# Finance Sector Faces Three-Pronged Challenge On Data Security
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2017-11-16
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: Financial Services Facing Cyber Attacks: GDPR &amp; More
Meta Description: Discover why financial services are facing cyber threats and regulatory challenges, and how to turn GDPR compliance into a business opportunity.
URL: https://financedigest.com/finance-sector-faces-three-pronged-challenge-on-data-securityhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/fd161117-2-1736843257524-compressed.jpg)

**_-GDPR remains the priority but financial services also facing challenge from PSD2 and MiFID II-_**

![Steve Inglessis](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/fd161117-4-300x300-1736843257373-compressed.jpg)

Steve Inglessis

In the early days, cybersecurity was much easier; businesses could protect critical information by hiding it behind a firewall on a physical server somewhere that could only be accessed by authorised individuals.

In the last five – or even ten – years however, protecting data has become considerably more difficult and complex. The growing use of smartphones, cloud computing technology, IoT-enabled devices and the availability of information have made it easier than ever for businesses to be exposed online – anywhere and at any time. The simple fact is that in 2017, anyone with a [mobile phone could pose a potential threat to the most “sophisticated” of security](https://www.financedigest.com/why-the-finance-sector-must-prioritise-mobile-security-over-innovation.html "Why the finance sector must prioritise mobile security over innovation") systems.

Earlier in 2017, we witnessed two of the most devastating [cyber attacks](https://www.financedigest.com/lloyds-of-london-investigates-possible-cyber-attack.html "Lloyd’s of London investigates possible cyber attack") of the year: WannaCry and Petya. The [WannaCry attack brought down parts of the UK’s National Health Service](https://www.theguardian.com/technology/2017/jun/27/petya-ransomware-cyber-attack-who-what-why-how) (NHS), along with Spain’s Telefonica, FedEx and Deutsche Bahn also being hit. Petya, on the other hand, took over a number of computers and demanded $300, paid in Bitcoin. The malware caused serious disruption at large firms in Europe and the US, including the advertising firm WPP, Saint-Gobain and Russian steel and oil firms Evraz and Rosneft, [according to The Guardian](https://www.theguardian.com/technology/2017/jun/27/petya-ransomware-cyber-attack-who-what-why-how).

The [finance and banking industry](https://www.financedigest.com/how-is-green-finance-reshaping-the-banking-industry.html "How is green finance reshaping the banking industry?"), more so than any other – is routinely targeted. In the UK alone, [75 cyber attacks on financial services took place in 2016](https://www.ft.com/content/66c95bc0-71b8-3adc-9e35-bef3e67b9292) – a staggering amount compared to the five that took place in 2014. The Financial Conduct Authority (FCA) acknowledged that cyber attacks were increasing rapidly, year-on-year; five in 2014, 27 in 2015 and 75 in 2016.

But it’s not just cyber attacks that are forcing those in the [financial services sector](https://www.financedigest.com/iot-for-the-financial-sector.html "IoT for the Financial Sector") to re-evaluate their defences, but also the arrival of new regulations in the form of a three-pronged assault: the General Data Protection Regulation (GDPR), the Markets in Financial Instruments Directive (MiFID II), and the EU’s Payment Services Directive (PSD2).

Adhering to these regulations – particularly GDPR – might seem like a compliance burden, but it could yet be turned into an [opportunity for businesses](https://www.financedigest.com/thoracic-drainage-devices-market-rising-new-business-opportunities-for-investors.html "Thoracic Drainage Devices Market Rising New Business Opportunities for Investors").

_DataRaze’s_ _Commercial Director, Steve Inglessis, discusses how financial services firms can prepare ahead of GDPR – sharing some top tips and highlighting why GDPR is not a compliance burden but, actually, an opportunity._ **Know where your data is**

While the trio of regulations all present challenges, GDPR is, at the moment, the biggest concern. [Statistics from Gartner](http://www.gartner.com/newsroom/id/3701117) suggests as many as 50% of companies affected by the regulation are still not in full compliance.

However, according to data from Network Group Events’ 2017 Financial Services Information Security Network, 52% of chief information security officers working in the finance sector have made [GDPR compliance an investment priority](http://www.computerweekly.com/news/450418886/Financial-services-CISOs-prioritise-GDPR-but-their-service-providers-might-not-have).

