# How financial services organisations can address the ‘Vulnerability Lag’ and safeguard their most important digital assets
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2022-04-01
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: Innovate or stagnate: Financial Services must balance
Meta Description: Discover how financial services organisations can bridge the gap between rapid innovation and security to safeguard valuable customer data from cybercriminals.
URL: https://financedigest.com/how-financial-services-organisations-can-address-the-vulnerability-lag-and-safeguard-their-most-important-digital-assetshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/istock-1198455339-1736815910341-compressed.jpg)

_By_ **_Barry Cashman,_** _Regional Vice President for UKI at_ [_Veritas Technologies_](https://www.veritas.com/)

As the Greek philosopher, Heraclitus, is famously quoted saying, “change is the only constant in life”. This was all too true when businesses were faced with a global pandemic that no one could have seen coming. In order to adapt and keep afloat during such unprecedented times, businesses needed to innovate fast, but their security measures struggled to keep pace. [Financial services](https://www.financedigest.com/trends-in-the-financial-service-landscape-and-the-impact-on-fraud.html "Trends in the financial service landscape and the impact on fraud") organisations were especially stretched by these challenges, as employees shifted to new remote working patterns, more services moved online, and new products were introduced at speed, without the necessary steps taken to ensure all the new technologies that were added were protected.

This created a ‘vulnerability lag’, where [systems and data](https://www.financedigest.com/interoperability-of-data-to-accelerate-the-ventilator-test-systems-market.html "Interoperability of data to accelerate the Ventilator Test Systems Market") have been left unprotected and open to attack. And while businesses were right to prioritise continuity for customers and empowering the shift to remote working, the time has come to redress the balance between rapid [innovation and security](https://www.financedigest.com/infosecurity-europe-agenda-spotlights-innovation-as-security-leaders-address-cybersecurity-spend-in-the-face-of-economic-headwinds.html "Infosecurity Europe agenda spotlights innovation as security leaders address cybersecurity spend in the face of economic headwinds"), to protect from increasingly sophisticated cybercriminals.

**The hard facts**

Cybercrime is set to cost the global economy [$10.5 trillion annually by 2025](https://cybersecurityventures.com/cybercrime-damages-6-trillion-by-2021/). Industry research reveals that, in the UK, the average cost of a ransomware attack is around [£1.5 million.](https://www.comparitech.com/blog/information-security/uk-cyber-security-statistics/#:~:text=The%20average%20cost%20of%20ransomware%20attacks%20in%20the%20UK%20was%20around%20%241.96%20million) All things considered – the potential regulatory penalties, the impact of downtime, the cost of losing data that may be irretrievable – the financial repercussions for failing to protect your data could be crippling.

But the cost of an attack often goes far beyond the monetary [value a company will pay out in potential ransom payments](https://www.financedigest.com/2021-predictions-realising-the-value-of-payments-transformation.html "2021 Predictions: Realising the Value of Payments Transformation") and penalties for regulatory non-compliance. Trust is the biggest loss a company could ever face – when customers lose their trust in an organisation to secure and protect their data, it’s very difficult to win it back, especially for an industry such as [financial services](https://www.financedigest.com/the-future-for-financial-services-is-digital-engagement.html "The future for financial services is digital engagement").

Building an industry on collecting and using highly sensitive customer data is a double-edged sword – while [financial services](https://www.financedigest.com/how-crowdsourcing-can-help-drive-the-benefits-of-advanced-analytics-in-financial-services.html "HOW CROWDSOURCING CAN HELP DRIVE THE BENEFITS OF ADVANCED ANALYTICS IN FINANCIAL SERVICES") companies can take advantage of a vast pool of valuable customer data to offer personalised services and explore new revenue streams, if this data falls into the wrong hands, it could damage livelihoods beyond repair. This makes the [industry a very attractive](https://www.financedigest.com/thalia-da-attracts-fresh-investment-as-semiconductor-industry-recognises-the-analog-ip-reuse-challenge.html "Thalia DA attracts fresh investment as semiconductor industry recognises the analog IP reuse challenge") target for cybercriminals.

