Editorial & Advertiser disclosure

Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

Banking

Posted By Gbaf News

Posted on August 14, 2018

FCA lays out new rules for banks on reporting operational and security incidents to customers

Increased visibility for customers means banks must ramp up risk mitigation

On Wednesday 15th August, the Financial Conduct Authority (FCA) will enforce new rules requiring providers of personal and business accounts to publish information that will help current customers to compare bank accounts from different providers.

Banks will have to report major operational and security incidents that have taken place and disclose whether 24-hour customer helplines are available.

The pressure for banks to report system failures is further compounded by the Bank of England and FCA’s fast approaching 5 October deadline, by which they must report on their exposure to risks and how they will respond to outages[i].  With customers having more visibility and banking options than ever, finding new ways to mitigate risk is top of mind for banks in order to maintain their reputation as secure and trusted institutions.

Financial Services firms are increasingly moving from a product-centric approach to cybersecurity. Instead, they are focusing on compartmentalising and individually securing their critical applications, such as online banking or interbank payments, in order to prevent a domino effect if one area comes under attack.

But due to outdated infrastructure, it can be difficult for financial institutions to gauge how applications are built into the network and communicating with each other in real time. This is a crucial first step when it comes to writing security policies for individual applications, and consequently preventing operational and security incidents, says Nick Hammond, Lead Advisor for Financial Services at World Wide Technology.  

Nick Hammond, from World Wide Technology, comments:  “Financial Services firms are under significant pressure to be both quick and transparent when it comes to reporting operational and security incidents. To alleviate this pressure and maintain stringent security, they are working towards ensuring a high level of application assurance.

“Whilst older rules required yearly tick-box compliance exercises, new regulations necessitate continued assurance of critical applications. But the complex nature of existing systems throws a spanner in the works. Legacy infrastructures were often built with different and sometimes conflicting metrics over the years, meaning that an intricate patchwork of applications communicate with each other in complicated ways.

Nick Hammond continues: “The network of opaque interdependencies creates a big hurdle for banks, which means many are drawing on infrastructural expertise as the first step towards securing their internal software. By gaining insight into infrastructure, firms can create a real-time picture of the entire network, allowing them to confidently rationalise the way that different applications share data within the system.

“Consequently, firms can fit the right security policies to each segmented application, preventing unnecessary or illicit data flows. In turn, this will help them maintain their reputations as trusted and secure institutions.”

[i]https://www.theguardian.com/money/2018/jul/05/banking-outages-should-be-limited-to-two-days-say-regulators

Recommended for you

  • Statistical Models for Cash Flow Forecasting and Liquidity Management for SMEs in Banking

  • Data-Driven Financial Health Monitoring for SMEs in Banking

  • Digital Transformation in SME Banking: Adoption and Impact of Digital Solutions