# Identifying areas of vulnerability: Why cybersecurity shouldn’t be an afterthought for financial organisations
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2022-10-17
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Leveraging the Bank of England’s Cyber Framework for
Meta Description: Learn from cyber security expert Anna Webb how UK financial organisations can leverage the Bank of England&#039;s Cyber Framework to enhance their defences
URL: https://financedigest.com/identifying-areas-of-vulnerability-why-cybersecurity-shouldnt-be-an-afterthought-for-financial-organisationshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/istock-1011996682-1736815015241-compressed.jpg)

![](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/anna-webb-450x606-1736815015275-compressed.jpg)

_By_ **_Anna Webb,_** _Head of Security Operations at_ [_Kocho_](https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fkocho.co.uk%2F&data=04%7C01%7Cbenjamin.david%40reedexpo.co.uk%7Ca7927ba887934429dad808da1dffce0c%7C9274ee3f94254109a27f9fb15c10675d%7C0%7C0%7C637855281763115862%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=YQGombx1nMkABGmZnKk6vy4Sy%2BkT9o2K3RfrReAg5Mw%3D&reserved=0)

The Bank of England’s Cyber Framework has been designed to help UK financial institutions identify areas of vulnerability that can be exploited by a cyber attack. It will also help to increase awareness of how effective cyber security measures really are. In this article, Anna Webb, Head of Security Operations at Kocho, the cyber security, identity and cloud IT expert, discusses how financial [organisations can leverage the framework to bolster their cyber](https://www.financedigest.com/auditing-in-cyber-how-organisations-can-keep-track-of-their-data.html "AUDITING IN CYBER: HOW ORGANISATIONS CAN KEEP TRACK OF THEIR DATA") defences.

**Importance of cyber** [security for financial services](https://www.financedigest.com/what-can-we-learn-from-financial-services-security.html "What can we Learn from Financial Services Security?")

Cyber [security in financial](https://www.financedigest.com/5-steps-to-strengthening-your-online-financial-security.html "5 Steps to Strengthening Your Online Financial Security") services is incredibly important but also extremely complex. [Tech advancements and digitalisation projects rapidly accelerated](https://www.financedigest.com/final-call-for-entries-to-tech-start-up-accelerator.html "FINAL CALL FOR ENTRIES TO TECH START-UP ACCELERATOR") during the pandemic, increased the attack surface of company operations. The requirement to work from home, and access confidential information from outside corporate networks, increased the [risk of attack](https://www.financedigest.com/preventing-an-operationally-crippling-ransomware-attack-do-you-know-where-your-risk-exposure-lies.html "PREVENTING AN OPERATIONALLY CRIPPLING RANSOMWARE ATTACK –  DO YOU KNOW WHERE YOUR RISK EXPOSURE LIES?") still further and made it more difficult to adhere to strict compliance requirements. Furthermore, with ransomware attacks on the rise and high-profile vulnerabilities being discovered at an alarming frequency, keeping systems secure is akin to a game of whack-a-mole for understaffed and overworked IT teams. To put the scale of the challenge into perspective, the UK Government’s 2022 [Cyber Security Breaches Survey](https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2022/cyber-security-breaches-survey-2022) found that 39% of UK businesses identified a cyber attack in the last 12 months.

There isn’t an easy solution to this multifaceted situation, but if financial organisations break down the task into bite-sized pieces, it is certainly possible for them to minimise their exposure to cyber risks.

**Balancing cybersecurity and flexible working practices**

For many [financial organisations the quest to strike a balance between security and flexible working practices has been a top](https://www.financedigest.com/top-north-east-financial-adviser-firm-talks-corporation-tax.html "Top North East financial adviser firm talks corporation tax") priority. One approach is to introduce security protocols that reflect each employee’s job function, and the applications and systems they [need to access](https://www.financedigest.com/what-needs-to-happen-to-improve-the-landscape-for-smes-trying-to-access-finance-options-in-the-uk.html "What needs to happen to improve the landscape for SMEs trying to access finance options in the UK") in order to fulfil their role.

For example, employees in the accounting or marketing departments may be more likely to continue to work from home in the longer term, so they will need solutions that can strengthen their local [network security](https://www.financedigest.com/new-demands-on-network-security.html "NEW DEMANDS ON NETWORK SECURITY"). This compares to traders, who require more powerful systems and lower latency, and therefore will likely continue to work at the office, well within the local security protocols. Financial advisors are often mobile so may require more [robust network security and identity controls](https://www.financedigest.com/dollar-buoyant-as-robust-u-s-data-keep-fed-hawks-in-control.html "Dollar buoyant as robust U.S. data keep Fed hawks in control"). Commercial bankers, who once established relationships over business dinners, now find themselves trying to do the same using videoconferencing tools that must be adequately [secured if they are being used to share highly confidential data](https://www.financedigest.com/assurance-v-security-reassessing-responsibility-for-data-assurance.html "Assurance v Security: Reassessing Responsibility for Data Assurance").

The IT department will need to support all these new ways of [working with the right security solutions to ensure the overall success of the organisation](https://www.financedigest.com/how-collaboration-technologies-are-helping-organisations-to-embrace-a-hybrid-working-model.html "How collaboration technologies are helping organisations to embrace a hybrid working model").

