# How Financial Services Firms Can Mitigate Against Their Top Data Security Threats
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-10-29
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: Mitigating Cybersecurity Threats in Financial Services
Meta Description: Discover the key strategies to protect sensitive data from cyber-attacks, including leveraging Zero Trust frameworks and automating security measures.
URL: https://financedigest.com/how-financial-services-firms-can-mitigate-against-their-top-data-security-threatshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/web-dangerfjuzibpo-sbi-300188267-1736837498883-compressed.jpg)

_![](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/9-1736837498836-compressed.jpg)_

_By **Martin Ward,** Director, Security Governance Risk and Compliance,_ [_iManage_](http://www.imanage.com)

Sensitive data is the coin of the realm for financial services firms. Unfortunately, this makes them a prime target for bad actors of every stripe who are looking to get their hands on that data.

[A recent security report](https://enterprise.verizon.com/content/verizonenterprise/us/en/index/resources/reports/2021-dbir-executive-brief.pdf) indicates that cyber-attacks continue to plague the financial services sector, with ransomware attacks making up a vast portion of the reported security incidents. Meanwhile, at a gathering earlier this year of the chief executives of the six largest banks in the United States, [cybersecurity was named as the greatest threat](https://www.nytimes.com/2021/07/03/business/dealbook/hacking-wall-street.html) to their companies and the wider financial system.

Given this unforgiving landscape, how can firms best mitigate and guard against the persistent threats to their data?

**[Understanding Where Risk](https://www.financedigest.com/how-data-visualisation-is-helping-the-insurance-sector-understand-environmental-risks.html "How data visualisation is helping the insurance sector understand environmental risks") Actually Lies**

One of the first steps [firms should take is to carefully scrutinise the cloud services](https://www.financedigest.com/financial-services-firms-turn-to-big-data-intelligence-to-fight-fraudulent-activity-according-to-xerox-study.html "FINANCIAL SERVICES FIRMS TURN TO BIG DATA INTELLIGENCE TO FIGHT FRAUDULENT ACTIVITY ACCORDING TO XEROX STUDY") they’re utilising. That’s because as more and more [financial services firms](https://www.financedigest.com/financial-firms-can-use-technology-combat-todays-cybercriminals.html "How financial firms can use technology to combat today’s cybercriminals") have embraced the cloud, a transference of risk has occurred: out of the organisation to the cloud vendor, with the cloud vendor responsible for the lion’s share of security controls.

The bad guys are aware of this shift, and they’re adjusting their attack methodologies accordingly, to focus on the weak links in the [supply chain](https://www.financedigest.com/5-steps-to-successful-supply-chain-finance.html "5 Steps to successful supply chain finance"). For instance, how are IT [services being delivered](https://www.financedigest.com/solgari-tenx2-announce-global-growth-partnership-to-deliver-compliant-integrated-omni-channel-cloud-communications-services.html "Solgari& TenX2 announce global growth partnership to deliver compliant, integrated omni-channel cloud communications services")? What platforms are being leveraged? Who’s providing IT [support for the service](https://www.financedigest.com/uk-gives-bbc-world-service-20-million-pounds-to-support-english-language-broadcasting.html "UK gives BBC World Service 20 million pounds to support English language broadcasting")?

By taking the time to understand the ins-and-outs of those IT services and where the weak points are, bad actors have a better chance of successfully targeting the sensitive [data that the services](https://www.financedigest.com/how-big-data-is-sending-shockwaves-through-the-financial-services-sector.html "How big data is sending shockwaves through the financial services sector") manage. Incidentally, this is the same general strategy that was employed in the [SolarWinds hack](https://www.businessinsider.com/solarwinds-hack-explained-government-agencies-cyber-security-2020-12) earlier this year that targeted government agencies and Fortune 500 companies alike.

