# Combatting cyber-attacks means thinking outside the box
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2017-10-31
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: How UK Bank Clearing Houses Can Tackle Cybersecurity Threats
Meta Description: Stay ahead of cybersecurity threats in the financial sector with new laws impacting bank clearing houses in the UK. Protect your data and services effectively.
URL: https://financedigest.com/combatting-cyber-attacks-means-thinking-outside-the-boxhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/fd311017-8-1736843327874-compressed.jpg)

By **Paul Darby,** Regional Manager EMEA, Vidder

![Paul Darby](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/fd311017-10-300x291-1736843327789-compressed.jpg)

Paul Darby

Over the last few months, a number of legislative and regulatory changes in relation to the threat of cyberattacks have been announced that will affect bank clearing housesin the UK. From May 2018 they will be required to complete regular cybersecurity reports, [putting regulations](https://www.financedigest.com/cash-crunch-for-british-funds-puts-regulators-under-pensions-lens.html "Cash crunch for British funds puts regulators under pensions lens") more in line with EU directives around critical infrastructure. This follows the finalisation, in 2016, of a new Network and Information Security Directive (NIS) which sets out cybersecurity obligations, including incident reporting, for operators of essential services and [digital](https://www.financedigest.com/maintaining-security-and-compliance-amid-digital-transformation-in-financial-services.html "Maintaining Security and Compliance amid Digital Transformation in Financial Services") service providers.

While there remains uncertainty over exactly how the NIS will [impact firms operating in banking](https://www.financedigest.com/the-latest-trends-in-instant-payments-and-how-they-impact-banks.html "The latest trends in instant payments and how they impact banks") and financial services, the message is clear; cybersecurity presents an increasing risk and companies across the financial sector need to take it even more seriously as attacks become more sophisticated.

According to the Verizon [2017 Data Breach Investigations Report](http://www.verizonenterprise.com/verizon-insights-lab/dbir/2017/), 24% of all breaches are in the financial services industry. Despite the fact that cyberattacks are on the increase and there is considerably more attention given in the media to the risk of ransomware in particular, too many organisations are still using [security solutions](https://www.financedigest.com/securing-financial-institutions-with-the-help-of-pam-solutions.html "Securing financial institutions with the help of PAM solutions") that were architected before the entrance of state sponsored attacks that can spread globally in days. The report [claims that companies](https://www.financedigest.com/game-company-roblox-enabled-girls-sexual-exploitation-lawsuit-claims.html "Game company Roblox enabled girl’s sexual exploitation, lawsuit claims") are choosing to accept the risk of an attack that will necessitate a ransom payment instead of investing in suitable security precautions.

Part of the difficulty in protecting against cyberattacks is that traditional security systems have become less able to protect today’s networks. Finance companies, like other enterprises, benefit from the [digital revolution](https://www.financedigest.com/the-fintech-digital-revolution-will-continue-in-2022.html "The Fintech Digital Revolution Will Continue in 2022") which allows employees, partners and customers to access information remotely and through a wide variety of devices. To keep this access secure, the solutions tend to focus on traditional network and perimeter chokepoints, forcing [security managers](https://www.financedigest.com/managing-compliance-complexity-will-deliver-security-rewards.html "Managing compliance complexity will deliver security rewards") to focus their resources on constantly tuning firewalls whilst maintaining larger access control lists with more complex access policies as networks grow in complexity. Yet once a device or user account has been compromised, predatory malware can migrate behind the perimeter and breach sensitive systems as [witnessed with the recent](https://www.financedigest.com/polypropylene-fibre-market-witness-a-spike-in-growth-pace-recent-improvements-in-pricing-models-fmi.html "Polypropylene Fibre Market Witness a Spike in Growth Pace Recent Improvements in Pricing Models: FMI") Petya and WannaCry attacks.

But networks are moving into the cloud, which means that security processes need to change to match even more complex enforcement requirements, [putting more pressure](https://www.financedigest.com/analysis-war-in-ukraine-puts-pressure-on-east-european-banks-to-prop-up-sinking-currencies.html "Analysis-War in Ukraine puts pressure on East European banks to prop up sinking currencies") on security solutions and those who administer them.

