# Improving Enterprise Security in the Financial Sector
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2019-03-28
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: Top Strategies for Cybersecurity in Financial Sector
Meta Description: Discover the latest insights from CISO Gerald Beuchelt on the critical importance of cybersecurity in the financial sector and practical steps for enhancing
URL: https://financedigest.com/improving-enterprise-security-in-the-financial-sectorhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/gerald-beuchelt-1736839081590-compressed.jpg)

_By Gerald Beuchelt, CISO,_ [_LogMeIn_](http://www.logmein.com)

Cybersecurity is a critical concern within any industry, but especially the financial sector which has long been an attractive target. The appeal of financial gain and wide access to highly personal and valuable customer information has meant that financial services firms are [targeted more than any other sector](https://newsroom.accenture.com/news/cybercrime-costs-financial-services-sector-more-than-any-other-industry-with-breach-rate-tripling-over-past-five-years-according-to-report-from-accenture-and-ponemon-institute.htm). In fact, UK banking customers lost £358 million to unauthorised fraud in the first half of 2018 and during the second half of the year, the financial industry experienced a [37 percent increase in takeover attacks and a 107 percent increase in attempts to gain control of user accounts during mobile transactions](https://www.law.com/corpcounsel/2019/03/05/financial-sector-sees-major-spike-in-mobile-cyberattacks-report-says/?slreturn=20190206045747). Added to this direct threat on the financial sector is the seemingly endless news of breaches at trusted brands, including British Airways and Ticketmaster, and we have a culture of fear.

![Gerald Beuchelt, CISO, LogMeIn](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/gerald-beuchelt-1736839081590-compressed.jpg)

Gerald Beuchelt, CISO, LogMeIn

While the attackers’ sophistication and types of threats are ever evolving, some basics of cybersecurity remain unchanged. Mainly, passwords are an easy point of entry for attackers with [81% of data breaches involving weak, reused or stolen credentials](https://urldefense.proofpoint.com/v2/url?u=https-3A__www.knowbe4.com_hubfs_rp-5FDBIR-5F2017-5FReport-5Fexecsummary-5Fen-5Fxg.pdf&d=DwMFAw&c=k6LEwkJiSX1kJxtgPu1uYQ&r=FKfF03f2VWSTcXZjPKR-VdChomqx3N6cvbn7kvevU_8&m=sRKYP3_t-zA2C9yMsSY8qCs28Md7IHuQOpS0jeWAmMc&s=OYzA3Itw0BjKQX6U86OnzByxqt5nxbN37VIOdLtbx00&e=). One might think that given the threat on financial institutions, they would be at the forefront of all security practices, including smart passwords. However, a recent study that scored businesses on password practices and multifactor authentication (MFA) adoption found the industry performing below average.

With security practices continuing to plague organisations, what steps can [banks](https://www.financedigest.com/stellantis-reshuffles-european-financing-operations-through-new-jvs-with-banks.html "Stellantis reshuffles European financing operations through new JVs with banks") and financial institutions take to strengthen defences?

**Maintaining system evaluations**

At a most basic definition, breaches occur when an organisation’s [vulnerabilities are found and exploited by attackers](https://www.financedigest.com/finding-it-hard-to-recruit-good-it-security-managers-dont-leave-yourself-vulnerable-to-attack.html "Finding it hard to recruit good IT security managers? Don’t leave yourself vulnerable to attack"). Banks and other financial institutions must be continually evaluating their [systems](https://www.financedigest.com/the-role-embedded-finance-systems-will-play-as-commerce-goes-increasingly-digital.html "The Role Embedded Finance Systems Will Play as Commerce Goes Increasingly Digital") for possible weaknesses, especially as attackers’ techniques constantly change. Complacency is an organisation’s greatest enemy. Simply because a system was secure last year, last month or even last week, does not mean it will be sufficient against [future threats](https://www.financedigest.com/the-future-of-finance-how-to-defend-against-the-top-threats-to-cloud-security.html "The Future of Finance: How to defend against the top threats to cloud security").

Whilst risk assessments of critical [systems should be a regular occurrence within financial institutions, organisations should also ensure they assess secondary systems containing non-critical assets](https://www.financedigest.com/guide-to-choosing-a-digital-asset-management-system.html "Guide to Choosing a Digital Asset Management System"). Employee-private activities and accounts, such as personal emails or Facebook, are still potential gateways to an internal network, so authentication policies should be a main focus of these assessments. As part of these evaluations, it’s [important to consider what information](https://www.financedigest.com/software-to-display-your-businesss-important-information.html "Software to Display Your Business’s Important Information") employees have access to. They should only have the [data needed to carry out their job](https://www.financedigest.com/euro-zone-bond-yields-rise-after-u-s-jobs-data.html "Euro zone bond yields rise after U.S. jobs data") and no more. Limiting access where possible helps reduce the potential vulnerabilities.

