can be compromised with ill intent. When planning your security portfolio, it’s best to operate on the Zero Trust assumption that no one or nothing can be trusted, and verify everything.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.