Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    ;
    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Technology > How financial institutions can keep data safer
    Technology

    How financial institutions can keep data safer

    How financial institutions can keep data safer

    Published by Gbaf News

    Posted on August 31, 2019

    Featured image for article about Technology

    By Matt Lock, Technical Director at Varonis

    Matt Lock

    Matt Lock

    The financial sector is a prime target for threat actors looking to make money by infiltrating corporate networks to steal data or insider information or install ransomware. Not only could this result in the loss of data, funds and reputation, but it could also land the concerned institution with a large fine from regulators.In 2018 the FCA issued fines totalling more than £60 million, a sizeable proportion of which was due to data breaches.

    Unfortunately, many banks and financial institutions are making life easier for those wishing to steal critical information from them simply as a result of poor cyber security practices. This often comes down to how security risks are prioritised within the business,which is the responsibility of the C-suite. They must understand and keep up to date on the latest threats and the tactics cybercriminals use. This will help inform the appropriate allocation of budgets and resources in line with the level of risk.

    Reduce exposed data

    Some of the biggest risk factors that financial institutions face is unmanaged access to data and storing too much unused and unnecessary data on their networks.

    For instance, in one organisation we discovered a payroll file open to the entire company. Even the receptionist on the front desk could easily access confidential payroll files through her account.

    This company isn’t alone. Varonis research found that the average organisation operating in the financial industry leaves one in five (21 percent) of its sensitive files and folders exposed.On average, financial institutions had 352,700 unprotected, sensitive files accessible to anyone on the corporate system.

    This is a concern for a number of reasons. Firstly, unrestricted access to files means that anyone in an organisation can view and alter files regardless of their job role,whether they genuinely need access or not.For example, should a temporary consultant be able to access and change a client’s personally identifiable information (PII)?As such, if any unauthorised changes are made to a file, or it is leaked outside the organisation, there is little insight as to how this happened or who is responsible.

    Secondly, if a threat actor does manage to infiltrate a corporate network, they will have unfettered access to any data that is not restricted. The implication is that hundreds,or even thousands,of files could be quickly and easily stolen before an information security team is even aware there is an unauthorised person on the system.Permissive access can have significant implications if an organisation falls victim to ransomware; if the individual that is compromised has global access rights, all the data that they can access will be encrypted.

    To reduce exposure and keep these files and folders safe, financial institutions need to operate a policy of “least privilege”, where employees only have access to the data needed to carry out their roles. Measures for implementing a least privilege approach to information security include: removing global access to data; ensuring that all data has an owner or steward and regularly re-certifying access to reflect role changes or staff leaving.

    Automation plays a key role in enforcing least privilege as it can be used to discover those accounts that have access to information they do not need for their job role.

    Crack down on overdue passwords

    When looking to protect access to data through login details, setting expiry dates for passwords is essential, as this forces users to create new ones on a regular basis. If there is no end date, threat actors have longer to figure out what a particular password is, and it gives them unlimited time once they are in a corporate network.Creating an end date for passwords also means that it is less likely that the credentials of someone who has left the company will still be valid and provide a threat actor with a way into a network. Yet despite the clear benefits, our research found that 38 percent of users had passwords that never expire.

    Remove stale data

    Another significant issue affecting the security of organisations is data that is out of date, no longer in use or just generally redundant, known as stale data.Holding on to that data unnecessarily simply creates more challenges, not only security risks but also management and storage costs.

    Our research discovered that more than half (53 percent) of all data in a company is stale, and nearly nine out of 10 (87 percent) companies have more than 1,000 stale files – seven out of 10 (71 percent) have upward of 5,000.

    Financial organisations need to know exactly what data they have on their corporate networks and where it is. This is not only beneficial for security issues, but it can also help improve the overall business. For starters, the less data an organisation has to keep, the less it needs to spend on storage. Then there are Data Subject Access Requests (DSARs), which enable individuals to request any information that a company holds on them and how it is being used. Under the GDPR the timeframe for responding to these requests has been reduced from 40 days to a calendar month and organisations can no longer charge a fee.Financial institutions need to know what and where this information is if they are to have any chance of responding to the DSAR within the time limit.

    Regain control

    To take back control of their data, financial institutions need to conduct a complete analysis of all the folders and files on their corporate networks down to granular detail. This must highlight data that is stale and enable an organisation to either delete it from the system or archive it. The analysis should also identify who has access to which files and folders to allow permissions to be changed so that they are only accessible to those that need them for their work,based upon the least privilege approach.