Financial institutions can also seriously benefit from leveraging advanced offensive security, such as penetration testing and “red team” exercises to [improve visibility](https://www.financedigest.com/improving-online-visibility-for-insurers.html "IMPROVING ONLINE VISIBILITY FOR INSURERS") and security awareness across the organisation. Red team testing comprehensively exposes physical, hardware, software and human vulnerabilities before they become entry [points for hackers or provide](https://www.financedigest.com/finger-pointing-helps-no-one-it-is-time-for-retailers-energy-providers-and-government-to-band-together.html "Finger-pointing helps no one: it is time for retailers, energy providers and government to band together") opportunities for bad actors and malicious insiders to compromise systems.

**Putting the focus on passwords**

Going back to the above point on understanding vulnerabilities, while there are endless new technologies to combat cybersecurity risk, including advanced AI and biometrics, sometimes the simple solution is the most valuable. Case in point, [ground-breaking technology](https://www.financedigest.com/seenthis-launches-ground-breaking-segment-by-segment-optimization-technology-for-display-advertising.html "SeenThis launches ground-breaking segment-by-segment optimization technology for display advertising") can’t help a weak password culture. The basics of password policies and [authentication are critical to enterprise security](https://www.financedigest.com/behavioral-biometrics-simple-and-secure-way-to-authenticate-consumers-digital-identities.html "Behavioral Biometrics: Simple and Secure way to Authenticate Consumers’ Digital Identities").

As such, password management should be a [top priority](https://www.financedigest.com/why-intelligent-automation-should-be-a-top-priority-for-enterprises-in-2022.html "Why Intelligent Automation should be a top priority for enterprises in 2022"). This should include education for all staff on [safe password practices](https://www.financedigest.com/factoring-in-fail-safes-five-practical-steps-for-more-efficient-transparent-reporting.html "Factoring in fail-safes: five practical steps for more efficient, transparent reporting"), how to create a strong password, and the importance of using unique credentials across all accounts. To encourage adoption, organisations can implement password management tools or at the very least, direct employees towards the solutions. These tools will help remove the reluctance towards keeping track of multiple, complex passwords.

Going further in password security, multifactor authentication (MFA) is one of the most effective ways to add another layer of security to password [protected accounts](https://www.financedigest.com/midlands-accountants-say-its-never-too-early-to-get-financial-protection.html "MIDLANDS ACCOUNTANTS SAY IT’S NEVER TOO EARLY TO GET FINANCIAL PROTECTION"). With MFA, the hacker has to provide an additional factor (a one-time code generated by a hardware token, fingerprint, etc.), even if they do obtain the password. The recent Timehop breach, which affected nearly its entire customer base of 21 [million users](https://www.financedigest.com/zoom-reaches-85-million-settlement-over-user-privacy-zoombombing.html "Zoom reaches million settlement over user privacy, ‘Zoombombing’"), occurred because the company hadn’t protected access to its cloud network with MFA. Again, one might expect the financial sector to have already adopted this practice, however a recent report found that only 16% of banking/financial institutions had adopted MFA, compared to 31% of technology businesses.

**Embed [security culture](https://www.financedigest.com/a-culture-of-cyber-security-throughout-financial-services-organisations.html "A Culture of Cyber Security Throughout Financial Services Organisations") through training**

Organisations can invest in all of the right [security technology](https://www.financedigest.com/how-open-source-technology-is-securing-the-future-of-financial-services.html "How open-source technology is securing the future of financial services") and develop all of the needed policies, but they’ll be useless if employees aren’t trained on them or don’t understand the importance of adhering to them.

Firstly, employees need to understand the severity of the threats and the prowess of attackers. Secondly, guidelines should be distributed with well-illustrated [security policies and education](https://www.financedigest.com/education-security-in-2022-hybrid-cloud-device-management-drives-it-challenges.html "Education Security in 2022: Hybrid-Cloud, Device Management Drives IT Challenges") on how to follow said policies. Finally, regular training sessions should be conducted to keep staff up-to-date on new [threats and ensure proper security](https://www.financedigest.com/how-financial-services-firms-can-mitigate-against-their-top-data-security-threats.html "How Financial Services Firms Can Mitigate Against Their Top Data Security Threats") practices are embedded in company culture.

Given what’s at risk, banks and financial organisations simply cannot allow [security](https://www.financedigest.com/top-fintech-trends-for-2021-enabling-smart-and-secure-finance.html "Top Fintech Trends for 2021 Enabling Smart and Secure Finance") to be an afterthought. Banking is going through a period of huge change, with [Open Banking](https://www.financedigest.com/how-accountants-can-improve-financial-planning-and-results-through-open-banking-to-help-smes.html "How accountants can improve financial planning and results through Open Banking to help SMEs") and PSD2 being some of the biggest shake ups to the industry in years, which brings new opportunities for innovation – as well as threats. Organisations cannot risk taking for granted their security and misreading the [importance](https://www.financedigest.com/as-consumer-spending-increases-convenience-and-security-have-never-been-more-important.html "As consumer spending increases, convenience and security have never been more important") of basic security practices and employee adoption.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

