# Maintaining Security and Compliance amid Digital Transformation in Financial Services
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-06-30
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Financial Services Industry Transformation &amp; Cloud Risks
Meta Description: Discover how the financial services industry is evolving with cloud and SaaS applications, the risks involved, and how to mitigate them with full-fidelity
URL: https://financedigest.com/maintaining-security-and-compliance-amid-digital-transformation-in-financial-serviceshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/hand-and-touchscreen-technologyfjlnctsd-1736838249994-compressed.jpg)

_By **John Atkinson,** Director of Solutions Engineering, UK & Ireland, at Riverbed Technology_

The financial services industry is transforming as companies move to cloud and Software-as-a-Service (SaaS) applications to support both work-from-anywhere business models and the creation of new, customer-centric services. Although this digitisation is driving positive change, it’s not without risk. Particularly in the financial [sector in relation to security](https://www.financedigest.com/why-the-finance-sector-must-prioritise-mobile-security-over-innovation.html "Why the finance sector must prioritise mobile security over innovation") and compliance and protecting the highly sensitive data they are responsible for. This issue is being exacerbated by the ever-improving capabilities of cybercriminals. Should a financial institutions’ customers or employees become victims of undetected attacks, the organisations’ reputation, not to mention [stability and financial](https://www.financedigest.com/g7-finance-leaders-pledge-financial-stability-supply-chain-diversity.html "G7 finance leaders pledge financial stability, supply chain diversity") position, could be compromised. However, these threats can be minimised through full-fidelity visibility.

Before we explain this further, we must first understand how COVID-19 has changed the way banks and other [financial institutions operate and the knock-on effects of this on security](https://www.financedigest.com/post-brexit-uk-workers-can-have-financial-security.html "Post Brexit – UK workers CAN have financial security") and compliance.

**Moving to the cloud**

Over the past few years, [financial services](https://www.financedigest.com/the-future-for-financial-services-is-digital-engagement.html "The future for financial services is digital engagement") companies, who have traditionally relied on on-premises set-ups, have begun moving to the cloud. COVID-19, and its associated economic and operational challenges, prompted a rise in this trend, as organisations turned to the [cloud’s flexible cost structure to minimise losses and enable new ways](https://www.financedigest.com/7-ways-cloud-technology-can-transform-business-finances.html "7 ways cloud technology can transform business finances") of working.

For example, in response to lockdown, HSBC [signed a deal](https://www.financedigest.com/italys-nexi-signs-digital-payments-deal-with-tims-olivetti.html "Italy’s Nexi signs digital payments deal with TIM’s Olivetti") with Amazon Web Services (AWS), while Goldman Sachs and Deutsche Bank embraced Google, to mobilise affordable and effective remote working. Meanwhile, Emirates NBD began working on personalised, digital [banking experiences](https://www.financedigest.com/transforming-the-banking-experience-to-be-mobile-first-and-people-centric.html "Transforming the banking experience to be mobile-first and people-centric"), built on AWS, allowing it to deliver strong customer service outside of its physical branches.

As Emirates NBD illustrates, the trend towards [cloud is set](https://www.financedigest.com/embracing-cloud-computing-how-and-why-organisations-are-set-to-invest-more-in-cloud-computing-in-2023.html "Embracing Cloud Computing: How and why organisations are set to invest more in cloud computing in 2023") to continue after the pandemic. In fact, [EY’s UK Banking Cloud Adoption Index](https://www.ey.com/en_uk/news/2020/11/uk-banks-have-less-than-10-of-business-infrastructure-currently-migrated-onto-public-cloud) indicates that over a quarter of banks will move half or more of their business to the public cloud next year. However, the research also reveals that adoption is being slowed by concerns about [data security](https://www.financedigest.com/the-challenge-of-keeping-data-secure-why-in-house-security-isnt-enough.html "The challenge of keeping data secure: why in-house security isn’t enough") and regulatory risk.

**[Security and compliance](https://www.financedigest.com/fintechs-must-remove-security-and-compliance-friction-to-unlock-new-growth.html "Fintechs Must Remove Security and Compliance Friction to Unlock New Growth") complexity**

All leading cloud providers bake [security into their services](https://www.financedigest.com/what-can-we-learn-from-financial-services-security.html "What can we Learn from Financial Services Security?"). However, the transition of [data onto external servers increases the security](https://www.financedigest.com/2023-fintech-prediction-secure-and-private-data-usage-is-key.html "2023 FinTech Prediction: Secure and Private Data Usage is Key") risk, with cybersecurity threats, including phishing and ransomware, becoming more difficult to spot without the complete visibility that only comes on-premises.

The same challenges apply for SaaS applications as they are cloud-based. Although applications such as Office365, Slack, and Salesforce are enabling smooth remote working and the delivery of a strong level of [customer service](https://www.financedigest.com/id-fraud-is-on-the-rise-can-financial-services-do-more-to-protect-their-customers.html "ID fraud is on the rise: can financial services do more to protect their customers?"), they’re also widening the threat surface endangering these benefits. As the demand for SaaS grows – [Gartner](https://www.gartner.com/en/newsroom/press-releases/2020-07-23-gartner-forecasts-worldwide-public-cloud-revenue-to-grow-6point3-percent-in-2020) predicts that SaaS revenue will have increased to $140.6 billion by 2022, a $38.5 billion increase from 2019 – so too will the issue.

