Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Finance > What Security Means for Financial Institutions in a Digital-First Economy
    Finance

    What Security Means for Financial Institutions in a Digital-First Economy

    What Security Means for Financial Institutions in a Digital-First Economy

    Published by Jessica Weisman-Pitts

    Posted on July 25, 2022

    Featured image for article about Finance

    By Ross Brewer, Vice President and General Manager of EMEA and APJ for AttackIQ, touches on how financial institutions can build a threat-informed defence and navigate the current compliance space.

    Ransomware continues to proliferate in today’s ever-expanding digital economy, hindering companies’ and Governments’ abilities to ward off threats. The highest number of ransomware attacks has been recorded last year – over 470 million, making 2021 the costliest year to date for enterprises. A total of around $6 billion was lost because of cyber-crime in the U.S., according to a recent report by the Federal Bureau of Investigation. Businesses in the U.K. have also been hit hard by cybercrime over the past year, with financial losses amounting to over £1 billion. Global malware campaigns targeting financial institutions (MirrorBlast), as well as notorious financially motivated cybercriminal gangs, including Cobalt who have attacked 100 financial firms in more than 40 countries, are placing even more pressure on businesses.

    Attackers follow opportunities and thieves follow the money. As banks pivoted to online banking over the last 20 years, criminals went online, conducting heists in cyberspace that Bonnie and Clyde once did in person. To combat these destructive attacks, banks are doubling down on their security budgets, and Governments across the globe are pushing for strengthened regulations. While financial services have to report when a breach has taken place and highlight their response in the event of an attack, there are no boxes to tick when it comes to their performance data. With regulators, auditors, and lobbying associations asking for more granular detail, and every process becoming a digital process, financial institutions are experiencing more and more pressure when it comes to threat detection and response readiness.

    Cybersecurity compliance for financial institutions, which today seems more like a spider web of overlapping mandatory and optional regulations, makes it even more difficult for enterprises to navigate the current threat landscape.[i] Only by keeping up with the evolving compliance space, as well as choosing the right threat protection provider, institutions can stay one step ahead of cybercriminals.

    The evolution of the compliance space

    Governments around the world are seeking to strengthen cybersecurity regulations, propelling a whole sector to adopt advanced solutions for cyber compliance. In March, the U.S. Senate passed the Strengthening American Cybersecurity Act, which would require companies involved in critical infrastructure to report cyberattacks and ransomware payments. And in the U.K., the Government has set out to improve cyber regulations across the board, investing over £2 million in its National Cyber Strategy. Singapore has taken more stringent steps: in the event of a cybersecurity breach, banks will have to pay higher penalties with the maximum penalty for a breach standing at around $736,791.

    Compliance is risk management and threat management coming together. Businesses should be able to use risk metrics and build executive reports around them, especially with professional associations, lobbying associations, and auditors asking for more detailed performance data. This is where automated security control can aid teams by providing real-time data on the effectiveness of their security programs. Through knowledge-based frameworks, such as MITRE ATT&CK, security programs can be put to the test effectively, using knowledge of adversary tactics, techniques, and procedures (TTP). Simulating real-world behaviours is the key to building a repository of relevant data that can be shared with regulators and investors, as well as preparing businesses for facing a real-world threat.

    A transformation of the computing universe

    With businesses moving operations to the cloud, securing systems and protecting supply chains have grown immensely in complexity. While most major cloud service providers have native security controls within them to improve cybersecurity, security teams often fail to recognize them, as well as validate them: 82 per cent of breaches could have been stopped with existing controls. Third-party supplier breaches have also increased in ruthlessness, with “island hopping” becoming a widespread phenomenon. Rather than launching a direct cyberattack, ransomware operators are now after vulnerable partner networks. Recent research finds that 60 per cent of financial institutions experienced an increase in “island hopping”, a 58 per cent increase from last year.

    Because of this, businesses must assume that their external defences will be breached by intruders, and carry out the continuous automated testing of their controls. This “assume breach” strategy needs to be followed by investment in best-in-class capabilities, whether this means investing in talent, or better technology. For example, threat detection platforms that are mapped to most of the major cloud providers will be more effective in protecting financial institutions against attacks. Protection of systems can only be ensured through continuous testing, and it is important that companies also consider moving away from testing controls only once or twice a year.

