# Keeping data in the vault: insider breach risk in financial services
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2020-05-15
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: Insider Threats in Financial Services: Understanding and
Meta Description: Discover how financial organisations can reduce breach risk from within by understanding and mitigating insider threats. Learn more from the Egress CEO.
URL: https://financedigest.com/keeping-data-in-the-vault-insider-breach-risk-in-financial-serviceshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/tungsten-network-finance-accelerates-growth-1736838913973-compressed.jpg)

**_By_** **_Tony Pepper,_** **_CEO._** [**_Egress_**](https://www.egress.com/)

Financial services organisations are trusted with far more than just money; they are also responsible for keeping customers’ highly sensitive personal and financial data under lock and key. We’re hyper-aware that the growing value of this data means financial organisations are prime targets for malicious cyberattacks – but this isn’t the only threat they face. In fact, not a [day passes](https://www.financedigest.com/india-to-hold-one-day-state-mourning-on-passing-away-of-queen-elizabeth.html "India to hold one day state mourning on passing away of Queen Elizabeth") without these firms’ own employees putting data at risk from within.

You might think that, when it comes to reducing overall breach risk, employees represent low-hanging fruit – surely it is easier to control the actions of a company’s own [team members](https://www.financedigest.com/playground-xyz-appoints-new-team-members-as-it-solidifies-its-position-as-a-leader-in-the-attention-space.html "Playground xyz appoints new team members as it solidifies its position as a leader in the attention space") than it is to defend against external attackers? However, this not the reality experienced by financial [firms](https://www.financedigest.com/how-finance-firms-can-unify-two-data-approaches-to-improve-both-compliance-and-security.html "How finance firms can unify two data approaches to improve both compliance and security") worldwide. While external attackers are always motivated by malicious intent, the employee population is far more heterogenous and, in a sense, much more human. This makes understanding and [mitigating insider risk](https://www.financedigest.com/mitigating-operational-risk-through-centralising-reconciliation.html "MITIGATING OPERATIONAL RISK THROUGH CENTRALISING RECONCILIATION") a more nuanced exercise. Just because it is difficult, however, doesn’t mean it is impossible. It’s crucial that financial [services companies](https://www.financedigest.com/why-financial-services-companies-should-consider-rfps-in-their-digital-transformation-strategies.html "Why financial services companies should consider RFPs in their digital transformation strategies") shift the dial on insider risk and reduce breach frequency, because the penalties for failing to do so are becoming increasingly draconian and the repercussions from customers much more severe.

The recent [Egress Insider Breach Survey](https://www.egress.com/news/insider-data-breach-survey-2020) aimed to understand the different attitudes towards data sharing and ownership among employees in financial services companies and the approaches that IT leaders in the sector are taking to managing insider breach risk.

We found a whole range of diverse profiles of people who put sensitive [financial data](https://www.financedigest.com/data-centres-and-the-changing-financial-trading-landscape.html "Data centres and the changing financial trading landscape") at risk for very different, but very human, reasons. Some [need monitoring to keep their less-than-honest traits from getting the better of them, while others need a helping hand to save](https://www.financedigest.com/what-you-need-to-know-about-tax-savings-for-businesses-in-las-vegas-nv.html "What You Need to Know About Tax Savings for Businesses in Las Vegas NV") them from making genuine, well-meaning mistakes. And across all respondents, we also found confusion over who really owns data, contributing to the more cavalier attitudes displayed by some.

**Deliberate “data breachers” – from well-intentioned but reckless to disaffected and destructive**

Our study found that the financial [services sector](https://www.financedigest.com/protecting-the-uk-financial-services-sector-from-cyberattacks-now-and-in-2023.html "Protecting the UK financial services sector from cyberattacks now and in 2023") has more than its fair share of deliberate “data breachers”. Of the thousand employees we questioned, almost a third (32%) said they or a colleague had intentionally broken company policy when sharing or removing information in the [past year](https://www.financedigest.com/how-has-growth-of-marine-scrubber-systems-market-taken-off-over-the-past-few-years.html "How has Growth of Marine Scrubber Systems Market Taken Off Over the Past Few Years"). This compares with just 15% of [healthcare workers and 11% of government sector](https://www.financedigest.com/installing-trust-what-intelligent-automation-can-do-for-the-healthcare-sector.html "Installing trust: What Intelligent Automation can do for the healthcare sector") employees.

