# Check, Please! Adding up the Costs of a Financial Data Breach
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2020-11-22
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: How Financial Services Can Safeguard Their Data and
Meta Description: Learn how financial services can safeguard sensitive data in emails to prevent costly breaches. Discover top cybersecurity strategies here.
URL: https://financedigest.com/check-please-adding-up-the-costs-of-a-financial-data-breachhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/untitled-design-2020-11-23t012933-1736838710117-compressed.jpg)

_By_ **_Andrea Babbs,_** _UK General Manager, VIPRE_

Reliance on email as a fundamental function of business communication has been in place for some time. But as remote working has become a key factor for the majority of business during 2020, it’s arguably more important than ever as a communication tool. The fact that roughly [206.4 billion](https://www.statista.com/statistics/456500/daily-number-of-e-mails-worldwide/) emails are sent and received each day means we’re all very familiar with that dreaded feeling of sending an email with typos, with the wrong attachment, or to the wrong contact. But this can be more than just an embarrassing mistake – the ramifications could, in fact, be catastrophic.

In particular, for the [financial services industry that deals with highly sensitive information including monetary transactions and financial data](https://www.financedigest.com/data-centres-and-the-changing-financial-trading-landscape.html "Data centres and the changing financial trading landscape"), the consequences of this information falling into the wrong hands could mean the loss of significant sums of money. Emails of this nature are the Holy Grail for cyber criminals. So how can [financial services organisations keep their confidential information secure to safeguard their data](https://www.financedigest.com/big-data-analytics-fraud-prevention-in-the-financial-sector.html "BIG DATA, ANALYTICS & FRAUD PREVENTION IN THE FINANCIAL SECTOR") and reputation? Andrea Babbs, UK General Manager, VIPRE, explains.

**How much?**

According to research from Ponemon Institute in its [Cost of a Data Breach Report 2020](https://www.ibm.com/uk-en/security/data-breach), organisations spend an average of $3.85 million recovering from security incidents, with the usual time to identify and contain a breach being 280 days. Accenture’s 2019 Ninth Annual Cost of Cybercrime found that financial services incurred the highest cybercrime costs of all industries. And while examples of external threats seem to make the headlines, such the [Capital One](https://www.capitalone.com/facts2019/) cyber incident, unintentional or insider breaches don’t always garner as much attention. Yet they are both as dangerous as each other. In fact, [human errors](https://www.financedigest.com/outthink-raises-10-million-to-tackle-human-errors-behind-data-breaches.html "OutThink raises million to tackle human errors behind data breaches") (including misdeliveries via email) are almost twice as likely to result in a confirmed data disclosure.

[Costs will be wide](https://www.financedigest.com/caixabank-proposes-sector-wide-freeze-in-variable-mortgage-costs-source-says.html "Caixabank proposes sector-wide freeze in variable mortgage costs, source says") ranging depending on the scale of each breach, but at a minimum there will be financial penalties, costs for audits to understand why the incident happened and what additional protocols and solutions need to be implemented to prevent it from happening in the future. There could also be huge costs involved for reimbursing customers who may have been affected by the breach in turn.

**Priceless damage**

The fallout from [data breaches](https://www.financedigest.com/when-not-if-why-a-data-breach-response-plan-is-more-important-now-than-ever.html "When not if: why a data breach response plan is more important now than ever") goes far beyond that of financial penalties and costs. Financial [services](https://www.financedigest.com/integrated-finance-the-advantages-of-using-financial-infrastructure-as-a-service.html "Integrated Finance: the advantages of using financial-infrastructure-as-a-service") businesses have reputations to uphold in order to maintain a loyal customer base. Those that fail to protect their customers’ sensitive information will have to manage the negative press and mistrust from existing and potential customers that could seriously impede the organisation as a whole. Within such a highly [competitive market](https://www.financedigest.com/apac-solar-micro-inverters-market-competitive-growth-strategies-based-on-type-applications-end-user-and-region.html "APAC Solar Micro Inverters Market Competitive Growth Strategies Based on Type, Applications, End User and Region"), it doesn’t take much for customers to take their money elsewhere – customer service and reputation is everything.