    Protecting data should the top business priority for the C-suite of financial institutions. Doing so not only protects the integrity of customers’ data but also guards the business from reputational damage, the potential loss of income, and the risks of hefty fines.

    Related Posts
    LakeFusion Secures Seed Funding to Advance AI-Native Master Data Management
    LakeFusion Secures Seed Funding to Advance AI-Native Master Data Management
    Clarity, Context, Confidence: Explainable AI and the New Era of Investor Trust
    Clarity, Context, Confidence: Explainable AI and the New Era of Investor Trust
    Data Intelligence Transforms the Future of Credit Risk Strategy
    Data Intelligence Transforms the Future of Credit Risk Strategy
    Architect of Integration Ushers in a New Era for AI in Regulated Industries
    Architect of Integration Ushers in a New Era for AI in Regulated Industries
    How One Technologist is Building Self-Healing AI Systems that Could Transform Financial Regulation
    How One Technologist is Building Self-Healing AI Systems that Could Transform Financial Regulation
    SBS is Doubling Down on SaaS to Power the Next Wave of Bank Modernization
    SBS is Doubling Down on SaaS to Power the Next Wave of Bank Modernization
    Trust Embedding: Integrating Governance into Next-Generation Data Platforms
    Trust Embedding: Integrating Governance into Next-Generation Data Platforms
    The Guardian of Connectivity: How Rohith Kumar Punithavel Is Redefining Trust in Private Networks
    The Guardian of Connectivity: How Rohith Kumar Punithavel Is Redefining Trust in Private Networks
    BNY Partners With HID and SwiftConnect to Provide Mobile Access to its Offices Around the Globe With Employee Badge in Apple Wallet
    BNY Partners With HID and SwiftConnect to Provide Mobile Access to its Offices Around the Globe With Employee Badge in Apple Wallet
    How Integral’s CTO Chidambaram Bhat is helping to solve  transfer pricing problems through cutting edge AI.
    How Integral’s CTO Chidambaram Bhat is helping to solve transfer pricing problems through cutting edge AI.
    Why Physical Infrastructure Still Matters in a Digital Economy
    Why Physical Infrastructure Still Matters in a Digital Economy
    Why Compliance Has Become an Engineering Problem
    Why Compliance Has Become an Engineering Problem

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Previous Technology PostFuture-Proofing Financial Services with Multi-Cloud
    Next Technology PostWhy your contact centre needs to embrace the cloud computing revolution

    More from Technology

    Explore more articles in the Technology category

    Can AI-Powered Security Prevent $4.2 Billion in Banking Fraud?

    Can AI-Powered Security Prevent $4.2 Billion in Banking Fraud?

    Reimagining Human-Technology Interaction: Sagar Kesarpu’s Mission to Humanize Automation

    Reimagining Human-Technology Interaction: Sagar Kesarpu’s Mission to Humanize Automation

    LeapXpert: How financial institutions can turn shadow messaging from a risk into an opportunity

    LeapXpert: How financial institutions can turn shadow messaging from a risk into an opportunity

    Intelligence in Motion: Building Predictive Systems for Global Operations

    Intelligence in Motion: Building Predictive Systems for Global Operations

    Predictive Analytics and Strategic Operations: Strengthening Supply Chain Resilience

    Predictive Analytics and Strategic Operations: Strengthening Supply Chain Resilience

    How Nclude.ai   turned broken portals into completed applications

    How Nclude.ai turned broken portals into completed applications

    The Silent Shift: Rethinking Services for a Digital World?

    The Silent Shift: Rethinking Services for a Digital World?

    Culture as Capital: How Woxa Corporation Is Redefining Fintech Sustainability

    Culture as Capital: How Woxa Corporation Is Redefining Fintech Sustainability

    Securing the Future: We're Fixing Cyber Resilience by Finally Making Compliance Cool

    Securing the Future: We're Fixing Cyber Resilience by Finally Making Compliance Cool

    Supply chain security risks now innumerable and unmanageable for majority of cybersecurity leaders, IO research reveals

    Supply chain security risks now innumerable and unmanageable for majority of cybersecurity leaders, IO research reveals

    Why AI's Promise of Efficiency May Break Tomorrow's Workforce

    Why AI's Promise of Efficiency May Break Tomorrow's Workforce

    Revolutionizing AppSec: The AI Security Crew Paradigm Shift

    Revolutionizing AppSec: The AI Security Crew Paradigm Shift

    View All Technology Posts