# How financial services leaders can prioritise cybersecurity investment
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2022-07-26
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Financial Services Industry: Mitigating Cybersecurity Risks
Meta Description: Gain insights from Microsoft UK&#039;s Director of Financial Services on the escalating cyber threats facing the industry post-pandemic and learn how
URL: https://financedigest.com/how-financial-services-leaders-can-prioritise-cybersecurity-investmenthtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/istock-1351578048-1736815537643-compressed.jpg)

_![](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/064-1736815537690-compressed.jpg)_

_By **Craig Wellman,** Director, Financial Services, Microsoft UK_

As industries and economies handled the aftermath of the pandemic, cybercriminals and hackers thrived amid the uncertainty. Previously isolated, loosely networked malicious actors were given the space and resource to form complex, inter-connected communities and economies.

Responsible for and dependent on a wealth of personal data, [financial information and digital assets, the financial services](https://www.financedigest.com/can-financial-services-brands-ever-be-credible-on-social.html "Can financial services brands ever be credible on social? ") industry proves to be a primary target of these attacks. Indeed, the sector was the second most targeted industry by ransomware in 2021, according to [Microsoft’s Digital Defence Report](https://www.microsoft.com/en-us/security/business/microsoft-digital-defense-report) – ahead of government, healthcare and education.

Facing such attacks, it’s no wonder that mitigating security risks and defending against cyber attacks has become top of mind for the sector, with [research](https://www2.deloitte.com/us/en/insights/industry/financial-services/cybersecurity-maturity-financial-institutions-cyber-risk.html) revealing that the industry spends 10% of its IT budget on security services. Yet despite this, many in the [industry continue to fall victim to attacks](https://www.financedigest.com/the-aftermath-of-covid-19-cybersecurity-crisis-have-the-attacks-benefitted-the-industry-more-than-they-hurt-it.html "The Aftermath of COVID-19 Cybersecurity Crisis: Have The Attacks Benefitted the Industry More Than They Hurt It?"). In fact, [74% of financial sector security leaders](https://www.vmware.com/content/dam/learn/en/pdf/carbonblack/Modern%20Bank%20Heists%205.0%20Report.pdf?irclickid=0O6346QewxyIRSdxSGSHCU9fUkGSqbyWjW3qxE0&utm_source=affiliate&utm_medium=ONLINE_TRACKING_LINK_&utm_campaign=Online%20Tracking%20Link&utm_term=engine%3Aimpact%7Cpublisherid%3A10078%7Ccampaignid%3A11461&irpid=10078&irgwc=1) reported experiencing ransomware attacks in the last year, resulting in huge pay-outs totalling $602 million in the US alone, according to Chainalysis.

While the kneejerk response of many leaders has been to increase security spending, a failure to guide this [investment towards securing](https://www.financedigest.com/2018-it-security-predictions-methods-for-attacks-investment-areas-cybersecurity-strategies.html "2018 IT Security Predictions-Methods For Attacks, Investment Areas & Cybersecurity Strategies") weak points and defending the touchpoints cybercriminals target continues to leave organisations vulnerable. Without a well thought out, strategic approach to security investment, cybercriminals have been able to evolve their tools and scale their resources at a [rate ahead](https://www.financedigest.com/hopes-of-slowdown-in-rate-hikes-bolster-shares-ahead-of-u-s-gdp.html "Hopes of slowdown in rate hikes bolster shares ahead of U.S. GDP") of the industry, allowing the continued success of attacks.

The question then becomes, what can [financial services](https://www.financedigest.com/how-crowdsourcing-can-help-drive-the-benefits-of-advanced-analytics-in-financial-services.html "HOW CROWDSOURCING CAN HELP DRIVE THE BENEFITS OF ADVANCED ANALYTICS IN FINANCIAL SERVICES") leaders do with the resources they have to protect their data, and avoid facing costly ultimatums from hackers? Thankfully, there are many clear [steps organisations](https://www.financedigest.com/6-steps-to-organising-an-introvert-friendly-networking-event.html "6 Steps to organising an introvert-friendly networking event ") can take to find a way forward.

**[Step 1 – Establish a security](https://www.financedigest.com/5-steps-to-strengthening-your-online-financial-security.html "5 Steps to Strengthening Your Online Financial Security") culture:**

Despite complex networks and sophisticated groups now driving cyber-attacks, the vast majority still lead with the same rudimentary techniques used to gain access to secure systems five-to-ten years ago, with over [70% of ransomware attacks](https://www.microsoft.com/en-us/security/business/microsoft-digital-defense-report) starting with phishing campaigns or password sprays.

Employees remain the first and most critical [line of defence](https://www.financedigest.com/merchants-are-the-first-line-of-defence-against-fraud-heres-how-we-can-help-them.html "Merchants are the first line of defence against fraud: here’s how we can help them") against malicious attacks. And as such, developing their awareness of how cybercriminals may look to use them to access [secure data](https://www.financedigest.com/assurance-v-security-reassessing-responsibility-for-data-assurance.html "Assurance v Security: Reassessing Responsibility for Data Assurance") is vital in preventing malicious attacks.