Traditional network and endpoint security solutions are no longer enough to protect critical [applications from untrusted users](https://www.financedigest.com/cable-cars-and-ropeways-market-competitive-growth-strategies-based-on-type-applications-end-user-and-region.html "Cable Cars And Ropeways Market Competitive Growth Strategies Based on Type, Applications, End User and Region") and devices, whether they are local or remote.  With the [exponential growth](https://www.financedigest.com/sales-of-electric-bicycle-motors-market-to-record-exponential-growth-during-2017-2025.html "Sales of Electric Bicycle Motors Market to Record Exponential Growth During 2017 – 2025") of access points, the control of access at the perimeter of the network is the most effective approach for the protection of data and critical services, yet the very notion of the perimeter is changing due to digitalization and IoT.  Unless they can block untrusted users and devices from the larger and more complex network, security departments are forced to address breaches reactively, which is less efficient and more expensive, and [gives hackers a first mover advantage](https://www.financedigest.com/how-automation-gives-fs-leaders-a-competitive-advantage.html "How automation gives FS leaders a competitive advantage").

One way to control access and address growing [cyber threats is to put in place](https://www.financedigest.com/is-the-next-big-cyber-threat-mis-placed-security-spending.html "Is the next big cyber threat mis-placed security spending?") more advanced trust criteria. Trusted Access Control powered by software defined perimeter (SDP) and trust assessment technology,will allow banks, clearing houses, [insurance companies and all other organisations with critical financial data](https://www.financedigest.com/the-data-driven-future-of-the-insurance-industry.html "The data-driven future of the insurance industry"), to secure their networks with a single layer of protection that combines access enforcement with trust assessment. Access is granted based on trust via application-specific tunnels which are [opened to specific services](https://www.financedigest.com/how-open-source-technology-is-securing-the-future-of-financial-services.html "How open-source technology is securing the future of financial services") after trust is determined.

The result is [enhanced security](https://www.financedigest.com/open-banking-as-a-means-to-enhance-social-commerce-security.html "Open banking as a means to enhance social commerce security") with less complexity and cost, versus adding more layers of hardware that cannot combine trust assessment with enforcement and therefore reduce protection while further increasing operating demands and making compliance audits more difficult.

Trusted Access Control has some significant [benefits in this new reality of complex networks and advanced attacks](https://www.financedigest.com/the-aftermath-of-covid-19-cybersecurity-crisis-have-the-attacks-benefitted-the-industry-more-than-they-hurt-it.html "The Aftermath of COVID-19 Cybersecurity Crisis: Have The Attacks Benefitted the Industry More Than They Hurt It?"). It is scalable and suits hybrid, growing networks. It centrally manages secure access from device and user to a [specific application](https://www.financedigest.com/application-specific-integrated-circuits-market-expected-to-reach-usd-33545-7-million-by-2026-tmr.html "Application Specific Integrated Circuits Market Expected To Reach USD 33,545.7 Million By 2026 – TMR") based on trust.It enables very granular access policies based on both a user and a device profile that are taken at the time the specific access is requested. Another advantage is that Trusted Access Control can protect applications regardless of where they reside – on premise, in a hybrid cloud and even in a public cloud.

As the industry is forced to withstand increasingly damaging cyberattacks, the necessity to find a solution that allows organisations to [move away](https://www.financedigest.com/exclusive-eu-to-move-away-from-emergency-phase-of-covid-pandemic-document.html "Exclusive-EU to move away from emergency phase of COVID pandemic – document") from a reactive to a more proactive and powerful approach becomes even greater. Tightening up [controls by making access to critical systems](https://www.financedigest.com/the-automation-control-system-market-to-see-through-the-probable-sea-change-through-digitization.html "The Automation Control System Market to see through the probable sea change through digitization") based on trust assessment could not only provide a transformation in protection levels but also deliver a key strategic advantage by reducing cost and complexity.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