The reasons given for this deliberate flouting of [security policy](https://www.financedigest.com/uk-finance-regulators-should-pay-heed-to-energy-security-policy-says-sunak.html "UK finance regulators should pay heed to energy security policy, says Sunak") varied. One-third said they were simply trying to get their job done but didn’t have the appropriate tools to share [data safely](https://www.financedigest.com/your-money-is-safe-but-your-data-might-not-be.html "YOUR MONEY IS SAFE, BUT YOUR DATA MIGHT NOT BE"). On the face of it we might have some sympathy with those employees, but would [consumers and businesses want to bank](https://www.financedigest.com/ant-group-starts-to-differentiate-consumer-loan-business-jiebei-from-bank-loans.html "Ant Group starts to differentiate consumer loan business Jiebei from bank loans") with those firms?

It’s more difficult to be sympathetic with those motivated by self-gain, including the 41% who took [data with them because they were moving to a new job](https://www.financedigest.com/euro-zone-bond-yields-rise-after-u-s-jobs-data.html "Euro zone bond yields rise after U.S. jobs data"). And we have even less sympathy for the 15% who compromised [data because they were angry with the company](https://www.financedigest.com/the-logo-of-french-cloud-computing-company-ovhcloud-is-seen-on-a-data-center-building-in-strasbourg-france-october-13-2021-reuters-christian-hartmann.html "The logo of French cloud computing company OVHcloud is seen on a data-center building in Strasbourg, France, October 13, 2021.  REUTERS/Christian Hartmann") and wanted to deliberately cause harm.

**Operator error – mobile, tired, under pressure**

Even with their firm’s best interests at heart, employees still make mistakes. 30% of [financial sector workers said they or a colleague had caused an accidental data](https://www.financedigest.com/big-data-analytics-fraud-prevention-in-the-financial-sector.html "BIG DATA, ANALYTICS & FRAUD PREVENTION IN THE FINANCIAL SECTOR") breach in the past year – again more than twice as many as their public sector counterparts. A third had sent an email to the wrong person and a further third had clicked on a link in a phishing email.

Their reasons behind these breaches varied from the pressure of [working in a stressful environment](https://www.financedigest.com/the-benefits-of-creating-a-great-working-environment.html "The Benefits of Creating a Great Working Environment"), to tiredness and rushing. A significant proportion, however, said they made an error due to using a mobile device – and given the current requirement for mobile remote working during this [COVID-19 pandemic](https://www.financedigest.com/uk-sees-biggest-rise-in-foreign-workers-since-covid-19-pandemic.html "UK sees biggest rise in foreign workers since COVID-19 pandemic"), this is a definite cause for concern.

**Breach detection gaps and technology limitations**

Next, we examined what IT leaders in the sector have in place to [mitigate insider breach risk](https://www.financedigest.com/new-isla-standards-provide-the-foundation-for-resource-optimisation-efficiency-and-risk-mitigation.html "New ISLA Standards Provide the Foundation for Resource Optimisation, Efficiency and Risk Mitigation"). Concerningly, 60% said the most likely way they would discover an insider [data breach](https://www.financedigest.com/how-financial-organisations-can-stay-protected-from-financial-data-breaches.html "How Financial Organisations can Stay Protected from Financial Data Breaches ") was via internal hand-raiser reporting by either the employee themselves or a colleague. Only one third felt that their breach [detection systems](https://www.financedigest.com/the-fall-detection-system-market-to-show-innovation-based-steadiness.html "The Fall Detection System Market to show innovation-based steadiness") would pick up the issue.

In a similar vein, traditional data protection [technology use was surprisingly inconsistent across financial firms](https://www.financedigest.com/financial-firms-can-use-technology-combat-todays-cybercriminals.html "How financial firms can use technology to combat today’s cybercriminals"). Email encryption, anti-malware and [secure](https://www.financedigest.com/top-fintech-trends-for-2021-enabling-smart-and-secure-finance.html "Top Fintech Trends for 2021 Enabling Smart and Secure Finance") collaboration software were in use by fewer than half of financial sector companies. Again, raising the question whether consumers and [businesses would be willing to trust their data to financial](https://www.financedigest.com/how-can-financial-institutions-make-the-most-of-data-for-their-business.html "HOW CAN FINANCIAL INSTITUTIONS MAKE THE MOST OF DATA FOR THEIR BUSINESS?  ") firms if they knew they didn’t have systems in place to protect it.