The fact is that the volume of data we create is rapidly increasing – [every day we create 2.5 quintillion bytes of data](https://www-01.ibm.com/common/ssi/cgi-bin/ssialias?htmlfid=WRL12345USEN) – that data is varied in both size and complexity; both structured and unstructured. As a result, businesses are increasingly data-driven, utilising large quantities of data to better understand business performance, collate insights and identify opportunities to improve. This process typically involves a number of solutions – each collecting, analysing and managing data. Of course, while businesses benefit tremendously from the insights gleaned from the data analysis, often [information is scattered across systems](https://www.financedigest.com/the-cardiovascular-information-systems-market-is-expected-to-grow-on-a-persistent-note-in-the-future.html "The Cardiovascular Information Systems Market is expected to grow on a persistent note in the future") – from legacy hardware to cloud-based platforms. Consequently, a unified and holistic view of data can be hard to achieve.

Knowing where your customers’ data is kept at all [times is a major step](https://www.financedigest.com/deliveroos-financial-hot-potato-time-for-new-cfo-to-step-up-to-the-plate.html "Deliveroo’s Financial Hot Potato: Time for new CFO to step up to the plate") to being GDPR compliant. Traditionally, the view has been that more data equals more value, but this is not the case – it’s about data quality. Also, employees within the business might be using a variety of Shadow IT solutions (i.e. solutions outside of the business’ standard IT infrastructure) to manage data – making it harder for you to understand your [current data](https://www.financedigest.com/cbd-gummies-market-current-scenario-and-industry-growth-forecast-with-major-key-players-data-2030.html "CBD Gummies Market| Current Scenario and Industry Growth Forecast with Major Key Players data 2030") procedures, as well as exposing your business to potential data security risks.

There’s also the problem of PSD2 to consider. PSD2 will effectively break down the bank’s monopoly on its users’ data – allowing third-party ‘merchants’, like tech companies for example, to retrieve account data directly from the bank – with the consumer’s permission, of course. It means that, with the consumer’s permission, third-party vendors can make a payment for you, rather than you having to be redirected to another service, such as PayPal or Visa.

From the perspective of both regulations, then, how that data is stored and transferred will, therefore, be crucial to ensuring compliance to both regulations. Financial [services firms will need to look at maintaining the necessary level of data transparency to fulfil](https://www.financedigest.com/e-commerce-fulfillment-services-market-to-reflect-impressive-growth-rate-to-during-forecast-period-observes-tmr.html "E-commerce Fulfillment Services Market to Reflect Impressive Growth Rate to During Forecast Period, Observes TMR") the requirements of PSD2, but also balancing the problem of “sensitive” data and ensuring they have acquired consent from the account holder to distribute information. Both parties – the bank and the third-party vendor – will need to have a clear process.

Taking the time to understand how your business captures, stores and processes [data will help to streamline the process and standardise the systems](https://www.financedigest.com/interoperability-of-data-to-accelerate-the-whole-slide-imaging-systems-market.html "Interoperability of data to accelerate the Whole Slide Imaging Systems Market") you use. Taking these steps will enable you to assess current [risk levels and develop an approach](https://www.financedigest.com/demystifying-us-feds-approach-on-systemic-climate-risk-stress-testing.html "Demystifying US Fed’s approach on Systemic Climate Risk Stress Testing") to GDPR-compliant data management. Also, by having good [data quality and storage](https://www.financedigest.com/data-storage-market-revenue-is-expected-to-increase-at-a-cagr-of-13-6-during-2021-2025.html "Data Storage Market revenue is expected to increase at a CAGR of 13.6% during 2021-2025"), meeting the requirements of PSD2 will be made significantly easier.

**Establish data governance framework**

With data volume growing so fast – and GDPR fast approaching – information [management needs to change](https://www.financedigest.com/uk-at-forefront-of-fx-management-change.html "UK at Forefront of FX Management Change"). GDPR states that businesses can only capture data for the purpose it is required, meaning firms will not be able to record information other than that which is stated. Therefore, [financial firms need to first establish a data](https://www.financedigest.com/big-data-analytics-fraud-prevention-in-the-financial-sector.html "BIG DATA, ANALYTICS & FRAUD PREVENTION IN THE FINANCIAL SECTOR") governance framework, one that ensures that only the right, high-qualitydata is collected and for the intended purpose, and then proceed to carefully dispose of data which they do not need.

