# How finance firms can unify two data approaches to improve both compliance and security
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-10-14
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: Unified Data Governance &amp; Security for Finance: The
Meta Description: Discover how finance firms can efficiently manage data governance, GDPR compliance, and cyber security threats with a unified approach, explained by database
URL: https://financedigest.com/how-finance-firms-can-unify-two-data-approaches-to-improve-both-compliance-and-securityhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/graphicstock-top-view-of-man-sitting-at-the-table-analyzes-performance-and-looking-at-phone-in-office-back-view-coworkingr880ovq3g-1-1-1736837559440-compressed.jpg)

_By **David Walker,** Field CTO, EMEA,_ [_Yugabyte_](https://www.yugabyte.com) _, the leader in open-source distributed SQL databases._

![](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/a5-1736837559450-compressed.jpg)

_Finance and banking organisations often pay two teams of specialists to do two apparently different things, but if you open the lid, they’re actually very similar processes at the data level. What if organisations could do both, and in a secure and technically superior way, wonders database sector veteran David Walker?_

It’s no longer constantly in the headlines, but GDPR (General Data Protection Regulation) remains a challenge for any organisation trying to operate in the EU: since ratification in May 2018, [the total fine count to date](https://www.dlapiper.com/en/uk/insights/publications/2021/01/dla-piper-gdpr-fines-and-data-breach-survey-2021/) for member states is over $330m (June 2021 figures).

For finance firms, the need to be able to securely and accurately place, move, archive and audit data in multiple applications and meet GDPR is challenging enough. That complexity just goes up several notches when it is across multiple countries; and increases again when these countries are in many regions, initiating all kinds of cross border, multi-data protection legislative norms, too.

Data leaks remain a concern, and not having the appropriate [controls over that data](https://www.financedigest.com/dollar-buoyant-as-robust-u-s-data-keep-fed-hawks-in-control.html "Dollar buoyant as robust U.S. data keep Fed hawks in control") is an executive nightmare. Not having the appropriate controls in each and every geographical location could not only disable your ability to trade, it could also be a risk for the [company if you end up incurring a financial](https://www.financedigest.com/how-financial-services-companies-can-successfully-utilise-low-code-and-no-code-technologies.html "How financial services companies can successfully utilise low-code and no-code technologies") penalty. So data governance and geo-location should be a number one priority; but, just as critically, you also need to be constantly shoring up the corporate defences against cyber security threats, which the FBI says is increasing [“exponentially”](https://www.theguardian.com/us-news/2021/jun/04/fbi-christopher-wray-cyberattacks-9-11) and is approaching the 9/11 threat levels.

**_The power of two parallel processes_**

There are two very [important business processes](https://www.financedigest.com/5-reasons-why-modernising-is-the-most-important-ongoing-process-for-any-business.html "5 Reasons Why Modernising Is The Most Important Ongoing Process For Any Business") around securing data—one compliance-oriented, one IT security oriented. Compliance is ultimately about telling the organisation to look after the data, and on the security side, it’s the practice of making data [handling function as secure](https://www.financedigest.com/how-to-handle-cyber-security-during-mergers-and-acquisitions.html "How to Handle Cyber Security during Mergers and Acquisitions") as possible. Regulations like GDPR are all about you being able to always know where the data is and who is handling it, and whether it can be shared with somebody else; [security is about systems where you have identified the sensitive data](https://www.financedigest.com/the-financial-sector-must-act-to-tackle-internal-data-security.html "THE FINANCIAL SECTOR MUST ACT TO TACKLE INTERNAL DATA SECURITY") and putting roles around it to make sure that only the right people can handle it and that it can’t be accessed illegally. But, for finance firms, there is commonality here; as both are about data, yet they are often pursued not as one task, but two. Why is this?

Until now, organisations have found it simpler to deal with the twin challenge with two different groups of specialists: compliance people who are looking after the regulations like GDPR or UK [financial services](https://www.financedigest.com/financial-services-firms-turn-to-big-data-intelligence-to-fight-fraudulent-activity-according-to-xerox-study.html "FINANCIAL SERVICES FIRMS TURN TO BIG DATA INTELLIGENCE TO FIGHT FRAUDULENT ACTIVITY ACCORDING TO XEROX STUDY") regulations, for example, and security teams who are tasked with looking after the security of customer and company data to ensure that it can’t be taken by hackers. They have ended up as discrete specialties because there have historically been additional layers of work needed on each side in both implementation and technical terms, and as a result the [CEO must talk to two different sets](https://www.financedigest.com/unilever-ceo-set-to-leave-after-gsk-debacle-arrival-of-activist-investor.html "Unilever CEO set to leave after GSK debacle, arrival of activist investor") of practitioners about the company’s data.

However, the objective of that CEO’s [compliance expert is setting out the principles that only the people who need to see the data](https://www.financedigest.com/britain-plans-new-data-rules-to-ease-compliance-burden.html "Britain plans new data rules to ease compliance burden") can handle it—defining its proper use. But [isn’t that what her security](https://www.financedigest.com/the-challenge-of-keeping-data-secure-why-in-house-security-isnt-enough.html "The challenge of keeping data secure: why in-house security isn’t enough") colleague is also trying to do? Although [finance and banking organisations for technical reasons](https://www.financedigest.com/4-reasons-your-finance-employees-are-showing-signs-of-stress.html "4 reasons your finance employees are showing signs of stress") tend to split them into two, they are very co-dependent on what each is doing. So, is this [continued division of compliance and security](https://www.financedigest.com/ils-investment-returns-continue-to-outperform-according-to-aon-insurance-linked-securities-report.html "ILS investment returns continue to outperform, according to Aon insurance-linked securities report") defensible?