    As ransomware attacks grow in complexity, and the threat landscape expands, the finance sector finds itself at a crossroads. With the compliance space evolving regularly and auditors asking for more granular performance detail, institutions need more support in building a threat-informed defence. TTP knowledge-based frameworks, paired with continuous testing aided by automated security controls, will ensure that banks, brokerage firms, and payment providers are protected from breaches, building a safer future for the sector.

    [i] https://www.upguard.com/blog/cybersecurity-regulations-financial-industry

    Related Posts
    UK competition watchdog to probe AB Foods' Hovis purchase
    UK competition watchdog to probe AB Foods' Hovis purchase
    Trump said he has no bigger healthcare plans: Obamacare will 'repeal itself'
    Trump said he has no bigger healthcare plans: Obamacare will 'repeal itself'
    Analysis-Spanish consumer credit hits near 18-year high on economic boom
    Analysis-Spanish consumer credit hits near 18-year high on economic boom
    Maersk tests Red Sea route as Gaza ceasefire offers hope
    Maersk tests Red Sea route as Gaza ceasefire offers hope
    French court orders Shein to verify age for adult products, rejects government suspension request
    French court orders Shein to verify age for adult products, rejects government suspension request
    No drop in military aid to Kyiv since US policy shift, NATO official says
    No drop in military aid to Kyiv since US policy shift, NATO official says
    Big central banks signal rate-cut cycle is ending
    Big central banks signal rate-cut cycle is ending
    Embraer's Eve makes maiden flight of 'flying car' prototype
    Embraer's Eve makes maiden flight of 'flying car' prototype
    UK financial watchdog to investigate travel retailer WH Smith
    UK financial watchdog to investigate travel retailer WH Smith
    Presses fall silent after mobs torch offices of Bangladesh's top newspapers
    Presses fall silent after mobs torch offices of Bangladesh's top newspapers
    Ukraine can advise Poland on drone defence, Zelenskiy says in Warsaw
    Ukraine can advise Poland on drone defence, Zelenskiy says in Warsaw
    French government calls for Christmas truce in farmer protests
    French government calls for Christmas truce in farmer protests

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    More from Finance

    Explore more articles in the Finance category

    Renault escapes 'junk' bond rating after S&P upgrade

    Renault escapes 'junk' bond rating after S&P upgrade

    ECB's growth, inflation risks are large but balanced, Sleijpen says

    ECB's growth, inflation risks are large but balanced, Sleijpen says

    Italy's BPER strikes deal with unions on 800 voluntary exits, 650 hires

    Italy's BPER strikes deal with unions on 800 voluntary exits, 650 hires

    ECB policymakers not yet ready to take rate cut off the table

    ECB policymakers not yet ready to take rate cut off the table

    ECB's Santos Pereira: inflation at target, rate moves to hinge on economy

    ECB's Santos Pereira: inflation at target, rate moves to hinge on economy

    Rogue texts, aliens and a marriage proposal - welcome to Vladimir Putin's phone-in

    Rogue texts, aliens and a marriage proposal - welcome to Vladimir Putin's phone-in

    Exclusive-Nexperia's China unit switches to local firms for wafer supplies, document shows

    Exclusive-Nexperia's China unit switches to local firms for wafer supplies, document shows

    Germany headed for biggest deficit since reunification, Bundesbank says

    Germany headed for biggest deficit since reunification, Bundesbank says

    UK retailers report fall in sales ahead of Christmas, CBI says

    UK retailers report fall in sales ahead of Christmas, CBI says

    A Santa rally? Investors hope for year-end gains to cap strong 2025

    A Santa rally? Investors hope for year-end gains to cap strong 2025

    Wall St climbs on tech strength, Nike tumbles on China miss

    Wall St climbs on tech strength, Nike tumbles on China miss

    French authorities set new conditions on Nestle's Perrier production

    French authorities set new conditions on Nestle's Perrier production

    View All Finance Posts
    Previous Finance Post‘Equity like water’: do private companies need to be more liquid?
    Next Finance PostIncome diversification is not just the future: it is now