This will involve updating existing IT infrastructure and improving data security measures, [moving to scalable cloud-based solutions to support more streamlined data](https://www.financedigest.com/dollar-moves-off-lows-on-heels-of-inflation-data.html "Dollar moves off lows on heels of inflation data") management in line with new policies. It is vital however, that legacy IT assets and data is completely destroyed and financial firms [need](https://www.financedigest.com/global-crises-that-need-the-finance-industry.html "Global Crises That Need The Finance Industry") to be sure any data disposal is compliant with new regulations.

Enlisting the services of a professional, external data disposal firm, could help with this and ensure any destruction is carried out professionally.

It is important to remember though, that even if you outsource the [data destruction, your company is still responsible if this isn’t carried out properly so businesses should make sure they obtain a robust chain of custody to ensure data is destroyed safely](https://www.financedigest.com/your-money-is-safe-but-your-data-might-not-be.html "YOUR MONEY IS SAFE, BUT YOUR DATA MIGHT NOT BE") and correctly to avoid potential problems down the line.

Remember, good data governance is not just about the collection of high-quality data, but also having a robust, industry-compliant and risk-free data disposal method.

There’s also [MiFID II](https://www.fca.org.uk/markets/mifid-ii) to be accounted for. Under MiFID II, firms are required to store recordings of all conversations related to a deal – even if the conversations do not lead to a transaction – for five years. Also, how that information is recorded is irrelevant. On the other hand, GDPR mandates that personal data should be kept in an identifiable format for no longer than necessary. How do financial [services firms balance](https://www.financedigest.com/balancing-innovation-and-security-within-the-financial-services-industry.html "Balancing innovation and security within the financial services industry") the two regulatory requirements? Firms will need to regularly review the necessity of the records in light of both MiFID II and GDPR, obtaining consent for recordings where legally required to do so.

Firms **must** be able to demonstrate that they have kept to the requirements of both regulations. Of course, the record keeping process will need to be regularly reviewed, but thinking about the process now, rather than later, will put [businesses in a good position for the future](https://www.financedigest.com/title-homeopathic-veterinary-medicines-market-growing-at-a-cagr-of-5-business-and-future-opportunity-2031.html "Title: Homeopathic Veterinary Medicines Market Growing at a CAGR of ~5% | Business and Future Opportunity – 2031").

Also, [firms will need to invest](https://www.financedigest.com/toshiba-in-talks-with-four-investment-firms-for-strategic-ideas-sources.html "Toshiba in talks with four investment firms for strategic ideas -sources") in the right technology that makes the capturing of information compliant under both MiFID II and GDPR. A single solution for call recording – used by everyone in the business – will be absolutely necessary and consent **must** be acquired for every call.

**Protect your data and achieve transparency**

Many [financial service firms share information](https://www.financedigest.com/overcoming-information-overload-in-the-financial-sector.html "OVERCOMING INFORMATION OVERLOAD IN THE FINANCIAL SECTOR") with third parties, such as clients, suppliers, regulators or partners but as GDPR puts increased accountability on data processors, the controller/processor relationship becomes even more important.

Should one fail to protect that data in line with GDPR standards, the other will be held accountable too. To ensure ongoing compliance, financial [services firms must](https://www.financedigest.com/as-saas-grows-financial-services-must-rethink-their-security-approach.html "As SaaS grows, financial services must rethink their security approach") have a handle on all of its existing data.

This includes data ownership, as well as access and data usage, and record that information in a central location – something that will be increasingly important as PSD2 comes into play. As that data is transferred to a third party, the interaction needs to be recorded and the third party must have a system in place that compiles clear and [detailed reports](https://www.financedigest.com/chromoendoscopy-agents-market-2031-report-details-the-future-development-manufacturers-trends-share-size-and-forecast.html "Chromoendoscopy Agents Market 2031 Report Details the Future Development, Manufacturers, Trends, Share, Size and Forecast") on how the data is being used and interacted with.

Ultimately, while GDPR and other incoming, stricter, data [security regulations present a lot of work for financial](https://www.financedigest.com/post-brexit-uk-workers-can-have-financial-security.html "Post Brexit – UK workers CAN have financial security") firms, taking the steps above will pave the way to ongoing compliance, enabling them to increase efficiency and productivity. Companies which are ultimately able to demonstrate better compliance and [data security will inevitably gain](https://www.financedigest.com/global-shares-slide-dollar-gains-as-rates-rise-on-strong-data.html "Global shares slide, dollar gains as rates rise on strong data") the trust of customers, as well as avoiding the fines and punishments facing them from May 25, 2018.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