There are solid [organisational reasons to keep](https://www.financedigest.com/auditing-in-cyber-how-organisations-can-keep-track-of-their-data.html "AUDITING IN CYBER: HOW ORGANISATIONS CAN KEEP TRACK OF THEIR DATA") them separate, and it comes down not so much to technical or domain reasons but about who we need to deal with external regulators or auditors. We are positioned internally to answer the people who could ask us the tough questions, e.g. a financial regulator to whom we direct a team focused to answer, and at the IT [security level they stand ready to help the CIO or CEO when they ask after a ransomware attack](https://www.financedigest.com/2018-it-security-predictions-methods-for-attacks-investment-areas-cybersecurity-strategies.html "2018 IT Security Predictions-Methods For Attacks, Investment Areas & Cybersecurity Strategies") hits the news, are we doing everything we can from a technical level to prevent this happening to us?

**A** [data solution that addresses what both sides need](https://www.financedigest.com/leaders-recognise-the-importance-of-green-transport-at-cop27-but-we-need-data.html "Leaders recognise the importance of green transport at COP27, but we need data")

Different people can address these different [data challenges](https://www.financedigest.com/new-gleif-challenge-facility-extends-ability-to-trigger-updates-of-legal-entity-identifier-data-to-all-interested-parties.html "New GLEIF Challenge Facility Extends Ability to Trigger Updates of Legal Entity Identifier Data to All Interested Parties"), but they actually want the same thing out of the technology that they’re securing. And what if instead of twin/parallel approaches to what aren’t really two problems at all but one, with all the inefficiency and duplicated effort that risks, there was one approach that actually reinforced the intrinsic quality of the [data we want to protect](https://www.financedigest.com/4-steps-you-should-be-taking-to-protect-data.html "4 Steps You Should Be Taking To Protect Data") and so continuously raised the bar for both needs?

Recent database [industry advances mean there is just such a unified way](https://www.financedigest.com/5-ways-the-fs-industry-can-support-the-recovery.html "5 ways the FS industry can support the recovery") forward, and which gives you a core that delivers 90% of what both sides need that merely then requires the additional 10% to be added on for specific purposes. This is the shift to microservices and full exploitation of Web-based data and development disciplines. At its heart is a new way of managing data in a database, which actually becomes the critical engine of the unified approach. It [must be secure](https://www.financedigest.com/why-the-finance-sector-must-prioritise-mobile-security-over-innovation.html "Why the finance sector must prioritise mobile security over innovation"), and it must be resilient, and it also must be able to manage where data is stored and how it’s transmitted.

So, if you can build a database which has all these characteristics, you can easily also run it in multiple compliance/data protection jurisdictions, storing data where created or where owned, but also be able to work with it securely on a global scale. This can only really happen, however, if you can abstract out [data and how you want to work with it from the specific](https://www.financedigest.com/who-urges-china-to-share-specific-data-regularly-on-covid-situation.html "WHO urges China to share specific data regularly on COVID situation") software implementation(s) you want to store it in, separating the transactional and the analytical sides.

**‘All this important data heavy-lifting with just one** [cloud database’](https://www.financedigest.com/oracle-offers-its-mysql-heatwave-database-and-analytics-on-amazons-cloud.html "Oracle offers its MySQL HeatWave database and analytics on Amazon’s cloud")

To date, there have also been technical reasons why compliance and [security couldn’t share](https://www.financedigest.com/privacy-vs-security-is-the-cybersecurity-information-sharing-act-beneficial.html "PRIVACY VS SECURITY: IS THE CYBERSECURITY INFORMATION SHARING ACT BENEFICIAL?") the same tools. If you had to manage three or five databases or one for every jurisdiction, if you had to develop different code and different [solutions to sit on top](https://www.financedigest.com/james-trainor-top-fbi-cyber-expert-joins-aons-cyber-solutions-group.html "James Trainor, top FBI cyber expert, joins Aon’s Cyber Solutions Group") of it, your agility as a business is radically diminished and your costs would just go up unacceptably. But what if you could do all this important [data heavy lifting](https://www.financedigest.com/european-shares-edge-higher-on-healthcare-lift-weak-china-data-stokes-worries.html "European shares edge higher on healthcare lift, weak China data stokes worries") with just one cloud database that could be used for all these different needs in different locations, and which also simply required familiar SQL to access and manipulate?

By using the latest in open-source database, combined with agile and CI/CD (continuous integration and continuous delivery), for finance companies to move to a common core of quality, scalable and [secure data management across all your business and legal needs](https://www.financedigest.com/why-preparation-for-new-swift-cyber-security-standards-needs-to-start-now.html "‘Why preparation for new SWIFT cyber security standards needs to start now’") will lower costs and improve ROI. Importantly, it will also enable you to respond much more quickly and nimbly to both on-going [compliance needs with all its associated regular change and the eternal](https://www.financedigest.com/fintech-and-compliance-managing-the-eternal-balancing-act.html "Fintech and compliance: Managing the eternal balancing act") “war” against the hackers.

And if you don’t do it? You will continue to have separate teams, separate development costs, separate workflows and separate stakeholders and process owners. And while that has made sense for a long time, it doesn’t now—so why not see if it could [work for you and your organisation](https://www.financedigest.com/uk-based-bitfount-raises-5m-seed-to-streamline-collaboration-between-organisations-working-with-sensitive-datasets.html "UK-based Bitfount raises M seed to streamline collaboration between organisations working with sensitive datasets.") too?

**_About Author:_**

_David Walker is Field CTO, EMEA, for_ [_Yugabyte_](https://www.yugabyte.com) _, the leader in open-source distributed SQL databases for global, Internet- scale applications with low query latency and extreme resilience against failures._


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

