# As SaaS grows, financial services must rethink their security approach
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-08-02
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: Financial Services Industry Facing Shadow IT Threat
Meta Description: Learn about the risks of Shadow IT in financial services, from data breaches to financial loss. Uncover the impact on IT budgets and revenue. Stay informed and
URL: https://financedigest.com/as-saas-grows-financial-services-must-rethink-their-security-approachhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/graphicstock-businessman-using-laptop-with-graph-statistical-analysis-business-success-sbi-301985310-1736838080803-compressed.jpg)

_By_ **_Ben Bulpett,_** _Identity Platform Director, EMEA, SailPoint_

The financial services industry is facing an increasing number of issues related to the adoption of cloud-based services. The growth of cloud and SaaS has accelerated with the consumerisation of information technology, along with the shift to working from home. Users have become comfortable [downloading and using apps](https://www.financedigest.com/40000-downloads-of-e-money-app-devere-vault-by-end-of-2017.html "40,000+ downloads of e-money app deVere Vault by end of 2017") and services from the cloud to assist them in their work but often without explicit IT departmental approval. In fact, there are [3 to 4 times more SaaS apps in use at a company than the IT department is aware of, on average](https://www.infosecurity-magazine.com/news/data-loss-impacts-40-of-saas-app/). This is known as ‘Shadow IT’ and while it can cause headaches for any industry, [financial services](https://www.financedigest.com/as-hackers-declare-cyberwarfare-financial-services-cannot-afford-to-be-complacent.html "As hackers declare cyberwarfare, financial services cannot afford to be complacent") are open to the biggest threat.

The [data that banks hold on an individual is far more sensitive than other industries](https://www.financedigest.com/theres-nothing-artificial-about-the-role-of-ai-and-data-in-the-finance-industry.html "There’s nothing artificial about the role of AI and data in the finance industry "). By not getting approval on SaaS, the IT team have no visibility and no understanding of how to properly secure the software. One [small security](https://www.financedigest.com/security-tips-for-small-businesses.html "Security Tips For Small Businesses") slip-up and consumers can be left with very little. But it’s not just about bad security and the reputational damage that comes with it. Shadow IT can also cause [heavy financial loss](https://www.financedigest.com/uk-motor-and-home-insurers-headed-for-heavy-losses-ey-warns.html "UK motor and home insurers headed for heavy losses, EY warns").

**The risks with Shadow IT**

[Shadow IT takes up a whopping 30 to 40% of overall IT spending for large enterprises](https://www.gartner.com/smarterwithgartner/dont-let-shadow-it-put-your-business-at-risk/), according to Gartner. This means that [nearly half](https://www.financedigest.com/nearly-half-of-parents-still-give-pocket-money-to-their-adult-children.html "Nearly half of parents still give pocket money to their adult children") your IT budget is being spent on tools that teams and business units are purchasing (and using) without the IT department’s knowledge. A lot of unapproved software and services may duplicate the functionality of approved ones, meaning your company [spends money](https://www.financedigest.com/student-finances-exposed-how-do-they-really-spend-their-money.html "Student finances exposed: How do they really spend their money?") inefficiently. How does this impact overall revenue? While it depends on the industry, on average companies spend 3.28% of their revenue on IT, according to a recent study by Deloitte Insights. Banking and [securities firms spend](https://www.financedigest.com/infosecurity-europe-agenda-spotlights-innovation-as-security-leaders-address-cybersecurity-spend-in-the-face-of-economic-headwinds.html "Infosecurity Europe agenda spotlights innovation as security leaders address cybersecurity spend in the face of economic headwinds") the most (7.16%) and construction companies spend the least (1.51%).

Additionally, Shadow IT comes with a higher risk of [security and compliance](https://www.financedigest.com/fintechs-must-remove-security-and-compliance-friction-to-unlock-new-growth.html "Fintechs Must Remove Security and Compliance Friction to Unlock New Growth") complications because the tools are not properly vetted. These [risks include lack of security](https://www.financedigest.com/combating-the-security-risk-of-remote-working.html "Combating the security risk of remote working "), which can lead to data breaches. Your IT team is unable to ensure the [security of the software or services](https://www.financedigest.com/how-financial-services-are-overhauling-security-to-defend-against-spoofing-scams.html "How financial services are overhauling security to defend against spoofing scams") and can’t manage them effectively and run updates. Gartner predicts that by 2022, one-third of successful attacks experienced by enterprises will be on their shadow IT resources. If we use [Ponemon’s average breach cost of $3.86M and average probability of a breach at 27.2% annually](https://www.csoonline.com/article/3434601/what-is-the-cost-of-a-data-breach.html), Shadow IT may be costing you as much as $350,000 per year in breach-related risk costs.

