# A Culture of Cyber Security Throughout Financial Services Organisations
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2022-08-12
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: How Financial Services Can Prevent Cyber Attacks: Insights from CISOs
Meta Description: Learn how CISOs and Risk Managers in financial services are prioritising cyber security awareness to protect against cyber attacks and data breaches in the
URL: https://financedigest.com/a-culture-of-cyber-security-throughout-financial-services-organisationshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/istock-1065824694-1736815485549-compressed.jpg)

![Michael Cantor, CIO, Park Place Technologies](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/michael-cantor-450x448-1736815485520-compressed.jpg)

_By_ **_Michael Cantor,_** _CIO, Park Place Technologies_

Financial Services organisations have long been a top target for cyber-attacks given both the nature of their financial transactions and the sensitivity of the data being held and processed. It is not just the digital transactions themselves that entice cyber criminals to regularly try and breach existing security protocols. [Financial Services’](https://www.financedigest.com/can-financial-services-brands-ever-be-credible-on-social.html "Can financial services brands ever be credible on social? ") organisations hold full Personally Identifiable Information (PII) data sets of customers, including home addresses, social security numbers, banking details, transaction history, phone numbers, email addresses, and income information.

When breaches occur with this level of dependency information, cyber criminals can go on to easily access accounts, copy payment cards and make fraudulent purchases. Unsurprisingly, breaches are incredibly bad news and high [impact in this sector](https://www.financedigest.com/tomorrows-world-how-cloud-computing-will-impact-the-financial-services-sector-in-2016.html "TOMORROW’S WORLD: HOW CLOUD COMPUTING WILL IMPACT THE FINANCIAL SERVICES SECTOR IN 2016") as they undermine customer confidence, create large compensation cases, and regularly cause large fines for non-compliancy of data protection regulations (GDPR).

**CISOs and** [Risk Managers](https://www.financedigest.com/aon-announces-agreement-to-acquire-risk-management-firm-creating-a-comprehensive-cyber-risk-management-advisory-group.html "Aon announces agreement to acquire risk management firm, creating a comprehensive cyber risk management advisory group")

Creation of a complete culture of cyber [security that spans right across financial](https://www.financedigest.com/post-brexit-uk-workers-can-have-financial-security.html "Post Brexit – UK workers CAN have financial security") establishments has therefore been a high priority for CISOs and Risk Managers in the finance arena, who find themselves at the forefront of the fight to engineer, foster and encourage a culture of pervasive cyber security awareness. These financial CISOs are the risk management professionals who live and breathe with the knowledge that any lapse by any employee can leave the entire organization exposed and vulnerable, and who understand the importance and safety that adherence to a detailed [cyber security](https://www.financedigest.com/how-to-handle-cyber-security-during-mergers-and-acquisitions.html "How to Handle Cyber Security during Mergers and Acquisitions") plan, unique to their organization, brings. [Financial establishments and financial services](https://www.financedigest.com/how-crowdsourcing-can-help-drive-the-benefits-of-advanced-analytics-in-financial-services.html "HOW CROWDSOURCING CAN HELP DRIVE THE BENEFITS OF ADVANCED ANALYTICS IN FINANCIAL SERVICES") have, more than any other sector, seen heightened advances in digital innovations through internet banking, mobile apps, and instant payments – and all occurring within a relatively short timescale.  Such fast adoption of new technology platforms can cause a perfect storm of vulnerabilities largely through lack of familiarity, potentially increasing the [finance industry’s](https://www.financedigest.com/theres-nothing-artificial-about-the-role-of-ai-and-data-in-the-finance-industry.html "There’s nothing artificial about the role of AI and data in the finance industry ") attack vector.

Given the scope of the threat, no one CISO or group of [cyber security](https://www.financedigest.com/the-future-of-cyber-security.html "THE FUTURE OF CYBER SECURITY") specialists can be completely responsible for stemming attacks or changing employee behaviours. The requirement to create a pervasive culture of accountability for cyber security in [finance has never been more critical with such a surge in digital innovation](https://www.financedigest.com/innovations-in-finance.html "Innovations in finance"). Some CISOs struggle to gain immediate [internal acceptance of cyber initiatives as they invariably increase extra security](https://www.financedigest.com/the-financial-sector-must-act-to-tackle-internal-data-security.html "THE FINANCIAL SECTOR MUST ACT TO TACKLE INTERNAL DATA SECURITY") processes or in more extreme scenarios, can initially decrease productivity levels as users grapple with additional layers and verifications. Instead, CISOs should embark on a graduated path of security sensitivities. There are three routes in this journey that CISOs need to develop.

**Understanding Roles**

First, if they are to successfully increase defences, CISOs need to fully understand [roles and processes in the existing regime to understand why and when job](https://www.financedigest.com/amazon-ceo-says-job-cuts-to-exceed-18000-roles.html "Amazon CEO says job cuts to exceed 18,000 roles") functions rely on systems that could pose and increase vulnerabilities. Secondly, as with all successful change, CISOs should spend the first months of cyber change initiatives on the ground, familiarising themselves with workflows and identifying suitable departmental ‘champions’ who can act as envoys or ambassadors. They will [become practical flag bearers for ongoing change](https://www.financedigest.com/quidditch-becomes-quadball-as-sports-bodies-change-name.html "Quidditch becomes quadball as sport’s bodies change name") who will be on-point for communications for threat handling and remediation. These departmental cyber champions will also field questions and interactions about cyber concerns, as you would with a local [Health and Safety](https://www.financedigest.com/occupational-health-and-safety-must-be-brought-back-to-the-forefront-of-esg.html "Occupational Health and Safety must be brought back to the forefront of ESG") Officer. Creating any true culture change needs to facilitate [two-way communications](https://www.financedigest.com/dodge-a-bullet-with-the-insurance-act-2015-act-now-to-implement-two-way-communication.html "Dodge a bullet with the Insurance Act 2015: Act now to implement two-way communication") from day one and needs to embrace everyone, so selecting the right team is essential. Recognised accredited [cyber training relevant to the expected outcomes of a cyber ambassador is critical here as responsibilities](https://www.financedigest.com/aon-introduces-new-cyber-solution-in-response-to-eu-regulation-on-data-protection.html "Aon introduces new cyber solution in response to EU regulation on data protection") move outside of IT. Not only does individualised cyber training bring empowerment and extra capabilities internally, but it [leads to personal recognition that reflects positively](https://www.financedigest.com/leading-payment-platform-appoints-new-key-positions-to-help-with-growth.html "Leading Payment Platform Appoints New Key Positions to Help With Growth") on future career opportunities.