**[Investing in compliance as a business](https://www.financedigest.com/why-investing-in-employee-health-can-be-good-for-business.html "Why investing in employee health can be good for business") enabler**

Legislation will always evolve as it tries to [keep pace with advances in technology and with the ever-changing modes](https://www.financedigest.com/in-listening-mode-new-bayer-ceo-keeps-open-mind-on-company-split.html "In listening mode, new Bayer CEO keeps ‘open mind’ on company split") of attack by cyber criminals. As financial organisations look to innovate and remain competitive, they need to ensure that they are undergoing digital [transformation in a way](https://www.financedigest.com/7-ways-cloud-technology-can-transform-business-finances.html "7 ways cloud technology can transform business finances") that is sustainable and safe – especially if they’re outsourcing operations to other companies and giving them access to their data.

A recent regulatory development is the Bank of England [CBEST security assessment framework](https://www.bankofengland.co.uk/financial-stability/operational-resilience-of-the-financial-sector/cbest-threat-intelligence-led-assessments-implementation-guide), which is designed to help financial organisations improve their cyber resilience, and is also now integrated into supervisory strategies from regulators such as the Prudential Regulation Authority (PRA) and the Financial Conduct Authority (FCA). These voluntary assessments focus on revealing and understanding weaknesses and vulnerabilities and [set out the remedial action that should be taken to fortify organisations](https://www.financedigest.com/embracing-cloud-computing-how-and-why-organisations-are-set-to-invest-more-in-cloud-computing-in-2023.html "Embracing Cloud Computing: How and why organisations are set to invest more in cloud computing in 2023") and, by proxy, the wider financial network.

During the assessment, a highly skilled cyber threat [intelligence analyst will oversee a series of realistic penetration tests that replicate sophisticated modern cyber attacks](https://www.financedigest.com/new-intelligence-points-to-pro-ukraine-group-in-nord-stream-attack-nyt.html "New intelligence points to pro-Ukraine group in Nord Stream attack -NYT") without causing any damage to the actual system of the financial institution. As part of the process, the [organisation’s cyber](https://www.financedigest.com/cyber-threats-for-finance-organisations-to-watch-in-2023.html "Cyber threats for finance organisations to watch in 2023") defences are benchmarked for maturity against the standard key performance indicators. The continued use of CBEST has been confirmed as a highly effective regulatory assessment tool, which can also be undertaken on a cross-jurisdictional basis, and in cooperation with other regulations and frameworks.

For any financial service organisations that are outsourcing any of their services, it is valuable to be aware of the exponential rise in cyber attacks on [supply chains](https://www.financedigest.com/5-steps-to-successful-supply-chain-finance.html "5 Steps to successful supply chain finance"). For the UK government that meant further legislation on security has become inevitable. A framework known as [National Cyber Strategy 2022](https://www.gov.uk/government/publications/national-cyber-strategy-2022/national-cyber-security-strategy-2022) (NCS) is designed to aid UK organisations in developing IT infrastructure security so that they are prepared for such attacks. A new national cyber strategy is expected to be launched by the end of this year, with proposals likely to become law sometime in 2023.

**The role of MSP in bolstering IT defences**

Many organisations opt to outsource their IT and [cyber security to gain access to greater expertise](https://www.financedigest.com/aon-boosts-cyber-expertise-with-london-appoinment.html "AON BOOSTS CYBER EXPERTISE WITH LONDON APPOINMENT") and resources. Indeed, in the UK, [55% of mid-sized organisations and 60% of large organisations](https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2022/cyber-security-breaches-survey-2022) rely on third parties to secure their operations. However, it would be wrong to assume that this option makes an organisation immune to cyber attacks. Organisations should look to take control of their cyber security now by examining their existing IT service [supply chain](https://www.financedigest.com/g7-finance-leaders-pledge-financial-stability-supply-chain-diversity.html "G7 finance leaders pledge financial stability, supply chain diversity").

When selecting an MSP or reviewing the capabilities of one already in place, organisations should begin by checking its security certifications. A simple and easy step, this shows if they’ve achieved any industry-recognised security certifications. Good ones to look out for are the government-backed [Cyber Essentials Plus programme](https://www.ncsc.gov.uk/cyberessentials/overview) or an ISO 27001 certification.

The next step – especially when initially scouting for an MSP – is to check relevant case studies and references. All MSPs worth their salt should be able to provide their work history and demonstrate experience with cyber security. Check for awards that prove they have been recognised for their expertise – especially keep an eye out for accreditations that are sector specific. For example, the [Channel E2E list](https://www.channele2e.com/top100/) which compiles the top 100 service providers for the financial sector.

**Conclusion**

Securing a complex network seems to be an impossible task, but risk can be reduced by focusing on key requirements such as introducing role-based identity controls, keeping systems updated, ensuring a high-quality [security posture for the cloud services](https://www.financedigest.com/how-financial-services-are-overhauling-security-to-defend-against-spoofing-scams.html "How financial services are overhauling security to defend against spoofing scams"), keeping track of and addressing vulnerabilities, securing endpoints, and finally educating every employee on every level about cyber security. By addressing these factors, organisations can keep adversaries at bay.

However, in this ever-changing landscape of rising threats and new vulnerabilities, a trusted MSP, with specialist [expertise in how to identity and mitigate risks](https://www.financedigest.com/jaywing-releases-horizon-a-new-ifrs-9-modelling-solution-that-encapsulates-its-extensive-credit-risk-expertise.html "Jaywing releases Horizon, a new IFRS 9 modelling solution that encapsulates its extensive credit risk expertise"), can help stop incidents from escalating into something that’s financially and reputationally disastrous.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