Organisational culture is fundamental to maintaining security, and at Microsoft, we often find that the most secure organisations have created a people-first [security culture](https://www.financedigest.com/a-culture-of-cyber-security-throughout-financial-services-organisations.html "A Culture of Cyber Security Throughout Financial Services Organisations"), not just a set of directives. For [financial services](https://www.financedigest.com/as-hackers-declare-cyberwarfare-financial-services-cannot-afford-to-be-complacent.html "As hackers declare cyberwarfare, financial services cannot afford to be complacent") leaders, ensuring employees are equipped with the tools, training and sector-specific knowledge they need to stay safe is essential. [Leaders can bolster protective practices by encouraging employees](https://www.financedigest.com/3-impactful-ways-that-leaders-can-contribute-to-the-independent-development-of-their-employees.html "3 Impactful Ways that Leaders Can Contribute to the Independent Development of Their Employees") to be wary of communications that ask for sensitive information, creating an environment where they feel supported to report suspicious activity, and offering help and training to those who remain unsure.

**Step 2 – Understanding and securing the weak points in IT infrastructure:**

Increasingly becoming the infrastructure of choice, hybrid- and multi-cloud solutions can offer the industry more flexibility and resilience, but financial services organisations [must also secure](https://www.financedigest.com/why-the-finance-sector-must-prioritise-mobile-security-over-innovation.html "Why the finance sector must prioritise mobile security over innovation") against the vulnerabilities and risks such software creates. Doing so requires cloud-agnostic tools that can [reach across](https://www.financedigest.com/700000-employees-across-the-uk-have-access-to-fair-finance-will-reach-one-million-employees-in-2017.html "700,000 Employees Across The UK Have Access to Fair Finance, Will Reach One Million Employees in 2017") your infrastructure and reinforce the areas of overlap and connection to keep attackers out.

**Step 3 – Underpin security with visibility:**

Today’s [big data](https://www.financedigest.com/big-data-suggests-leicesters-football-success-could-usher-in-economic-boom.html "Big data suggests Leicester’s football success could usher in economic boom"), multiplatform, hyper-connected workplace has created evolving, inherent risks for every sector. Over the past two years, [financial services](https://www.financedigest.com/what-can-we-learn-from-financial-services-security.html "What can we Learn from Financial Services Security?") organisations have seen a massive increase in their digital footprint, resulting in data fragmentation across applications, devices and locations. The lines between risk roles and the [responsibility for protecting](https://www.financedigest.com/aon-introduces-new-cyber-solution-in-response-to-eu-regulation-on-data-protection.html "Aon introduces new cyber solution in response to EU regulation on data protection") the workplace are also blurring.

The market has responded with an array of products which require security, compliance and legal teams to stitch together different solutions, but the result proves ineffective, [offering a fragmented view of the data](https://www.financedigest.com/aon-data-empowers-unica-to-offer-flood-insurance-for-5-2bn-canadian-peril.html "Aon data empowers Unica to offer flood insurance for .2bn Canadian peril") estate. As these environments become more complex, the [risk of breaches remaining unnoticed and ransomware](https://www.financedigest.com/preventing-an-operationally-crippling-ransomware-attack-do-you-know-where-your-risk-exposure-lies.html "PREVENTING AN OPERATIONALLY CRIPPLING RANSOMWARE ATTACK – DO YOU KNOW WHERE YOUR RISK EXPOSURE LIES?") being allowed to spread across a network grows. Making sure leaders and IT teams have access to tools which offer one single view of the entire data estate, such as [Microsoft Purview](https://docs.microsoft.com/en-us/azure/purview/overview), will allow the financial services sector to govern, protect and manage the entire data estate, enabling an effective and timely response to malicious activity.

**Step 4 – Maintain [strong security](https://www.financedigest.com/industrial-cyber-security-solutions-and-services-strong-increase-in-user-base-pans-out-for-north-america-to-lead-market.html "Industrial Cyber Security Solutions and Services – Strong Increase in User Base Pans Out for North America to Lead Market") hygiene:**

Given the rudimentary techniques often used by cybercriminals, [our research](https://www.microsoft.com/en-us/security/business/microsoft-digital-defense-report) reveals that the basic fundamentals of cybersecurity, such as multi-factor authentication and keeping on top of software updates, can protect against 98% of current attacks.

Providing a strong security culture is established, [maintaining](https://www.financedigest.com/maintaining-security-and-compliance-amid-digital-transformation-in-financial-services.html "Maintaining Security and Compliance amid Digital Transformation in Financial Services") what we refer to as “security hygiene” can be simple and straightforward. For example, commonplace multi-factor authentication [technology only requires employees to confirm a login with a secondary device](https://www.financedigest.com/the-medical-device-technologies-market-to-stick-around-based-on-organic-expansion.html "The Medical Device Technologies Market to stick around based on organic expansion"). A host of tools are available to support organisations to keep software and endpoints up-to-date and correctly configured, such as [Microsoft Endpoint Manager](https://www.microsoft.com/en-gb/security/business/microsoft-endpoint-manager), which can secure each touchpoint in an organisation’s IT infrastructure.

In following these steps to guide their security investment, financial services leaders will be able better guide their spending and resource to [turn the tide](https://www.financedigest.com/is-the-tide-turning-for-chinese-brands-overseas.html "IS THE TIDE TURNING FOR CHINESE BRANDS OVERSEAS?") against escalating security risks.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