So, why is this the case? From the data we uncovered, it seems as though organisations are resigned to a proportion of insider breach incidents occurring, accepting them as an inevitable result of doing business and employing people. But this doesn’t need to be the case. It is possible to apply human layer security solutions to mitigate these risk factors and make a [positive impact](https://www.financedigest.com/broadcast-switchers-market-increasing-adoption-of-ip-live-production-technology-to-positively-impact-growth.html "Broadcast Switchers Market: Increasing Adoption of IP Live Production Technology to Positively Impact Growth") on breach frequency figures.

**Human layer security – a helping hand and a watchful eye**

Take the issue of rushing or tiredness. This can lead to users adding the wrong recipients to emails or failing to spot the subtle changes in familiar [email addresses](https://www.financedigest.com/how-to-create-a-professional-email-address.html "How to Create a Professional Email Address") that denote targeted phishing attempts. This risk can be overcome with tools that use contextual [machine learning](https://www.financedigest.com/transforming-insurance-through-artificial-intelligence-and-machine-learning.html "Transforming Insurance Through Artificial Intelligence and Machine Learning") to analyse what the good security behaviour looks like for each user and support them with alerts that tell them they’ve added an unusual recipient to an email, or that they are about to answer a phishing email. A small prompt is all these users need to stop them from making an [error and causing a data breach](https://www.financedigest.com/outthink-raises-10-million-to-tackle-human-errors-behind-data-breaches.html "OutThink raises million to tackle human errors behind data breaches").

Similarly, when using [mobile devices with smaller screens](https://www.financedigest.com/adverty-wins-third-us-patent-for-brainimpression-bringing-ad-viewability-technology-to-gaming-on-mobile-tv-screens-and-the-wider-metaverse.html "Adverty wins third US patent for BrainImpression™, bringing ad viewability technology to gaming on mobile, TV screens and the wider metaverse"), it is very easy to choose the wrong attachment and send sensitive data outside the organisation to the wrong recipient or to the right person unprotected. If an employee is less than honest, our always-on, constantly connected [culture also enables](https://www.financedigest.com/smart-working-versus-presenteeism-enabling-productivity-in-a-post-pandemic-hybrid-work-culture.html "Smart Working Versus Presenteeism: Enabling Productivity in a Post-Pandemic Hybrid Work Culture") them to deliberately do so too. However, it is possible to stop these incidents with an intelligent solution that scans email and attachment content and identifies data such as personally identifiable information (PII) or [bank account](https://www.financedigest.com/community-fintech-11onze-to-launch-el-canut-a-super-app-offering-universal-banking-accounts-and-digital-debit-cards.html "Community fintech 11Onze to launch – EL CANUT – a super APP offering universal banking accounts and digital debit cards") details to alert users that they are about to send information to an unauthorised recipient, or without the correct level of encryption applied. If the user persists, the risky email can be blocked from being sent and administrators alerted to a potentially intentional attempt to [breach data](https://www.financedigest.com/amazons-twitch-blames-configuration-error-for-data-breach.html "Amazon’s Twitch blames configuration error for data breach"), so they can respond accordingly.

Ultimately, the most effective way to address human-activated [threats to security](https://www.financedigest.com/how-financial-services-firms-can-mitigate-against-their-top-data-security-threats.html "How Financial Services Firms Can Mitigate Against Their Top Data Security Threats") is by implementing tools that support and manage users when they are at their most humanly vulnerable; tired, rushing, under pressure, angry or self-interested. As our research and wider evidence shows, the [financial services sector is more than averagely vulnerable to insider data](https://www.financedigest.com/financial-services-firms-turn-to-big-data-intelligence-to-fight-fraudulent-activity-according-to-xerox-study.html "FINANCIAL SERVICES FIRMS TURN TO BIG DATA INTELLIGENCE TO FIGHT FRAUDULENT ACTIVITY ACCORDING TO XEROX STUDY") breaches, meaning human layer security must be a priority for IT leaders in the field if they hope to reduce breach frequency and keep sensitive data firmly in the vault.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