What’s more, employees aren’t just using the SaaS applications their organisations sanction. They’re also creating [private accounts for the applications of their choosing](https://www.financedigest.com/mistakes-to-avoid-while-choosing-a-private-money-lender.html "Mistakes To Avoid While Choosing a Private Money Lender") to maximise productivity. For instance, signing up to Slack to facilitate collaboration, or using WeTransfer to share files with co-workers if they feel the corporate VPN is obstructively slow. While staff are carrying out these actions with the best intentions, they’re extending the [security perimeter by generating a new form of Shadow IT that their employers simply don’t](https://www.financedigest.com/dont-let-the-promises-of-virtual-desktop-security-cloud-your-judgement.html "Don’t let the promises of virtual desktop security cloud your judgement") have visibility over.

The lack of visibility caused by employee-run tools, the move to cloud, and SaaS are significantly impairing IT’s ability to monitor end-to-end traffic patterns. As a result, this means that they can’t identify divergences from the norm that could indicate a [security or compliance breach that needs](https://www.financedigest.com/why-preparation-for-new-swift-cyber-security-standards-needs-to-start-now.html "‘Why preparation for new SWIFT cyber security standards needs to start now’") addressing.

**Overcoming the threat by regaining visibility**

The good news is that banks and other [financial companies](https://www.financedigest.com/how-financial-services-companies-can-successfully-utilise-low-code-and-no-code-technologies.html "How financial services companies can successfully utilise low-code and no-code technologies") can regain full-fidelity or complete visibility. They can do this by developing a careful vetting process for the cloud-based applications they use, in tandem with clearly [communicating their policies on employees using unsanctioned apps](https://www.financedigest.com/one-app-for-a-total-communications-experience.html "One App for a Total Communications Experience"). With these steps in place, they can gather and document the data being created across the enterprise – including both their cloud and on-premises infrastructure – to create a complete end-to-end picture of their entire IT infrastructure.

Manually collecting this information is virtually impossible, so [organisations need to invest in Network](https://www.financedigest.com/6-steps-to-organising-an-introvert-friendly-networking-event.html "6 Steps to organising an introvert-friendly networking event ") Performance Monitoring (NPM) tools to automate the process. With the data gathered in one place, [companies are empowered to conduct regular risk assessments and remediate threats](https://www.financedigest.com/5-ways-to-protect-your-company-from-cyber-security-threats.html "5 Ways to Protect Your Company From Cyber Security Threats"). For example, comparing the age of staff passwords against corporate policies, and requesting employees change them if needed to protect [data and ensure compliance](https://www.financedigest.com/britain-plans-new-data-rules-to-ease-compliance-burden.html "Britain plans new data rules to ease compliance burden"). Beyond gathering information, these solutions can also generate benchmarks for ‘normal’ activity and [flag anything that falls](https://www.financedigest.com/euro-zone-bond-yields-fall-as-ecb-policymaker-flags-recession-risk-gilts-eyed.html "Euro zone bond yields fall as ECB policymaker flags recession risk, gilts eyed") outside of these parameters to IT for further investigation. This approach ultimately supports cyber forensics, threat hunting, and incident response – a security [benefit embraced by many of Riverbed’s NPM customers](https://www.financedigest.com/online-marketplaces-embracing-embedded-finance-to-benefit-both-customers-and-vendors.html "Online marketplaces: embracing embedded finance to benefit both customers and vendors     ").

**Secure and compliant** [digital transformation](https://www.financedigest.com/digital-transformation-for-the-world-of-finance-the-rise-in-collaboration-tools-and-saas-applications.html "Digital transformation for the world of finance: The rise in collaboration tools and SaaS applications ")

[Financial organisations must maintain strong levels of security](https://www.financedigest.com/the-financial-sector-must-act-to-tackle-internal-data-security.html "THE FINANCIAL SECTOR MUST ACT TO TACKLE INTERNAL DATA SECURITY") and compliance as they digitise. Central to this is attaining complete visibility over the whole digital estate, regardless of the physical location of employees or whether [data is being held in the cloud](https://www.financedigest.com/three-ways-the-data-cloud-can-keep-financial-services-competitive.html "Three Ways the Data Cloud Can Keep Financial Services Competitive") or on-premises. Equipped with this insight, [companies can identify threats and strategise effective](https://www.financedigest.com/how-can-financial-services-companies-compete-more-effectively-in-times-of-uncertainty.html "How can Financial Services Companies compete more effectively in times of uncertainty?") solutions. This means staff can [work both effectively and securely](https://www.financedigest.com/combating-the-security-risk-of-remote-working.html "Combating the security risk of remote working "), all data can be safeguarded, and compliance can be guaranteed in the new, digital environment.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