**[Keeping track](https://www.financedigest.com/will-mays-new-minister-percy-keep-the-northern-powerhouse-on-track-post-brexit.html "WILL MAY’S NEW MINISTER PERCY KEEP THE NORTHERN POWERHOUSE ON TRACK POST BREXIT?") of SaaS**

Tracking your SaaS footprint goes [beyond core enterprise apps](https://www.financedigest.com/beyond-apps-and-ipads.html "Beyond apps and iPads") and spreadsheets – the reality is that this isn’t complete visibility. It’s a fraction of what’s out there, and the moment that spreadsheet is updated it’s now out of date. This approach is both time-consuming and filled with inaccuracies.

For example, if a finance director, through a cloud file storage app, shared a root-level folder with outside parties, this inadvertently [provides access to detailed financial](https://www.financedigest.com/mazars-to-acquire-financial-modelling-consultancy-and-training-provider-corality-financial-group.html "Mazars to acquire financial modelling consultancy and training provider, Corality Financial Group") statements that would never be released publicly or shared. Salaries, profit and loss, and more would be unintentionally exposed. In addition, the [finance director’s team](https://www.financedigest.com/what-skills-and-areas-of-knowledge-should-finance-teams-develop-during-2023.html "What Skills and Areas of Knowledge Should Finance Teams Develop During 2023? ") files, folders, and discussions would be made completely public rather than internal and read-only. This makes [financial files and other sensitive information indexable by search engines](https://www.financedigest.com/31972social-engineering-in-the-financial-services-people-are-the-weakest-link-in-the-security-chain.html "Social engineering in the Financial Services : People Are The  Weakest Link in the Security Chain") and the fault lies with the CISO and CIO, rather than the finance director.

Similarly, when a company is unknowingly running multiple duplicate project management apps outside of IT’s purview, spread throughout the company, this creates massive [cost overlap and security](https://www.financedigest.com/durham-county-council-reduces-data-log-analysis-costs-by-50-with-real-time-analysis-and-security-tool.html "Durham County Council reduces data log analysis costs by 50% with real-time analysis and security tool") vulnerabilities. How much sensitive data may have been [stored in the other apps](https://www.financedigest.com/apple-given-fourth-dutch-fine-in-app-store-dispute.html "Apple given fourth Dutch fine in App Store dispute")? These examples are all too common, and probably true at your own company.

**[Shining a light](https://www.financedigest.com/playground-xyz-shines-a-light-on-the-nuanced-interplay-between-context-creativity-and-attention-for-advertisers-in-new-study.html "Playground xyz shines a light on the nuanced interplay between context, creativity and attention for advertisers in new study") using identity security**

Organisations can shine a light on Shadow IT and SaaS access risk, and ultimately have greater visibility of the full scope of ungoverned SaaS applications, by using [technology such as identity](https://www.financedigest.com/top-5-trends-in-decentralised-self-sovereign-identity-ssi-and-privacy-preserving-technology-in-web-3-0.html "Top 5 trends in Decentralised Self-Sovereign Identity (SSI) and Privacy-Preserving Technology in Web 3.0 ") security. This allows them to drive a seamless [process from discovery to governance across](https://www.financedigest.com/board-report-highlights-complex-decision-making-process-across-banking-and-finance-sector.html "Board Report Highlights Complex Decision-Making Process Across Banking and Finance sector") the entirety of their SaaS app landscape and wrap the right security controls around every newly-discovered SaaS app (and the data within).

Not only does this help companies shut down issues around Shadow IT across the business, by doing so it also enables companies to be able to save [hundreds of thousands of pounds each year](https://www.financedigest.com/commonenergy-mistakes-costing-homeowners-hundreds-of-pounds-each-year.html "Commonenergy mistakes costing homeowners hundreds of pounds each year").

**Greater visibility**

It’s estimated that by 2022, nearly [90% of organisations will rely almost entirely on SaaS apps to run their business](https://cloudcomputing-news.net/news/2017/may/18/why-saas-runaway-train-s-showing-no-signs-stopping-business/). In this new era of working, the only [way to fully protect](https://www.financedigest.com/5-ways-to-protect-your-wealth-for-future-generations.html "5 Ways to Protect Your Wealth for Future Generations") today’s cloud enterprise is by first discovering all of these hidden SaaS applications and then applying the very same identity governance controls that are already in place for the rest of the critical business applications.

There is no room for mistakes. By addressing Shadow IT and SaaS access risk and having deeper visibility of the full scope of ungoverned SaaS applications, the [financial services](https://www.financedigest.com/what-can-we-learn-from-financial-services-security.html "What can we Learn from Financial Services Security?") industry can save hundreds of thousands of pounds each year. And most importantly, keep their [customers protected](https://www.financedigest.com/id-fraud-is-on-the-rise-can-financial-services-do-more-to-protect-their-customers.html "ID fraud is on the rise: can financial services do more to protect their customers?").


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