Many [financial services organisations globally are not managing their data](https://www.financedigest.com/financial-services-firms-turn-to-big-data-intelligence-to-fight-fraudulent-activity-according-to-xerox-study.html "FINANCIAL SERVICES FIRMS TURN TO BIG DATA INTELLIGENCE TO FIGHT FRAUDULENT ACTIVITY ACCORDING TO XEROX STUDY") as well as they could be. According to recent Veritas research, companies in the financial services space are more likely to be struggling to keep pace with their security than those from most other sectors, with nearly half (48%) stating that their data security is lagging behind their digital transformation deployments. The average [across all industries](https://www.financedigest.com/digital-transformation-across-the-banking-industry.html "Digital transformation across the banking industry") is 39%.

Further, [financial services](https://www.financedigest.com/as-hackers-declare-cyberwarfare-financial-services-cannot-afford-to-be-complacent.html "As hackers declare cyberwarfare, financial services cannot afford to be complacent") organisations that want to eliminate their vulnerability lag within a year would need to spend on average an additional £1.99 million and hire 29 new members of IT staff each. £1.99 [million is 5% more than the average required across](https://www.financedigest.com/700000-employees-across-the-uk-have-access-to-fair-finance-will-reach-one-million-employees-in-2017.html "700,000 Employees Across The UK Have Access to Fair Finance, Will Reach One Million Employees in 2017") all sectors, which may be disappointing news for IT leaders in the sector, given that they already typically spent 19% more than their peers on IT initiatives last year.

Surviving any kind of [ransomware attack](https://www.financedigest.com/preventing-an-operationally-crippling-ransomware-attack-do-you-know-where-your-risk-exposure-lies.html "PREVENTING AN OPERATIONALLY CRIPPLING RANSOMWARE ATTACK – DO YOU KNOW WHERE YOUR RISK EXPOSURE LIES?") always starts with understanding your data – what it is, where it is and what it’s worth. Yet, most businesses lack clarity about the [data](https://www.financedigest.com/auditing-in-cyber-how-organisations-can-keep-track-of-their-data.html "AUDITING IN CYBER: HOW ORGANISATIONS CAN KEEP TRACK OF THEIR DATA") they might need to protect, with the average UK organisation admitting that 39% of the data their organisation was storing is “dark” – that is to say, they don’t know what it is – and that a further 51% is Redundant, Obsolete or Trivial (ROT).

**A light at the end of the tunnel**

While the pressures that rapid [digital transformation put on IT departments weren’t unique to the financial services](https://www.financedigest.com/how-to-enhance-banking-services-with-digital-performance-intelligence.html "HOW TO ENHANCE BANKING SERVICES WITH DIGITAL PERFORMANCE INTELLIGENCE") sector, its position as a highly attractive target to hackers may have meant that the industry has felt them more acutely. With hackers beating at the door and limited resources to push them back, as well as tightening [industry regulations](https://www.financedigest.com/how-solvency-ii-transformed-itself-the-fund-industry-and-regulation.html "How Solvency II transformed itself, the fund industry and regulation"), it can feel like the IT teams are between a rock and a hard place.

But astute IT leaders are partnering with data protection providers that can minimise the admin burden of data protection through [simplified tools leveraging artificial intelligence](https://www.financedigest.com/how-artificial-intelligence-is-simplifying-sanctions-screening-for-insurers.html "How Artificial Intelligence is Simplifying Sanctions Screening for Insurers") (AI) and machine learning (ML). Taking this approach can help [financial services organisations accelerate their security](https://www.financedigest.com/post-brexit-uk-workers-can-have-financial-security.html "Post Brexit – UK workers CAN have financial security") rollouts and stop their protection infrastructure from lagging behind their digital transformation.

Allowing AI and ML to take on the time-consuming manual processes also enables [skilled IT team](https://www.financedigest.com/what-skills-and-areas-of-knowledge-should-finance-teams-develop-during-2023.html "What Skills and Areas of Knowledge Should Finance Teams Develop During 2023? ") members to focus on innovation projects, rather than on playing ‘catch up’. Ultimately, these processes can still be human-governed, with AI doing the leg work.

Despite any company’s best efforts, [ransomware attacks](https://www.financedigest.com/wannacry-ransomware-attack-how-to-protect-your-data-online.html "WannaCry ransomware attack: How to protect your data online") are a matter of ‘when’ rather than ‘if’, so knowing ‘when’ becomes absolutely critical. What distinguishes one victim from another is their ability to resist and [bounce back](https://www.financedigest.com/biotech-stocks-pin-bounce-back-hopes-on-ma-boost.html "Biotech stocks pin bounce back hopes on M&A boost").


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