**Check, please!**

Within the financial [services sector](https://www.financedigest.com/how-communication-technology-can-help-relieve-pressure-on-staff-in-the-financial-services-sector.html "How communication technology can help relieve pressure on staff in the financial services sector "), the stakes are high, so an effective, layered cybersecurity strategy is essential to mitigate risk and keep sensitive information secure. With this, there are three critical components that must be considered:

1. **Authentication and encryption:** Hackers may try to attack [systems directly or intercept emails via an insecure transport](https://www.financedigest.com/intelligent-transport-systems-its-market-2021-by-global-key-players-types-applications-countries-industry-size-and-forecast-to-2027.html "Intelligent Transport Systems (ITS) Market 2021 by Global Key Players, Types, Applications, Countries, Industry Size and Forecast to 2027") link. Security protocols are designed to prevent most instances of unauthorised interception, content modification and email spoofing. Adding a dedicated email to email encryption [service to your email security](https://www.financedigest.com/facilitating-open-finance-through-secure-services.html "Facilitating open finance through secure services") arsenal increases your protection in this area. Encryption and authentication, however, do not safeguard you against human errors and misdeliveries.
2. **Policies and training:** [Security](https://www.financedigest.com/top-fintech-trends-for-2021-enabling-smart-and-secure-finance.html "Top Fintech Trends for 2021 Enabling Smart and Secure Finance") guidelines and rules regarding the circulation and storage of sensitive financial information are essential, as well as clear steps to follow when a security incident happens. Employees [must undergo cyber security](https://www.financedigest.com/the-three-must-haves-of-cyber-security-that-you-need-to-stay-cyber-safe.html "The three “must haves” of cyber security that you need to stay cyber safe") awareness training when they join the organisation and then be enrolled in an ongoing programme with quarterly or monthly short, informative sessions. This training should also incorporate ongoing phishing simulations, as [well as simulated phishing attacks](https://www.financedigest.com/tennis-panic-attack-ends-tsurenkos-indian-wells-as-raducanu-marches-on.html "Tennis-Panic attack ends Tsurenko’s Indian wells, as Raducanu marches on") to demonstrate to users how these incidents can appear, and educate them on how to spot and flag them accordingly. Moreover, [automated phishing simulations can also provide key metrics and reports](https://www.financedigest.com/impact-com-named-a-market-leader-in-research-in-actions-partner-management-automation-report-and-in-g2-winter-reports.html "impact.com Named a Market Leader in Research in Action’s Partner Management Automation Report and in G2 Winter Reports") on how users are improving in their training. This reinforcement of the security messaging, [working in tandem with simulated phishing attacks ensures that everyone is capable of spotting a phishing scam or knows how to handle sensitive information](https://www.financedigest.com/the-importance-of-information-security-in-a-post-pandemic-hybrid-working-world.html "The importance of information security in a post-pandemic hybrid working world") as they are aware and reminded regularly of the risks involved.
3. **Data loss prevention (DLP):** DLP [solutions enable the firm to implement security](https://www.financedigest.com/securing-financial-institutions-with-the-help-of-pam-solutions.html "Securing financial institutions with the help of PAM solutions") measures for the detection, control and prevention of risky email sending behaviours. Fully technical solutions such as machine learning can go so far to prevent breaches, but it is only the human element that can truly decipher between what is safe to send, and what is not. In practice, machine learning will either stop everything from being sent – becoming more of a nuisance than support to users – or it will stop nothing. Rather than disabling [time saving](https://www.financedigest.com/modernisation-of-insurance-technology-saves-invaluable-time-and-money.html "Modernisation of insurance technology saves invaluable time and money") features such as autocomplete to prevent employees from becoming complacent when it comes to selecting the right email recipient, DLP solutions do not impede the working practices of users but instead give them a critical second chance to double check.

It is this double check that can be the critical factor in an organisation’s cybersecurity efforts. Users can be prompted based on several parameters that can be specified. For example, colleagues in different departments exchanging confidential documents with each other and external suppliers means that the TO and CC fields are likely to have multiple recipients in them. A simple incorrect [email address](https://www.financedigest.com/how-to-create-a-professional-email-address.html "How to Create a Professional Email Address"), or a cleverly disguised spoofed email cropping up with emails going back and forth is likely to be missed without a tool in place to highlight this to the user, to give them a chance to double check the accuracy of email recipients and the contents of attachments.

**Conclusion**

Email remains a risky, yet [essential tool for every business](https://www.financedigest.com/business-texting-an-essential-communication-tool.html "Business Texting: An Essential Communication Tool"). But with a layered [security strategy](https://www.financedigest.com/security-trumps-obesity-in-britains-first-food-strategy.html "Security trumps obesity in Britain’s first food strategy") in place consisting of training, authentication tools and DLP solutions, organisations can minimise the risks involved and take a proactive approach to their cyber defences.

Given the nature of the industry, financial services organisations are a prime target for cyber criminals. The temptation of personal information and financial transactions for hackers is never going to dwindle, so financial institutions must prioritise [cyber security](https://www.financedigest.com/industrial-cyber-security-solutions-and-services-strong-increase-in-user-base-pans-out-for-north-america-to-lead-market.html "Industrial Cyber Security Solutions and Services – Strong Increase in User Base Pans Out for North America to Lead Market"), regularly assessing risks, deploying innovative, human-led solutions and educating workforces to provide the best defence possible.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