Once a thorough understanding and a development of a [network of cyber](https://www.financedigest.com/uks-morgan-advanced-materials-reports-cyber-security-incident-on-its-network.html "UK’s Morgan Advanced Materials reports cyber security incident on its network") ambassadors has occurred, CISOs need to quickly move to developing extra employee security practices and providing direction on ongoing cadences. But these new or enhanced security prevention measures invariably add to the [time that it takes for employees to finish jobs](https://www.financedigest.com/britains-purplebricks-to-cut-more-than-10-of-jobs-the-times.html "Britain’s Purplebricks to cut more than 10% of jobs – The Times"). Collective attitudes towards prioritising cyber – and by extension, creating a cyber culture – can only be changed by first educating [employees on the importance](https://www.financedigest.com/why-is-employee-reward-and-recognition-so-important.html "Why is employee reward and recognition so important?") and rationale in changing behaviours or methods of completing a task. This education process can take many forms, starting with various impacts via a series of simple simulated [attacks that provide anonymised responses back to risk](https://www.financedigest.com/preventing-an-operationally-crippling-ransomware-attack-do-you-know-where-your-risk-exposure-lies.html "PREVENTING AN OPERATIONALLY CRIPPLING RANSOMWARE ATTACK – DO YOU KNOW WHERE YOUR RISK EXPOSURE LIES?") professionals to highlight gaps in knowledge and provide early indicators on how easily breaches can occur and how fast new cyber processes can be adopted. Additionally, real world documented examples are often used to show how breaches have been catastrophic in similar sized organisations. Ongoing interactive education is [key to building a continued culture of security](https://www.financedigest.com/2023-fintech-prediction-secure-and-private-data-usage-is-key.html "2023 FinTech Prediction: Secure and Private Data Usage is Key"). Education and learnings on the impact of the breach ramifications – from board level to new recruits – is essential, at all times building [cyber security](https://www.financedigest.com/why-preparation-for-new-swift-cyber-security-standards-needs-to-start-now.html "‘Why preparation for new SWIFT cyber security standards needs to start now’") as an enabler rather than another workflow process to achieve. Successful [financial companies who avoid security](https://www.financedigest.com/what-can-we-learn-from-financial-services-security.html "What can we Learn from Financial Services Security?") breaches on an ongoing basis additionally bring the importance of cyber security into annual employee reviews, keeping it top of mind and primary to employees’ performance (and renumeration). HR therefore also play a key part determining a blame-free, but [responsible and empowering security](https://www.financedigest.com/assurance-v-security-reassessing-responsibility-for-data-assurance.html "Assurance v Security: Reassessing Responsibility for Data Assurance") culture.

**Empowering Employees**

Establishing a culture means by its very nature, that all are driving towards the same goal. That means gentle, but constant re-enforcement. And here’s where the third part of [cyber empowerment needs](https://www.financedigest.com/the-financial-services-industry-needs-to-get-serious-about-cyber-security-in-the-covid-19-era.html "The financial services industry needs to get serious about cyber security in the Covid-19 era") a careful balance to avoid falling into negative scare tactics or blame. Financial CISOs, for their part, need to at all times, empower employees with the right tools and resources to intelligently identify, question and report suspected attacks. They also need to deploy easy to use, reliable preventative tools such as password [managers and dependable email security](https://www.financedigest.com/managing-the-hidden-security-gap-in-financial-services-the-office-printer.html "MANAGING THE HIDDEN SECURITY GAP IN FINANCIAL SERVICES: THE OFFICE PRINTER") software, while not neglecting their own role in the ongoing monitoring of asset discovery to see which assets and software are lurking in the infrastructure (or may have been recently added to the infrastructure). Endpoint security, especially in hybrid environments, is more important than ever in these environments.

Once a culture exists internally, next, CISO attention must [turn towards](https://www.financedigest.com/entrepreneurs-worldwide-turn-their-focus-towards-doing-good.html "ENTREPRENEURS WORLDWIDE TURN THEIR FOCUS TOWARDS DOING GOOD") suppliers and partners who themselves can create an entry point for breach. This can be achieved by clearly setting the [organisations cyber](https://www.financedigest.com/auditing-in-cyber-how-organisations-can-keep-track-of-their-data.html "AUDITING IN CYBER: HOW ORGANISATIONS CAN KEEP TRACK OF THEIR DATA") security expectations up front and asking suppliers to prove compliance and adherence towards these standards, but within a reasonable, pre-agreed timeframe.

Creating this inherent cyber culture can only occur through ongoing education and training of employees on the ever-changing threat landscape and linking the importance and rationale to adopt best practices. To achieve an ongoing culture of acceptance, cyber security [must](https://www.financedigest.com/why-the-finance-sector-must-prioritise-mobile-security-over-innovation.html "Why the finance sector must prioritise mobile security over innovation") clearly help employees get their jobs done so that being security conscious is a positive, ongoing experience for any financial services business.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