Since [85% of all data breaches involve some type of social engineering or human element](https://enterprise.verizon.com/content/verizonenterprise/us/en/index/resources/reports/2021-dbir-executive-brief.pdf), the ability of a cloud vendor to mitigate against that element is one of the most important areas. [Clouds that are built around a Zero Trust](https://www.financedigest.com/how-cloud-is-driving-forward-implementation-of-zero-trust-security.html "How Cloud is Driving Forward Implementation of Zero Trust Security") model are – to a large extent – able to engineer out this human element. A Zero Trust framework assumes absolutely no [level](https://www.financedigest.com/the-effect-of-rising-fraud-levels-on-consumer-trust.html "The Effect of Rising Fraud Levels on Consumer Trust") of trust, whether that’s trust of networks, trust between host and applications, or even trust of super users or administrators.

The [effectiveness of this Zero Trust](https://www.financedigest.com/effectively-efficiently-build-financial-trust-customer-journey.html "Effectively and efficiently build financial trust on the customer journey") framework, however, is dependent upon it also incorporating a Zero Touch approach. Zero [Touch uses automation to take the human](https://www.financedigest.com/putting-the-human-touch-back-into-banking-magazine.html "“Putting the human touch back into banking”-Magazine") out of the equation for everything from routine server maintenance and patching, to more advanced troubleshooting.

This “hands off” approach ensures that no human actually has hands-on access to sensitive data, helping to “automate out” the weakest link – and giving [financial services](https://www.financedigest.com/trends-in-the-financial-service-landscape-and-the-impact-on-fraud.html "Trends in the financial service landscape and the impact on fraud") firms greater confidence that the service they’re utilising on a daily basis is secured at the highest possible levels.

**Safeguarding** [Remote Work](https://www.financedigest.com/combating-the-security-risk-of-remote-working.html "Combating the security risk of remote working ")

The risk that the “human element” presents isn’t limited to the cloud vendors that [financial services](https://www.financedigest.com/as-hackers-declare-cyberwarfare-financial-services-cannot-afford-to-be-complacent.html "As hackers declare cyberwarfare, financial services cannot afford to be complacent") utilise. Financial services firms also need to make sure they’re protecting against any intentional or unintentional damage that the [consumers](https://www.financedigest.com/do-consumers-want-robo-advisory-services.html "DO CONSUMERS WANT ROBO-ADVISORY SERVICES?") of those cloud services – their employees – might potentially cause.

Mitigating this element has become considerably more difficult over the last 18 [months since](https://www.financedigest.com/uk-factories-suffer-worst-month-since-may-2020-as-economy-stumbles-pmi.html "UK factories suffer worst month since May 2020 as economy stumbles – PMI") large numbers of those employees have been working remotely, outside the four walls of the firm, which greatly increases the risk level.

For starters, home networks are inherently more insecure than [corporate](https://www.financedigest.com/tungsten-network-to-collaborate-with-bnp-paribas-in-offering-e-invoicing-linked-receivables-supply-chain-financing-solutions-to-large-corporates.html "Tungsten Network to collaborate with BNP Paribas in offering e-invoicing linked Receivables & Supply Chain financing solutions to large corporates") networks. They simply don’t have the same [security controls in place](https://www.financedigest.com/private-equity-firms-hungry-for-investment-opportunities-but-business-owners-must-be-cautious.html "Half of Security Professionals Had No Contingency Plan in Place for COVID-19") – which means the likelihood of some type of malware getting on that home network and then providing a backdoor into the corporate environment increases. In fact, users are [three and a half times more likely to have malware on their home PC’s](https://www.ciosummits.com/Identifying_Unique_Risks_of_Work_from_Home-Remote_Office_Networks_1.pdf) than on their office devices. All it takes is one wrong click on a carefully crafted spear phishing email or [text message](https://www.financedigest.com/cm-takes-over-german-text-message-service-providers-smskaufen-and-innosend.html "CM takes over German text message service providers SMSKaufen and Innosend") for malware to propagate across the system.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

